Computer Security: One click to many
More senior colleagues might still recall the regular “clicking” campaigns that were intended to raise security awareness within the Organization among staff and users. With the roll-out of two-factor authentication, such campaigns were dropped. However, the world continues to turn and novel functionality and novel attack vectors try to circumvent our protections. And they have […]
In a recent security breach at CERN, a seemingly harmless email led to a chain reaction of compromised accounts and unauthorized access. The email, which appeared to be routine, requested users to click on a link to a Word document. Unbeknownst to many recipients, this link directed them to a non-CERN domain, setting the stage for a malicious attack.
The attack leveraged Microsoft's cloud configuration, specifically a feature known as "device code authentication." This feature, designed for user convenience by allowing prolonged access without daily logins, inadvertently made it easier for attackers to exploit. By copying a "verification code" displayed on a landing page, a victim unwittingly granted unauthorized access to their account. This breach not only jeopardized the individual's account but also opened the door for further attacks.
Once inside the victim's mailbox, an AI-enabled automation system scanned for additional email addresses, creating a cascade of attacks. The system identified over 5000 potential targets within CERN, sending them tailored emails with plausible hooks such as "Back orders" or "Q'2 EMEA Project." Of these, 108 recipients fell for the ruse, thereby compromising their Microsoft cloud tokens. These victims had to undergo a cumbersome process of re-authenticating via CERN's 2FA-protected Single Sign-On system.
Despite ongoing investigations by CERN's Computer Security Office into measures to prevent such attacks, like revoking device code authentication or reducing its validity period, the organization emphasized the importance of vigilance. They urged all staff and users to scrutinize every email, hovering over URLs and links to verify their legitimacy. Should a link seem suspicious, they advised against clicking, especially if the destination is unknown or unexpected, as was the case with the "mata-asia[.]com" domain.
CERN's Computer Security Office encourages the community to stay informed about security incidents and issues. They invite anyone interested to follow their Monthly Report or visit the official website for further information or assistance. For any queries or help, they can be reached at Computer.Security@cern.ch.
Written by urgent.news from CERN's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
