Yeah, this story isn't over yet. It has all the hallmarks of drip feeding bad news.
- First it was a legacy system.
- Then it was internal Microsoft corporate email.
- Then it was source code repositories.
- Then it was emails between Microsoft and Government agencies
- Now it's password credentials sent by Microsoft to those same agencies.
What's unclear is the source of those credentials emails. Are they from employees at Microsoft sending credentials to clients, or is it automatically generated password reset emails that were exfiltrated?
They've apparently known about this since early January, but it appears that the infiltration has been ongoing since November. It's still happening today.
That's nearly SIX MONTHS of access to internal Microsoft systems.
Just spit balling, but here's a question that nobody is asking:
How do you know when they're no longer in your system?
Here's another:
How do you know that nothing extra was left behind?
Or this one:
Why should anyone ever trust Microsoft ever again?
Or:
What guarantees can Microsoft ever make from here on out?