Microsoft Corporate Email Accounts Compromised by Midnight Blizzard

Incident Impacts Data Theft
Affected Sector Technology
Associated Intrusion Sets Midnight Blizzard

Beginning in late November 2023, the Midnight Blizzard intrusion set (linked to Russian Foreign Intelligence, SVR) compromised Microsoft's corporate systems.

The actor was able to "access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents."

Further investigation by Microsoft found that Midnight Blizzard used exfiltrated information in further attempts to gain access to other internal systems and data (including source code).

Cyber Threat Graph Context

Explore how this cyber incident relates to the wider threat graph

Microsoft Corporate Email Accounts Compromised by Midnight Blizzard Threat Reports

Report

Midnight Blizzard: Guidance for responders on nation-state attack

Following a compromise of Microsoft corporate systems by Midnight Blizzard which was detected on 12th January 2024, this blog post outlines ...

References