Hackers Gain Access to Mail Accounts at Microsoft

December 19, 2024

INCIDENT

The Microsoft security team detected a nation-state attack on our corporate systems on January 12, 2024. Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium.

Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.

The investigation indicates they were initially targeting email accounts for information related to Midnight Blizzard itself.

Incident Date

November 27, 2023

Estimated Cost


No cost values disclosed.

Victims

Type of Malware

No Malware identified