Microsoft Corporate Email Accounts Compromised by Midnight Blizzard
Incident Impacts | Data Theft |
---|---|
Affected Sector | Technology |
Associated Intrusion Sets | Midnight Blizzard |
Beginning in late November 2023, the Midnight Blizzard intrusion set (linked to Russian Foreign Intelligence, SVR) compromised Microsoft's corporate systems.
The actor was able to "access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents."
Further investigation by Microsoft found that Midnight Blizzard used exfiltrated information in further attempts to gain access to other internal systems and data (including source code).
Cyber Threat Graph Context
Explore how this cyber incident relates to the wider threat graph
Microsoft Corporate Email Accounts Compromised by Midnight Blizzard Threat Reports
Midnight Blizzard: Guidance for responders on nation-state attack
Following a compromise of Microsoft corporate systems by Midnight Blizzard which was detected on 12th January 2024, this blog post outlines ...