Microsoft says Midnight Blizzard read senior leaders' corporate email

Organization
Microsoft
Exploit
Credential Compromise
Industry
Technology

Microsoft disclosed on January 19, 2024 that its security team had detected a nation-state attack on its corporate systems a week earlier, on January 12. The company attributed the intrusion to Midnight Blizzard, the Russian state-sponsored group it also tracks as Nobelium and which other researchers call APT29 or Cozy Bear.

According to Microsoft, the attackers began in late November 2023 with a password spray attack against a legacy, non-production test tenant account that was not protected by multifactor authentication. They then used that account's permissions, including a deprecated OAuth application, to reach what Microsoft described as a very small percentage of its corporate email accounts. Residential proxy networks were used to obscure the source of the traffic.

The accounts reached included those of members of Microsoft's senior leadership team and staff in its cybersecurity, legal and other functions. Some emails and attached documents were exfiltrated. Microsoft said the group appeared to be seeking information about what Microsoft knew about Midnight Blizzard itself, and that it had found no evidence of access to customer environments, production systems, source code or AI systems.

Microsoft said it would apply current security standards to legacy systems and accelerate work under its Secure Future Initiative. Security researchers quoted by Cybersecurity Dive criticized the absence of multifactor authentication on the test account. Microsoft said in March 2024 that Midnight Blizzard was using information exfiltrated from its corporate email systems to gain unauthorized access, and that this had included access to some of the company's source code repositories and internal systems.

Sources