Last updated 2 months ago
Microsoft, a global technology company, was targeted in a campaign by Russian military intelligence hackers who exploited known vulnerabilities in older Internet routers to harvest authentication tokens from Microsoft Office users. The campaign affected over 18,000 networks, with no specific discovery date provided, but the disclosure occurred in April 2026. No record count or affected user population was quantified, but the scale of network compromise indicates a widespread incident.
The attack chain involved exploiting known flaws in legacy routers to intercept and siphon authentication tokens without deploying any malicious software or code. The threat actor, attributed to Russia's military intelligence units, used this initial access to silently harvest tokens from Microsoft Office users across thousands of networks. The compromised data consisted of authentication tokens, which could be used to bypass multi-factor authentication and gain persistent access to user accounts.
No post-incident details such as regulatory actions, litigation, ransom payments, or remediation milestones were reported in the article.
Exploited known flaws in older Internet routers to intercept authentication tokens
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor