June disruptions to Outlook, cloud platform were cyberattacks: Microsoft

In early June, sporadic but serious service disruptions plagued Microsoft's flagship office suite including the Outlook email and OneDrive file-sharing apps and cloud computing platform

Microsoft outlook outage
AP Boston
4 min read Last Updated : Jun 18 2023 | 6:39 AM IST

In early June, sporadic but serious service disruptions plagued Microsoft's flagship office suite including the Outlook email and OneDrive file-sharing apps and cloud computing platform. A shadowy hacktivist group claimed responsibility, saying it flooded the sites with junk traffic in distributed denial-of-service attacks.

Initially reticent to name the cause, Microsoft has now disclosed that DDoS attacks by a murky upstart were indeed to blame.

But the software giant has offered few details and would not comment on the attacks' magnitude. It would not say how many customers were affected or describe the attackers, who it has named Storm-1359. A group that calls itself Anonymous Sudan claimed responsibility on its Telegram social media channel at the time. Some security researchers believe the group to be Russian.

Microsoft's explanation in a blog post Friday evening followed a request by The Associated Press two days earlier. Slim on details, the post said the attacks temporarily impacted availability of some services. It said the attackers were focused on disruption and publicity and likely used rented cloud infrastructure and virtual private networks to bombard Microsoft servers from so-called botnets of zombie computers around the globe.

Microsoft said there was no evidence any customer data was accessed or compromised.

While DDoS attacks are mainly a nuisance making websites unreachable without penetrating them security experts say they can disrupt the work of millions if they successfully interrupt the services of a software service giant like Microsoft on which so much global commerce depends.

It's not clear if that's what happened here.

We really have no way to measure the impact if Microsoft doesn't provide that info, said Jake Williams, a prominent cybersecurity researcher and a former National Security Agency offensive hacker. Williams said he was not aware of Outlook previously being attacked at this scale.

We know some resources were inaccessible for some, but not others. This often happens with DDoS of globally distributed systems, Williams added. He said Microsoft's apparent unwillingness to provide an objective measure of customer impact probably speaks to the magnitude.

As for Storm-1359's identity, Williams said he doesn't think Microsoft knows yet. That would not be unusual. Cybersecurity sleuthing tends to take time and even then can be a challenge if the adversary is skilled.

Pro-Russian hacking groups including Killnet which the cybersecurity firm Mandiant says is Kremlin-affiliated have been bombarding government and other websites of Ukraine's allies with DDoS attacks. In October, some U.S. airport sites were hit.

Edward Amoroso, NYU professor and CEO of TAG Cyber, said the Microsoft incident highlights how DDoS attacks remain a significant risk that we all just agree to avoid talking about. It's not controversial to call this an unsolved problem.

He said Microsoft's difficulties fending of this particular attack suggest a single point of failure. The best defense against these attacks is to distribute a service massively, on a content distribution network for example.

Indeed, the techniques the attackers used are not old, said U.K. security researcher Kevin Beaumont. One dates back to 2009, he said.

Serious impacts from the Microsoft 365 office suite interruptions were reported on Monday June 5, peaking at 18,000 outage and problem reports on the tracker Downdetector shortly after 11 a.m. Eastern time.

On Twitter that day, Microsoft said Outlook, Microsoft Teams, SharePoint Online and OneDrive for Business were affected.

Attacks continued through the week, with Microsoft confirming on June 9 that its Azure cloud computing platform had been affected.

On June 8, the computer security news site BleepingComputer.com reported that cloud-based OneDrive file-hosting was down globally for a time.

Microsoft said at the time that desktop OneDrive clients were not affected, BleepingComputer reported.

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :MicrosoftcybersecurityTechnology

First Published: Jun 18 2023 | 6:39 AM IST

Next Story