Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

91–100 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#91
post #53

Earlier quoted context omitted.

Could just use "country".

Nation State suggests the nations government. If you just say country it might suggest organized crime or other randos from that country.

'Foreign government.'

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#92
My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way.

A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt matter).

The hackers then appeared to hijack the “remember me” login session from our employees Chrome.app. Within a few hours, online webmail logins (edit sessions not logins) were occurring all over the world for this user’s mailbox. The hackers then spread the “virus” by emailing this employee’s known contacts the same spoof.

I don’t think Microsoft ever fixed the bug, as far as I know. Our method to protect ourselves was to upgrade to IP restricted logins on a higher level of Microsoft 365, and disable the “remember me for 30 days” feature. We’re debating turning off access to web-mail entirely because it does scare me that I think its still possible to do.

Anyone else experience this?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#95
post #48

Earlier quoted context omitted.

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way.

Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#97

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

In this context, nation-state means “people with the authority and budget to do stuff like this”.

Its used because it makes the victim seem less incompetent, and doesn’t misidentify the attacker, doubling the ownage.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#98
post #92

My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way. A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt m…

How did you determine that the attacker hijacked the existing O365 session rather than logging in with the phished username and password? For an app like O365, usually that kind of cookie-stealing doesn't happen without malware on a user's computer.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#99
post #92

My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way. A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt m…

We actually had something similar happen, almost to a “T”.

Individual’s account was compromised and was used to send emails to their address book asking them to review an RFP. They would then delete the emails that were sent and the account owner was none the wiser.

I am not 100% certain as to how the initial compromise happened, but it was an O365 environment and MFA was on. O365 did pick it up and send an alert, but due to a configuration error it did not disable the account.

Anyways, it worked out and we transitioned to M365 as well.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#100

Earlier quoted context omitted.

Nation State suggests the nations government. If you just say country it might suggest organized crime or other randos from that country.

'Foreign government.'

Also a problem with many places. Think about Pakistan, where the military is not the government per se, but has the resources.

“Nation state adversary” says something without saying it.

Post reply on HN