Mimecast links breach to SolarWinds hackers

The company has confirmed that the Microsoft credentials hack was related to the SolarWinds Orion compromise

Mimecast has confirmed that a recent security incident which saw users’ Microsoft 365 accounts breached was carried out by the same threat actors responsible for the SolarWinds hack.

The major incident saw SolarWinds fall victim to “a highly sophisticated, manual supply chain attack” which was likely conducted by the Russian state. Moscow has denied involvement in the attack but warned businesses in the country that they could be at risk of US retaliation.

Weeks later, Mimecast announced that it had also been the target of a hack, with cyber criminals obtaining one of its digital certificates and abusing it to gain access to clients’ Microsoft 365 accounts.

While previously suspected, it has now been determined that the two incidents are linked. 

Mimecast has revealed on its blog that an internal investigation into the incident found that it “is related to the SolarWinds Orion software compromise and was perpetrated by the same sophisticated threat actor”.

“Our investigation also showed that the threat actor accessed, and potentially exfiltrated, certain encrypted service account credentials created by customers hosted in the United States and the United Kingdom," Mimecast said.

"These credentials establish connections from Mimecast tenants to on-premise and cloud services, which include LDAP, Azure Active Directory, Exchange Web Services, POP3 journaling, and SMTP-authenticated delivery routes."

The cloud cyber security services provider also advised its US and UK-based users “to take precautionary steps to reset their credentials”.

However, it added that it is “not aware that any of the encrypted credentials have been decrypted or misused”.

The company said that it is cooperating with law enforcement and that “elements of the investigation into this threat actor remain ongoing”.

13/01/2021: Mimecast admits hackers accessed users’ Microsoft credentials

Mimecast has admitted that a number of its users may have their Microsoft 365 accounts accessed by “a sophisticated threat actor”.

The security incident involved hackers obtaining one of Mimecast's digital certificates and abusing it to gain access to clients’ accounts.

The cloud cyber security services provider was alerted about the incident by Microsoft, and the two companies are working with a third-party forensics expert and law enforcement to investigate the breach.

According to Mimecast, “approximately 10%” of its customers used the connection involving the affected certificate, with not more than nine customers believed to be affected by the breach.

“There are indications that a low single digit number of our customers’ M365 tenants were targeted,” the company announced in a blog post, adding that it had “already contacted these customers to remediate the issue”.

Mimecast also advised “customers using this certificate-based connection to immediately delete the existing connection within their M365 tenant and re-establish a new certificate-based connection using the new certificate" that the company had "made available”.

The London-based company said that taking this precaution would “not impact inbound or outbound mail flow or associated security scanning”.

The news comes days after it was revealed that the cyber criminals who compromised SolarWinds in a sophisticated supply chain cyber attack broke into Microsoft and accessed the company’s  source code repositories.

However, it was also confirmed that the attackers, linked by US authorities to the Russian state, didn’t alter the codebase at the heart of Microsoft's core products and services. They did so through an internal account that had permissions to view, but not edit, these repositories.

Mimecast also made headlines last year when its Threat Center researchers discovered a rise in LimeRAT malware delivery using Microsoft Excel’s “VelvetSweatshop” default password. The research team found making an Excel file read-only instead of locking it encrypts the file without needing an externally created password to open it.

For some time, hackers had taken advantage of how Excel’s encryption and decryption processes work to distribute malware, Mimecast said at the time.

Featured Resources

Security analytics for your multi-cloud deployments

IBM Security QRadar SIEM solution brief

Download now

Five reasons to move to the cloud

Join the enterprises moving their workloads to the cloud

Download now

Architecting hybrid IT and edge for digital advantage

Why business leaders should consider a hybrid IT strategy

Download now

Six reasons to accelerate remote asset monitoring with AI

How to optimise resources, increase productivity, and grow profit margins with AI

Download now

Recommended

Austin Energy warns of scammers soliciting payments in the wake of mass power outages
scams

Austin Energy warns of scammers soliciting payments in the wake of mass power outages

23 Feb 2021
Cyber security firm saw attacks rise by 20% during 2020
cyber security

Cyber security firm saw attacks rise by 20% during 2020

23 Feb 2021
What to look for in a secure cloud system
cloud security

What to look for in a secure cloud system

23 Feb 2021
Hackers turn to 'silent stealing' in bid to exploit home workers
scams

Hackers turn to 'silent stealing' in bid to exploit home workers

22 Feb 2021

Most Popular

Mysterious Silver Sparrow malware hits 30,000 macOS devices
malware

Mysterious Silver Sparrow malware hits 30,000 macOS devices

22 Feb 2021
IBM reportedly mulls sale of Watson Health business
mergers and acquisitions

IBM reportedly mulls sale of Watson Health business

22 Feb 2021
Hackers publish Bombardier data in wide-reaching FTA cyber attack
cyber attacks

Hackers publish Bombardier data in wide-reaching FTA cyber attack

24 Feb 2021