Microsoft says Russia-linked group Midnight Blizzard hacked some employee emails beginning in November 2023; the same group breached SolarWinds as early as 2019
- Nation-state spies previously conducted cyber-espionage on US — Targeted breaches hit Microsoft executives, cyber team
Bloomberg
Context & Ripple Effects
The disclosure ties a new intrusion at Microsoft to the same Russia-linked actor associated with the SolarWinds breach, extending a recurring concern from software supply-chain compromise to high-value corporate communications. Microsoft subsequently said the activity reached some source-code repositories and internal systems, broadening the significance of the initial email-access report.
Related coverage also describes suspected Midnight Blizzard mailbox data theft at HPE, suggesting the issue is not confined to one vendor but concerns a shared class of strategically valuable enterprise targets.
First-order effects
- Microsoft must investigate the affected employee mailboxes, assess what information was exposed, and contain the actor’s access while communicating risk to customers and partners whose information may have appeared in those accounts.
- The disclosure puts renewed scrutiny on Microsoft’s identity, email, and internal-security controls because the actor is linked in the coverage to the earlier SolarWinds compromise.
Second-order effects
- Other large technology and enterprise IT providers face pressure to review privileged-mailbox protections and hunting procedures; the reported HPE incident provides a relevant parallel mailbox-compromise case.
- Customers and public-sector organizations that rely on major software vendors may reassess third-party access and incident-notification expectations, especially where executive or security-team correspondence is involved.
Third-order effects
- If repeated campaigns against major IT suppliers persist, cyber risk management will increasingly treat vendor communications and internal development environments as strategic attack surfaces, not merely operational systems.
- The pattern reinforces demand for security practices that limit the value of a single compromised identity or mailbox, though the available coverage does not establish whether providers will converge on a common standard.
The trend: State-linked espionage campaigns are increasingly testing the security perimeter of major technology suppliers and the sensitive internal information concentrated inside them.
Related: Microsoft · Russia · SolarWinds · Microsoft’s later disclosure of source-code and systems access · HPE’s reported Midnight Blizzard mailbox incident · Microsoft’s account of the group’s breach techniques
Related Coverage
- Hackers breached Microsoft to find out what Microsoft knows about them TechCrunch · Lorenzo Franceschi-Bicchierai
- Microsoft Executives' Emails Breached by Russia Hackers Hackread · Waqas
- Microsoft says Russian hackers attacked it to find information about themselves Business Insider · Lakshmi Varanasi
- Microsoft network breached through password-spraying by Russian-state hackers Ars Technica · Dan Goodin
- Microsoft says state-sponsored Russian hacking group accessed email accounts of senior leaders CNN · Catherine Thorbecke
- Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard Microsoft Security Response Center
- Microsoft says state-sponsored hackers spied on its executives iTnews
- Microsoft Targeted By Russian State-Sponsored Threat Group Nobelium In Security Breach HotHardware · Nathan Ord
- Microsoft's ‘Senior Leadership’ Emails Were Compromised By Russian Hacker Group PCMag · Emily Price
- Microsoft Says Russian Hackers Breached Senior Execs' Emails The Information · Aaron Holmes
- Microsoft executive emails hacked by Russian intelligence group, company says CNBC
- Microsoft: Our Email Was Hit by ‘Midnight Blizzard’ Newser · Jenn Gidman
- Russian hackers stole Microsoft corporate emails in month-long breach BleepingComputer · Lawrence Abrams
- Microsoft Says Russian Hackers Spied on Its Executives Reuters
- Microsoft says Russian government hackers stole email from its leaders DataBreaches.net
- Microsoft says Russian government hackers stole email from its leaders Washington Post · Joseph Menn
- Microsoft Reports Hack by Nation-State Actor Wall Street Journal · Dean Seal
- Microsoft says Russian intelligence group hacked executives' emails Seattle Business Journal · Alex Halverson
- Microsoft says senior leadership was hacked by Russia-tied group NBC News · Kevin Collier
- Microsoft says ‘Russian state-sponsored’ hackers gained access to ‘a very small percentage of Microsoft corporate email accounts’ PC Gamer · Andy Chalk
- Microsoft Says Senior Executives Hacked By Russian Group CRN · Kyle Alspach
- It's easy to point the finger here, and yes Microsoft certainly made some far reaching security mistakes. — But what's often referred to as basic security is probably in no company in the world in place for all assets. For many reasons, unknwon assets (shadow IT anyone?), conflicting business needs/requirements, etc etc. … @j_opdenakker@infosec.exchange · John Opdenakker
- Even “legacy non-production test ” systems need to be secured and not filled with production data or accounts. And “current security standards” need to apply throughout — > “We will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes” … @marcel@waldvogel.family · Marcel Waldvogel
- I agree with @alex here, Microsoft needs to do a much more public disclosure. — Microsoft staff use Microsoft 365 email with Exchange Online. Eg I was gossi@microsoft.com. — I think MS needs to explain to M365 customers how mailboxes were accessed via password spraying. — https://cybervillains.com/... @GossiTheDog@cyberplace.social · Kevin Beaumont
- I need to set up a calendar entry for Friday night, called Microsoft Hacked Announcements. @GossiTheDog@cyberplace.social · Kevin Beaumont
- As a reminder: some organizations are perpetual targets of high end adversaries. We are all in this fight together. I appreciate the transparency. … Andrew Thompson
- The Microsoft security team detected a nation-state attack on our corporate systems on January 12, 2024, and immediately activated our response process to investigate … Ann Johnson
- Microsoft actions following attack by nation state actor Midnight Blizzard Hacker News
Discussion
-
@mnownews
@mnownews
on threads
The hacking group behind this activity, known in the industry as Midnight Blizzard or APT29, is based in Russia and the UK and US governments have linked it to the country's foreign intelligence service. #MalaysiaNow #MNow #Malaysia #Microsoft #Russia https://www.malaysianow.com…
-
@andy_jabbour
Andy Jabbour
on threads
New threat report from @microsoft: Midnight Blizzard conducts targeted social engineering over Microsoft Teams. ‘has affected fewer than 40 unique global organizations...directed at government, non-government organizations (NGOs), IT services, technology, discrete manufacturing, …
-
@barrebull
Barre Bull
on threads
Microsoft has identified highly targeted social engineering attacks by the threat actor Midnight Blizzard (previously NOBELIUM) using credential theft phishing lures sent as Microsoft Teams chats. https://www.microsoft.com/...
