Microsoft Could Reap Over $150 Million in New US Cybersecurity Spending Despite Recent Hacks

A recent hack that affected thousands of servers exploited unknown flaws in the way those servers handled web versions of Microsoft Outlook email.

Advertisement
By Reuters | Updated: 15 March 2021 17:23 IST
Highlights
  • Microsoft products have been under scrutiny since the SolarWinds hack
  • Last hack via Microsoft Exchange affected thousands of servers worldwide
  • Microsoft had said it prioritises fixing attacks it sees in wide use

Microsoft has turned security offerings into a significant source of revenue

Photo Credit: Reuters

Microsoft stands to receive nearly a quarter of Covid relief funds destined for US cybersecurity defenders, sources told Reuters, angering some lawmakers who don't want to increase funding for a company whose software was recently at the heart of two big hacks. Congress allocated the funds at issue in the COVID relief bill signed on Thursday after two enormous cyberattacks leveraged weaknesses in Microsoft products to reach into computer networks at federal and local agencies and tens of thousands of companies. One breach attributed to Russia in December grabbed emails from the Justice Department, Commerce Department, and Treasury Department.

The hacks pose a significant national security threat, frustrating lawmakers who say Microsoft's faulty software is making it more profitable.

Advertisement

"If the only solution to a major breach in which hackers exploited a design flaw long ignored by Microsoft is to give Microsoft more money, the government needs to re-evaluate its dependence on Microsoft,” said Oregon Senator Ron Wyden, a leading Democrat on the intelligence committee.

"The government should not be rewarding a company that sold it insecure software with even bigger government contracts."

Advertisement

Microsoft previously said it prioritises fixing attacks that it sees in wide use.

A draft spending plan by the Cybersecurity Infrastructure Security Agency allocates more than $150 million of their new $650 million funding for a "secure cloud platform," according to documents seen by Reuters and people familiar with the matter.

Advertisement

More precisely, the money has been budgeted for Microsoft, according to four people briefed on the choice, largely to help other federal agencies upgrade their existing Microsoft deals to improve the security of their cloud systems.

A CISA spokesman declined to comment.

A key service Microsoft provides, known as activity logging, allows its clients to keep watch on data traffic within their part of the cloud and spot inconsistencies that could reveal hackers at work.

Advertisement

Officials have sought access to Microsoft's premium tracking capability after discovering the lack of logs made it much harder to investigate recent hacks tied to nation-states.

Microsoft said Sunday that while all its cloud products have security features, "larger organizations may require more advanced capabilities such as a greater depth of security logs and the ability to investigate those logs and take action." It did not address the fairness issues raised by lawmakers.

While some senior US cyber officials feel they have no choice but to pay up, Wyden and three other lawmakers have publicly raised concerns about the plan.

'Raw deal'

Most major software has been penetrated by well-financed teams of hackers at one time or another, but the ubiquity of Microsoft's products makes it a prime target.

The alleged Russian spying, known for exploiting software from SolarWinds, hit nine government agencies and 100 private companies, many of whom were exploited through manipulation of a Microsoft system.

More recent sprawling hacks into tens of thousands of servers around the world running Microsoft Exchange by a handful of attackers, including some tied to the Chinese government, relied on four previously unknown flaws in the way those servers handled web versions of Outlook email. China has denied backing the attacks.

In a hearing on the SolarWinds breach on February 26, Rhode Island Congressman Jim Langevin challenged Microsoft President Brad Smith about charging extra for logging, asking: “Is this a profit center for Microsoft, or is it a service being provided at cost to the customers?”

“We are a for-profit company,” Smith responded. “Everything we do is designed to generate a return, other than our philanthropic work.”

Microsoft has turned security offerings into a significant source of revenue, with the business generating $10 billion annually, up 40 percent from the previous year.

Representative Dutch Ruppersberger of the House appropriations committee said Congress must look into "why security is an afterthought in the procurement process" and move away from approving only the lowest bidders.

The government could impose new regulations, said Curtis Dukes, a former head of the defensive mission at the National Security Agency now at the nonprofit Center for Internet Security, which works closely with CISA. “Maybe with additional size, vendors should have to do more.”


PS5 vs Xbox Series X: Which is the best "next-gen" console in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Infinix Smart 20 Launched in India With a 7.7mm Slim Body, Ultra Link Support
  2. How to Watch WWDC 2026 Live on YouTube, Apple TV, and More
  3. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  4. Infinix Hot 70 Pro India Launch Timeline, Key Specifications Leaked
  5. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  6. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  7. Everything Announced at Xbox Games Showcase: Senua, Persona 6 and More
  8. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  9. WWDC 2026 Keynote Said to Be Tim Cook's Final Appearance as Apple CEO
  1. OnePlus Turbo 6X Series Launch Date Announced Along With Key Specifications, Features
  2. WWDC 2026 Keynote Said to Be Tim Cook's Final Appearance as Apple's CEO During an Event
  3. Infinix Smart 20 Launched in India With MediaTek Helio G81 Ultimate SoC, Slim 7.7mm Profile: Price, Features
  4. Infinix Hot 70 Pro India Launch Timeline Leaked; Could Feature Dimensity 7100 Chip, 6,000mAh Battery
  5. Bitcoin Rebounds Above $62,000 as Buyers Return at Lower Prices Despite ETF Outflow Concerns
  6. Samsung Galaxy S26 FE WPC Database Listing Reveals Design, Qi2 Wireless Charging Support
  7. Apple's Foldable iPhone Seen in New Images of Dummy Units That Reveal Design
  8. Samsung Galaxy S27 Pro Leak Hints at Display Size, Tipped to Launch With 5,000mAh Battery
  9. Samsung Galaxy A27 Leaked in New Mint Colour Option Ahead of Anticipated Launch
  10. Vivo X Fold 6 Confirmed to Launch in China Soon With OriginOS 6 Fold Skin, New AI Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.