/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says Russia-linked group Midnight Blizzard hacked some employee emails beginning in November 2023; the same group breached SolarWinds as early as 2019

- Nation-state spies previously conducted cyber-espionage on US  — Targeted breaches hit Microsoft executives, cyber team

Bloomberg

Context & Ripple Effects

The disclosure ties a new intrusion at Microsoft to the same Russia-linked actor associated with the SolarWinds breach, extending a recurring concern from software supply-chain compromise to high-value corporate communications. Microsoft subsequently said the activity reached some source-code repositories and internal systems, broadening the significance of the initial email-access report.

Related coverage also describes suspected Midnight Blizzard mailbox data theft at HPE, suggesting the issue is not confined to one vendor but concerns a shared class of strategically valuable enterprise targets.

First-order effects

  • Microsoft must investigate the affected employee mailboxes, assess what information was exposed, and contain the actor’s access while communicating risk to customers and partners whose information may have appeared in those accounts.
  • The disclosure puts renewed scrutiny on Microsoft’s identity, email, and internal-security controls because the actor is linked in the coverage to the earlier SolarWinds compromise.

Second-order effects

  • Other large technology and enterprise IT providers face pressure to review privileged-mailbox protections and hunting procedures; the reported HPE incident provides a relevant parallel mailbox-compromise case.
  • Customers and public-sector organizations that rely on major software vendors may reassess third-party access and incident-notification expectations, especially where executive or security-team correspondence is involved.

Third-order effects

  • If repeated campaigns against major IT suppliers persist, cyber risk management will increasingly treat vendor communications and internal development environments as strategic attack surfaces, not merely operational systems.
  • The pattern reinforces demand for security practices that limit the value of a single compromised identity or mailbox, though the available coverage does not establish whether providers will converge on a common standard.

The trend: State-linked espionage campaigns are increasingly testing the security perimeter of major technology suppliers and the sensitive internal information concentrated inside them.

Discussion

  • @mnownews @mnownews on threads
    The hacking group behind this activity, known in the industry as Midnight Blizzard or APT29, is based in Russia and the UK and US governments have linked it to the country's foreign intelligence service.  #MalaysiaNow #MNow #Malaysia #Microsoft #Russia https://www.malaysianow.com…
  • @andy_jabbour Andy Jabbour on threads
    New threat report from @microsoft: Midnight Blizzard conducts targeted social engineering over Microsoft Teams. ‘has affected fewer than 40 unique global organizations...directed at government, non-government organizations (NGOs), IT services, technology, discrete manufacturing, …
  • @barrebull Barre Bull on threads
    Microsoft has identified highly targeted social engineering attacks by the threat actor Midnight Blizzard (previously NOBELIUM) using credential theft phishing lures sent as Microsoft Teams chats. https://www.microsoft.com/...
  • @georgescriban @georgescriban on threads
    Folks may be more familiar with Midnight Blizzard's other/previous identifiers: Nobelium, APT29, Cozy Bear, The Dukes, etc.  You'll *definitely* be familiar with their work, including the SolarWinds supply chain attack, and the 2015 DNC hack-and-leak.  These guys suck.
  • @alex.stamos Alex Stamos on threads
    Microsoft just announced that they were breached by the SVR, the same Russian intelligence agency that broke into Solarwinds.  This is a big deal, and Microsoft owes all of us a much more detailed description of what happened. https://msrc.microsoft.com/...
  • @SteveBellovin@mastodon.lawprofs.org Steve Bellovin on mastodon
    @GossiTheDog @adamshostack A lot of fascinating implications here.  A successful password spray attack suggests no 2FA and either reused or weak passwords.  Access to email accounts belonging to “senior leadership... cybersecurity, and legal” teams using just the permissions of a…
  • @jeremymoskowitz Jeremy Moskowitz on x
    @SwiftOnSecurity Gotta say.. I don't get it. Ever since forever I've seen MS folks walking around with badges which double as smart cards which act as 2fa devices. How can a password spray therefore get someone's email to open up ??
  • @bushidotoken Will on x
    Big news, MS hit by Russia again, and it sounds like an SVR counterintelligence mission 👀 Targets 🎯 — MS SLT — Cybersecurity & legal employees — Emails and attachments — Information related to Midnight Blizzard itself (!) https://msrc.microsoft.com/...
  • @schwartzonsec Michael Schwartz on x
    @klrgrz Sigh... what does well-resourced even mean? And yeah, if you're part of critical infra, watch your back. If not, be concerned about the well resourced criminals vying for a slice of the trillion dollar cybercrime market.
  • @tomwarren Tom Warren on x
    this Microsoft hack is wild. The most valuable company in the world was breached by Russian hackers just days after it announced a major software security overhaul. Microsoft only discovered the breach last week, and it started at the end of November 😬https://www.theverge.com/ ..…
  • @ericgeller Eric Geller on x
    Given the method of access (a legacy test account implied to be lacking MFA), Microsoft says it's tightening security on legacy computer systems and warns that this might slow down its work. “This will likely cause some level of disruption while we adapt to this new reality.” [im…
  • @swiftonsecurity @swiftonsecurity on x
    Microsoft got whacked and slurped 😔 https://msrc.microsoft.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Microsoft disclosed that it got hacked by Russian government hackers. Curiously, the hackers' goal appears to be to find out what Microsoft knows about them. Company says they broke into “a very small [%] of Microsoft corporate email accounts.” https://techcrunch.com/...
  • @klrgrz @klrgrz on x
    Huge credit to MSFT for their response & transparency, but they hit one of my paint points from my ShmooCon talk. This quote will bias your corporate threat model. When has RU compromised a corporate network outside of espionage/CI type ops? https://msrc.microsoft.com/... [image]
  • @munster_gene Gene Munster on x
    $MSFT's data breach is a bad read for their security business and a win for $CRWD and $PANW, both Deepwater holdings. If $CRWD gains 2% of Microsofts security business, that increases revenue growth by 14%. If PANW gains 2%, revenue growth increases by 7%.
  • @debugprivilege @debugprivilege on x
    Interesting! Microsoft detected a nation-state attack on our corporate systems on January 12, 2024, and immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. https://msrc.microsoft.com…
  • @kylealspach Kyle Alspach on x
    Microsoft exec account hack becomes one of the 1st major incidents for the SEC disclosure rule https://www.crn.com/... “The Company has not yet determined whether the incident is reasonably likely to materially impact the Company's financial condition or results of operations.”
  • @bdsams Brad Sams on x
    A company with unlimited resources Vs An entity with unlimited time This is quite alarming at how long Microsoft was exposed but also shows that even the most valuable company in the world cannot sustain an impenetrable wall forever.
  • @matthew_pines Matthew Pines on x
    Microsoft disclosed today that the Russian SVR popped “members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.” https://www.sec.gov/... [image]