Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Pro-Iran hackers claim Microsoft 365 outage, vow latest attack is ‘only a small part of what is to come’

(Image by David Yu from Pixabay)

By Bridget Johnson

Pro-Iran hackers who claimed to have disrupted Microsoft 365 in the early days of the war said Thursday that they came back for another round of “targeting systems managed by the West that are actively used to serve the enemy by processing data and assisting in carrying out attacks.”

Reports of problems with Microsoft 365 began climbing at Downdetector at 10:25 a.m. on Thursday, peaking just after 11 a.m. and persisting throughout the afternoon. Users reported inability to access SharePoint and OneDrive, and issues with services including Microsoft Teams.

“We’ve confirmed some users in North America are experiencing issues accessing or using various Microsoft 365 services,” Microsoft posted on X at 11:56 a.m. “We’re analyzing service telemetry and diagnostic data to isolate the source of impact.”

At 4:09 p.m., the company said it had “completed reverting the networking update and confirmed through service telemetry and customer reports that this issue is resolved.”

The Islamic Cyber Resistance in Iraq – 313 Team first posted on its Telegram channel at 11:39 a.m. that it had “launched a massive and sophisticated cyberattack targeting the main servers of the Microsoft SharePoint network.” The hackers subsequently posted images of Downdetector reports and of Microsoft’s X posts.

“We continue to attack Microsoft 365’s main servers, and outages persist on Microsoft SharePoint servers despite mitigation efforts,” 313 Team claimed in a 1:02 p.m. update. “We will continue to avenge form the killers of Ayatollah Khamenei.” They noted in a 1:18 p.m. post that Microsoft was attempting to mitigate the attacks by “rerouting the massive and sophisticated traffic” from 313 Team’s attack to new servers.

At 4:30 p.m., after Microsoft said it had resolved the issue, 313 Team issued a statement claiming they conducted a “specialized operation” targeting the Microsoft 365 servers.

“These attacks carried out by your brothers are only a small part of what is to come, and they will shatter the prestige of the global companies that finance and support wars in the Middle East,” the hackers continued, adding that “the enemy will have no servers left in cyberspace that our attacks will not strike with force.”

On March 16,  313 Team claimed to have “launched a cyberattack targeting Microsoft 365 servers, completely shutting down the website” for five hours. 

Since the U.S. and Israel first attacked Iran in February, 313 Team has claimed to have hit various companies including Bluesky, eBay, Spotify, X and more with DDoS attacks.

The group claimed responsibility for a United Airlines website outage Wednesday night that left users reporting an inability to log in, check in or change flights.

The hackers said they continued the attack for 30 minutes. User reports of trouble at Downdetector peaked at 8:55 p.m. and 10:10 p.m. Wednesday, with reports trickling off in the early morning hours. “Our Technology teams are aware of the issue and are actively working to resolve it as quickly as possible,” the United Airlines X account posted at 11:22 p.m. in response to a customer reporting that she received error messages when trying to login via app or desktop.

On Sunday, 313 Team said it targeted the Airbnb website, which reflected an “access denied” message at one point. 

313 Team claimed late last month to have conducted “a sophisticated cyberattack targeting the U.S. National Weather Service” that “caused intermittent outages and slowed down the website’s operations” and said they were behind the outage of an incident response platform that alerts residents and response teams during disasters, attacks, public health emergencies and more.

On July 12, 313 Team claimed on their Telegram channel that they were behind a Navy Federal Credit Union app outage. The previous day, the hackers claimed to have disrupted the ABC News website.

Last week, the group said they targeted the n8n workflow automation platform and “completely disabled the login interface.”

Since then, 313 Team claimed to have targeted Nafath, the national digital identity platform in Saudi Arabia, and then turned its attention to the Saudi Ministry of Human Resources and Social Development’s Qiwa workforce management platform in what they said was a multi-day attack. “We want to reaffirm our unwavering support for the Republic of Yemen and the Ansar Allah movement in breaking the unjust blockade imposed by the illegitimate Saudi regime on the dear Yemeni people,” the group said Friday.

Click to listen highlighted text!