-
@georgescriban
@georgescriban
on threads
Folks may be more familiar with Midnight Blizzard's other/previous identifiers: Nobelium, APT29, Cozy Bear, The Dukes, etc. You'll *definitely* be familiar with their work, including the SolarWinds supply chain attack, and the 2015 DNC hack-and-leak. These guys suck.
-
@alex.stamos
Alex Stamos
on threads
Microsoft just announced that they were breached by the SVR, the same Russian intelligence agency that broke into Solarwinds. This is a big deal, and Microsoft owes all of us a much more detailed description of what happened. https://msrc.microsoft.com/...
-
@SteveBellovin@mastodon.lawprofs.org
Steve Bellovin
on mastodon
@GossiTheDog @adamshostack A lot of fascinating implications here. A successful password spray attack suggests no 2FA and either reused or weak passwords. Access to email accounts belonging to “senior leadership... cybersecurity, and legal” teams using just the permissions of a…
-
@jeremymoskowitz
Jeremy Moskowitz
on x
@SwiftOnSecurity Gotta say.. I don't get it. Ever since forever I've seen MS folks walking around with badges which double as smart cards which act as 2fa devices. How can a password spray therefore get someone's email to open up ??
-
@bushidotoken
Will
on x
Big news, MS hit by Russia again, and it sounds like an SVR counterintelligence mission 👀 Targets 🎯 — MS SLT — Cybersecurity & legal employees — Emails and attachments — Information related to Midnight Blizzard itself (!) https://msrc.microsoft.com/...
-
@schwartzonsec
Michael Schwartz
on x
@klrgrz Sigh... what does well-resourced even mean? And yeah, if you're part of critical infra, watch your back. If not, be concerned about the well resourced criminals vying for a slice of the trillion dollar cybercrime market.
-
@tomwarren
Tom Warren
on x
this Microsoft hack is wild. The most valuable company in the world was breached by Russian hackers just days after it announced a major software security overhaul. Microsoft only discovered the breach last week, and it started at the end of November 😬https://www.theverge.com/ ..…
-
@ericgeller
Eric Geller
on x
Given the method of access (a legacy test account implied to be lacking MFA), Microsoft says it's tightening security on legacy computer systems and warns that this might slow down its work. “This will likely cause some level of disruption while we adapt to this new reality.” [im…
-
@swiftonsecurity
@swiftonsecurity
on x
Microsoft got whacked and slurped 😔 https://msrc.microsoft.com/...
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
NEW: Microsoft disclosed that it got hacked by Russian government hackers. Curiously, the hackers' goal appears to be to find out what Microsoft knows about them. Company says they broke into “a very small [%] of Microsoft corporate email accounts.” https://techcrunch.com/...
-
@klrgrz
@klrgrz
on x
Huge credit to MSFT for their response & transparency, but they hit one of my paint points from my ShmooCon talk. This quote will bias your corporate threat model. When has RU compromised a corporate network outside of espionage/CI type ops? https://msrc.microsoft.com/... [image]
-
@munster_gene
Gene Munster
on x
$MSFT's data breach is a bad read for their security business and a win for $CRWD and $PANW, both Deepwater holdings. If $CRWD gains 2% of Microsofts security business, that increases revenue growth by 14%. If PANW gains 2%, revenue growth increases by 7%.
-
@debugprivilege
@debugprivilege
on x
Interesting! Microsoft detected a nation-state attack on our corporate systems on January 12, 2024, and immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. https://msrc.microsoft.com…
-
@kylealspach
Kyle Alspach
on x
Microsoft exec account hack becomes one of the 1st major incidents for the SEC disclosure rule https://www.crn.com/... “The Company has not yet determined whether the incident is reasonably likely to materially impact the Company's financial condition or results of operations.”
-
@bdsams
Brad Sams
on x
A company with unlimited resources Vs An entity with unlimited time This is quite alarming at how long Microsoft was exposed but also shows that even the most valuable company in the world cannot sustain an impenetrable wall forever.
-
@matthew_pines
Matthew Pines
on x
Microsoft disclosed today that the Russian SVR popped “members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.” https://www.sec.gov/... [image]