Microsoft says Russian state-sponsored hackers Midnight Blizzard accessed some of its “source code repositories and internal systems” following the January hack
and the Attack Isn't Over Pranav Dixit / Business Today : Microsoft discloses source code theft by Russian hackers Michael Kan / PCMag : Microsoft: Russian Hackers Accessed Company Source Code Jak Connor / TweakTown : Microsoft officially announces its under attack by hackers being paid by Russia Interesting Engineering : Microsoft reveals new wave of attacks by Russia's Midnight Blizzard Sophie Kiderlin / CNBC : Microsoft says a Russian hacking group is still trying to crack into its systems The Irish Times : Microsoft claims Russian-sponsored hackers trying to breach systems Kevin Collier / NBC News : Microsoft says it's struggling to fight off Russian cyberspies who stole company secrets Lucian Constantin / CSO : Microsoft email breach: Attackers accessed internal systems, source code Muhammad Qasim / Appuals : Microsoft Claims Russian Hackers Gained Access to its Source Code via Email Breach Jarin Noshin / International Business Times : Microsoft Reveals Extensive Hack by Russian State-Backed Hackers Matt Milano / WebProNews : Microsoft Says Source Code Stolen In Attack By Nation-State Actor Jonathan Lamont / MobileSyrup : Microsoft says hackers stole source code after spying on executive emails Chris Morris / Fast Company : Microsoft says Russian hackers continue to attack—and stole some of its source code Kevin Okemwa / Windows Central : Microsoft falls victim to yet another deceitful exploit by cybercriminals in less than 2 months Ryan Naraine / SecurityWeek : Microsoft Says Russian Gov Hackers Stole Source Code After Spying on Executive Emails Devesh Beri / MSPoweruser : Microsoft: Russians went beyond email spying and resulted in stolen source code Usman Qureshi / iPhone in Canada Blog : Russian Hackers Stole Microsoft Source Code in Executive Espionage Sam Sabin / Axios : Russian hackers continue to target Microsoft, company says Julia Shapero / The Hill : Microsoft says Russian hackers trying to use stolen ‘secrets’ to breach systems John Callaham / Neowin : Microsoft says a Russian hacker group got access to some of its source code repositories Kyt Dotson / SiliconANGLE : Microsoft says Russian-sponsored group Midnight Blizzard attempted another breach of its systems Matt Novak / Gizmodo : Microsoft Under Constant Attack by Russian Hackers, Filing Says Jonathan Greig / The Record : Microsoft: Russians are using stolen information to breach company's systems Tom Ivan / Video Games Chronicle : Microsoft says Russian state-backed hackers have accessed its source code and internal systems Tara Seals / Dark Reading : Russia-Sponsored Cyberattackers Infiltrate Microsoft's Code Base Ed Targett / The Stack : Microsoft customers are being targeted after Redmond's source code, secrets were stolen Solomon Klappholz / ITPro : Microsoft says Midnight Blizzard hacker group accessed source code and internal systems in January cyber attack Lawrence Bonk / Engadget : Russian state-sponsored hackers keep trying to infiltrate Microsoft Rounak Jain / Benzinga : Microsoft Says Russian Hackers Stole Code After Spying On Top Executives: Attack Still ‘Ongoing’ Dean Seal / Wall Street Journal : Microsoft Still Facing Intrusions From Russian-Sponsored Hacking Group Jamie Tarabay / Bloomberg : Russian Hackers Are Weaponizing Stolen Microsoft Passwords Akash Sriram / Reuters : Microsoft says Russian-state sponsored hackers have been able to access internal systems Mastodon: Paul Chambers / @paul@oldfriends.live : What could go wrong when the nation-state hackers with previous, and current, nefarious and evil intent have some of the source code to one of the most used operating system in the world? — 🔗 Microsoft says Russian hackers stole source code after spying on its executives … Bluesky: Chirag Mehta / @chirag.bsky.social : This doesn't look good. Downstream impact of a breach could be devastating, and can last for a long period of time. Even if the breach itself is not that material, it could enable multiple future breaches. Attacks, or cybersecurity, are not a one-off concept. [embedded post] @scriban.bsky.social : Seems less than ideal. [embedded post] X: @haxrob : @BushidoToken Not the first time SVR has have been found rummaging about in MS's source repos. As per MS's statement then: principle of least privilege does not apply to (viewable) access to source code. It's an age old debate, but one worth revisiting IMHO. https://msrc.microsoft.com/... [image] Nathan McNulty / @nathanmcnulty : I'm often hard on Microsoft because I know they can do better and sometimes decide not to I try really hard to have a well balanced view Stealing source code is not as big of a deal as you think. Most Microsoft employees have access, and they don't consider it a security risk. Shomik Ghosh / @shomikghosh21 : One hack can have long-reaching consequences as hackers mine the data over time https://www.reuters.