---
title: Microsoft Takes Unusual Step After 'Aggressive' Cyber Attack Campaign
description: Microsoft phishing attack example. The tech giant's unusual step after an aggressive phishing campaign.
---

[SecureWorld News ](https://www.secureworld.io/industry-news)

# [Microsoft Takes Unusual Step After 'Aggressive' Cyber Attack Campaign](https://www.secureworld.io/industry-news/microsoft-phishing-attack-example)

 Written by [SecureWorld News Team](https://www.secureworld.io/industry-news/author/secureworld-news-team) | Tue | Dec 4, 2018 | 4:14 PM Z

Microsoft says the cyber attack started the morning of Wednesday, November 14, 2018.

It came to thousands of users in the form of a phishing email that looked like it was a Microsoft OneDrive message from someone at the U.S. State Department:

The tech giant says it had the markings of a nation-state attack, and it was launched aggressively around the globe with many targets in the United States, as you see here:

### **Who was targeted in this phishing attack?**

"Our sensors revealed that the campaign primarily targeted public sector institutions and non-governmental organizations like think tanks and research centers, but also included educational institutions and private-sector corporations in the oil and gas, chemical, and hospitality industries."

### **Microsoft takes an unusual step**

Microsoft took the rare step of *notifying individual accounts that were being targeted*, through its Defending Democracy Program which it [announced](https://blogs.microsoft.com/on-the-issues/2018/04/13/announcing-the-defending-democracy-program/) earlier in 2018.

"... due to the nature of the victims, and because the campaign features characteristics of previously observed nation-state attacks, Microsoft took the step of notifying thousands of individual recipients in hundreds of targeted organizations."

You can read [technical details of the phishing attack here](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/analysis-of-cyberattack-on-u-s-think-tanks-non-profits-public-sector-by-unidentified-attackers/), if you would like to know more.

[View full post](https://www.secureworld.io/industry-news/microsoft-phishing-attack-example)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SecureWorld News Team"
  },
  "dateModified" : "2018-12-04T19:58:29.191Z",
  "datePublished" : "2018-12-04T16:14:05Z",
  "headline" : "Microsoft Takes Unusual Step After 'Aggressive' Cyber Attack Campaign",
  "image" : {
    "@type" : "ImageObject",
    "height" : 715,
    "url" : "https://info.secureworldexpo.com/hubfs/phishing-attack-map-microsoft.gif",
    "width" : 1001
  },
  "mainEntityOfPage" : "https://www.secureworld.io/industry-news/microsoft-phishing-attack-example",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/2221756/Logos/SWE/SWE_logo_full-long_forWHITEbackgrounds.jpg",
      "width" : 304.46954
    },
    "name" : "SecureWorld News"
  }
}
```