Recent reports have revealed that both China and Russia have been successful in breaching Microsoft's security systems, leading to significant concerns regarding the safety of sensitive data and login credentials. The US Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive following the confirmation that Russian-backed hackers had stolen emails exchanged between federal agencies and Microsoft, potentially compromising users' login information.
The directive mandates the affected agencies to promptly assess the extent of the breach by analyzing the stolen emails for any signs of leaked sensitive data or login details. These agencies have been instructed to reset their passwords and authentication tokens by April 30 to mitigate the risks posed by the breach. However, the specific federal agencies impacted by the breach were not disclosed by CISA.