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: Russian government hackers (Midnight Blizzard/SVR) keep hacking into Microsoft systems, the company revealed today. The hackers are using information stolen last year to continue their attacks targeting source code and company systems. https://techcrunch.com/... Tom Warren / @tomwarren : Microsoft says Russian hackers stole source code after spying on some of its executives. The hackers got into Microsoft executive email accounts and have now accessed the company's source code repositories and internal systems. Details below 👇 https://www.theverge.com/... LinkedIn: Bob Young : It is childishly naive - no, dangerously naive - to continue the current global trend towards data centralization and information processing centralization. … Subhash P. : Our teams have posted an update about the Russian state sponsored campaign against Microsoft. — https://lnkd.in/... #microsoft #msrc #hunt #microsoftsecurity Forums: r/worldnews : Russian state-backed hackers accessed Microsoft's core software systems, company says | CNN Business r/technology : Microsoft says Russian hackers breached its systems, accessed source code r/technology : Microsoft says Kremlin-backed hackers accessed its source and internal systems r/PrepperIntel : Other posts headline: “Microsoft says Russian hackers stole source code after spying on its executives” r/news : Russian hackers breached key Microsoft systems r/tech : Microsoft says Russian hackers stole source code after spying on its executives r/technews : Russian spies keep hacking into Microsoft in ‘ongoing attack,’ company says Msmash / Slashdot : Microsoft Says Russian Hackers Stole Source Code After Spying On Its Executives
Context & Ripple Effects
The incident expands a campaign Microsoft had initially described as an intrusion into employee email accounts, including executives’ accounts. Microsoft later detailed the group’s breach techniques in its account of Midnight Blizzard’s intrusion methods, making this disclosure significant as evidence that the attackers moved beyond mailbox access.
It also follows Microsoft’s disclosure that the Russia-linked group had accessed employee emails beginning in late 2023, a campaign tied in related coverage to the group’s earlier breach of Microsoft employee email. Microsoft says the campaign remains active and that stolen information is being used in continued access attempts.
First-order effects
- Microsoft must treat the affected repositories and internal systems as potentially exposed while continuing to defend against follow-on intrusion attempts.
- Midnight Blizzard gains information that could help it analyze Microsoft’s products or internal environment; the reported impact is source-code and systems access, not a confirmed compromise of customers or products.
Second-order effects
- Microsoft’s customers and security teams may give added weight to alerts and guidance related to this campaign, because stolen internal information can make targeting and social engineering more credible.
- Other large software providers face pressure to harden privileged email, repository, and internal-system access together rather than treating an email breach as an isolated event.
Third-order effects
- If state-backed groups can repeatedly convert identity-system access into source-code and internal-system visibility, software companies will increasingly treat developer infrastructure as a national-security-grade security boundary.
- The episode reinforces a broader shift from one-time breach disclosure toward persistent-campaign response, where stolen data can extend an intrusion’s operational life even after initial access is discovered.
The trend: State-backed cyber campaigns are increasingly exploiting identity and collaboration access as a bridge into the software-development and internal systems that underpin major platforms.