ZeroHour
CyberScooppublished ()ingested @snlyngaas

Microsoft: U.S. presidential campaign, government officials targeted by recent hacking effort

criticalThreat actor exploited in the wildimportance 60
Full article818 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Phosphorus, also known as APT35, has targeted email accounts associated with an unnamed U.S. presidential campaign along with current and former U.S. government officials.

Iran microsoft
(Getty Images)

Microsoft said Friday that an Iranian government-linked hacking group had targeted email accounts associated with an unnamed U.S. presidential campaign, along with current and former U.S. government officials.

The Iranian hackers’ other targets included “journalists covering global politics and prominent Iranians living outside Iran,” said Tom Burt, a corporate vice president at Microsoft.

Over 30 days between August and September, hackers made more than 2,700 “attempts” to identify email accounts belonging to specific customers, Microsoft said. From there, they attacked 241 of those accounts, the company said.

Four accounts were compromised as a result of those attacks. None of the breached accounts were associated with the U.S. presidential campaign or with current or former U.S. government officials, according to Microsoft. The company is working with the affected customers to secure their accounts, Burt said.

While Microsoft did not name the presidential campaign that the Iranian hackers targeted, Reuters reported that it was the Trump campaign. Tim Murtaugh, the Trump campaign’s director of communications, told Reuters the campaign had no indication that its infrastructure was targeted by the hackers.

CyberScoop could not independently confirm that the Trump campaign was targeted by the Iranian hackers. However, a search of public domain records did show that the Trump campaign’s email provider is Microsoft.

The Democratic National Committee on Tuesday sent an advisory to Democratic presidential campaigns flagging the Microsoft discovery. The Iranian hackers have been “attacking personal as well as official work accounts,” the DNC email said. “They create believable spear phishing emails and fake LinkedIn profiles as primary tactics.”

The DNC reiterated that Microsoft had seen the hacking group circumvent two-factor authentication in some cases, and urged campaigns to review a security checklist the DNC previously released.

The activity is the latest reminder that foreign governments will try to interfere in the 2020 U.S. election. On Thursday, the FBI and the Department of Homeland Security advised state election officials that the Russian government could use voter suppression tactics in an attempt to interfere in the 2020 U.S. election.

Burt described the hacking attempts as “not technically sophisticated,” but still clever: attackers gathered a good deal of personal information on their targets and used account recovery features to try to take over some email accounts.

The group, which Microsoft calls Phosphorus, has also been dubbed APT35 or Charming Kitten by cybersecurity companies. The group is known for targeting journalists and activists who focus on Iran.

In March, Microsoft used a court order to seize 99 websites that the hacking group was using to conduct cyberattacks.

Shannon Vavra contributed reporting. 

More Scoops

HOUSTON, TEXAS – FEBRUARY 17: Houston Water Director, Greg Eyerly, leads a tour of The East Water Purification Plant on Monday, Feb. 17, 2025 in Houston. A White House pilot project designed to boost the cybersecurity of water systems was announced on Monday in Texas. (Raquel Natalicchio/Houston Chronicle via Getty Images)

‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help

The six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.”

Programmable Logic Controller PLC System in Industrial Cabinet – stock photo, Ivan Shevchenko, Getty Images

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The FBI and Environmental Protection Agency issued a joint advisory last week confirming attacks at water and wastewater utilities in at least 12 states since July 27. (Getty Images)

Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iran-microsoft-2020-elections/