---
title: "Mimecast Certificate Compromised by Hackers For Microsoft Authentication | DuoCircle"
description: "Disclosed last week by Mimecast, a threat actor has compromised the certificate which was used to authenticate several products to Microsoft 365 Exchange Web."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/mimecast-certificate-compromised-by-hackers/"
---

Quick Answer

In January 2021, Mimecast disclosed that a threat actor compromised the certificate used to authenticate its Sync and Recover, Continuity Monitor, and Internal Email Protect (IEP) products to Microsoft 365 Exchange Web Services. Microsoft notified Mimecast and blocked the certificate on January 18, 2021\. About 10% of Mimecast customers used the affected certificate-based connection, and only a low single-digit number were actually targeted. Mimecast asked impacted customers to immediately delete the connection in their Microsoft 365 tenant and re-establish it using a new certificate. Investigators believe the activity may be linked to the SolarWinds supply chain compromise attributed to Russian actors associated with Turla.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fmimecast-certificate-compromised-by-hackers%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Mimecast%20Certificate%20Compromised%20by%20Hackers%20For%20Microsoft%20Authentication&url=undefined%2Fblog%2Fannouncements%2Fmimecast-certificate-compromised-by-hackers%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fmimecast-certificate-compromised-by-hackers%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fmimecast-certificate-compromised-by-hackers%2F&title=Mimecast%20Certificate%20Compromised%20by%20Hackers%20For%20Microsoft%20Authentication "Share on Reddit") [ ](mailto:?subject=Mimecast%20Certificate%20Compromised%20by%20Hackers%20For%20Microsoft%20Authentication&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fmimecast-certificate-compromised-by-hackers%2F "Share via Email") 

![Microsoft Authentication](https://media.mailhop.org/duocircle/images/2021/01/spf-validator-9327.jpg) 

_Disclosed last week by Mimecast, a threat actor has compromised the certificate_ which was used to authenticate several products to Microsoft 365 Exchange Web Services.

The London-based [email security](/) software company said the certificate used to authenticate its Sync and Recover, Continuity Monitor and Internal Email Protect (IEP) products to Microsoft 365 has been compromised. _Mimecast was informed of the compromise by Microsoft_.

_Mimecast’s stocks have dropped 2.30% down to 44 per share this week and are still dropping which is the lowest since Dec 15_. Mimecast is declining to answer questions about whether the threat actor who **injected malicious code** into the SolarWinds Orion network monitoring tool was the same threat actor that compromised its certificate.

_About 10% of customers use the compromised connection according to Mimecast_ and of those that use the connection, only “a low single digit number” were actually targeted. Mimecast said that they have already contacted the targeted tenants to **fix the issue** and a third party forensics firm has been called to help investigate the incident.

[![immediately delete the connection](https://media.mailhop.org/duocircle/images/2021/01/spf-record-generator-6472.jpg)](https://media.mailhop.org/duocircle/images/2021/01/spf-record-generator-6472.jpg)

Mimecast has asked the 10% of its customers who are using this certificate-based connection to “immediately delete the connection within their **Microsoft Office 365 tenant** and make a new certificate-based connection using the new certificate” that they have created.

_“The security of our customers is always our top priority,”_ Mimecast said in a statement issued Tuesday morning. “We have engaged a third-party forensics expert to assist in our investigation, and we will work closely with Microsoft and law enforcement as appropriate.”

“We can confirm that a certificate provided by Mimecast was compromised by a sophisticated actor, this certificate enables their customers to connect certain Mimecast applications to their **M365 tenant**. At Mimecast’s request, we are blocking this certificate on Monday, January 18, 2021.” in a statement by a Microsoft spokesperson according to [CRN](https://www.crn.com/news/security/hackers-compromise-mimecast-certificate-for-microsoft-authentication).

According to [Reuters](https://www.reuters.com/article/us-global-cyber-mimecast/email-security-firm-mimecast-says-hackers-hijacked-its-products-to-spy-on-customers-idUSKBN29H22K), cybersecurity investigators believe that the attack may have been closely related to the recently disclosed [supply chain attack](https://www.securityweek.com/continuous-updates-everything-you-need-know-about-solarwinds-attack) on the U.S. Software Vendor, SolarWinds and a few sensitive U.S. government agencies.

_The SolarWinds hack resulted in malicious software updates that were rolled out to around 18,000 of the company’s customers_. The threat actors also delivered other payloads to other several private and government organizations that showed an interest.

[![malware](https://media.mailhop.org/duocircle/images/2021/01/spf-permerror-6518.jpg)](https://media.mailhop.org/duocircle/images/2021/01/spf-permerror-6518.jpg)

The SolarWinds hack that was uncovered last month was believed to be the work of Russian cyberspies. The U.S. Government believes that Russia is behind the attack and the [malware](https://threatpost.com/solarwinds-hack-linked-turla-apt/162918/) used is related to **Turla APT** which is a known Russian cyberspy group.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Mimecast Certificate Compromised by Hackers For Microsoft Authentication","description":"Disclosed last week by Mimecast, a threat actor has compromised the certificate which was used to authenticate several products to Microsoft 365 Exchange Web.","url":"https://www.duocircle.com/blog/announcements/mimecast-certificate-compromised-by-hackers/","datePublished":"2021-01-20T18:24:43.000Z","dateModified":"2025-05-13T12:52:06.000Z","dateCreated":"2021-01-20T18:24:43.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/mimecast-certificate-compromised-by-hackers/"},"articleSection":"announcements","keywords":"","wordCount":419,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/01/spf-validator-9327.jpg","caption":"Microsoft Authentication","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Mimecast Certificate Compromised by Hackers For Microsoft Authentication","item":"https://www.duocircle.com/blog/announcements/mimecast-certificate-compromised-by-hackers/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Mimecast Certificate Compromised by Hackers For Microsoft Authentication","item":"https://www.duocircle.com/blog/announcements/mimecast-certificate-compromised-by-hackers/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Mimecast Certificate Compromised by Hackers For Microsoft Authentication","description":"Disclosed last week by Mimecast, a threat actor has compromised the certificate which was used to authenticate several products to Microsoft 365 Exchange Web.","url":"https://www.duocircle.com/blog/announcements/mimecast-certificate-compromised-by-hackers/","datePublished":"2021-01-20T18:24:43.000Z","dateModified":"2025-05-13T12:52:06.000Z","dateCreated":"2021-01-20T18:24:43.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/mimecast-certificate-compromised-by-hackers/"},"articleSection":"announcements","keywords":"","wordCount":419,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/01/spf-validator-9327.jpg","caption":"Microsoft Authentication","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
