The Brazilian hacker group Prime Suspectz defaced multiple Microsoft-related websites, altering pages for Microsoft operations in the U.K., Mexico, and Saudi Arabia and also hitting the MSNBC Sports Scoreboard site. The attackers replaced normal content with taunting messages, and in the MSNBC case displayed a nuclear explosion image, the group’s logo, and a message in Portuguese. Microsoft and MSNBC said the affected systems were restored quickly after discovery, with MSNBC taking impacted Scoreboard servers offline before returning them to service later the same day.
Microsoft said the compromised subsidiary sites were in some cases operated by third parties, were not connected to the Redmond corporate network, and did not expose consumer or sensitive company data. The incident was reported as at least the ninth known defacement of a Microsoft website tracked by Attrition.org and followed earlier compromises involving Microsoft sites in Brazil, Slovenia, Redmond, and New Zealand. The intrusion method remained under investigation, but the attacks intensified scrutiny of Microsoft’s web security amid broader concern over a serious flaw affecting Windows 2000 Server running IIS 5.0.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft said the defaced subsidiary sites were restored quickly, that some were operated by third parties, and that they were not connected to the Redmond corporate network. The company also said no consumer data was compromised.
After discovering the defacement on Friday morning, MSNBC took the compromised Scoreboard servers offline and restored them by about 11 a.m. PDT. The company said the impacted systems were separate from the main MSNBC site.
Around the same time, Prime Suspectz also defaced the MSNBC Sports Scoreboard site, displaying a nuclear explosion image, the group's logo, and a Portuguese message. MSNBC said the affected servers were operated by a third party and that the main MSNBC site was not affected.
In early May 2001, Prime Suspectz briefly defaced three Microsoft country websites serving the United Kingdom, Mexico, and Saudi Arabia, replacing normal pages with taunting messages. Microsoft said the sites were restored quickly and that no consumer or sensitive data was exposed.
After Microsoft disclosed a serious Windows 2000 IIS vulnerability in the Internet Printing component, exploit template code was published by a hacker known as dark spyrit. The flaw, discovered by eEye Digital Security, could allow remote takeover of vulnerable web servers and raised concern that exploitation would become easier.
CNN's report notes that the Brazilian hacker group Prime Suspectz had previously targeted Microsoft by compromising the Microsoft New Zealand website in January 2001.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
cnet.com
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.