Credential theft
Microsoft corporate email breach by Midnight Blizzard (Nobelium / APT29)
Primary Source βIncident Details
Midnight Blizzard (Russian SVR, also known as Nobelium/Cozy Bear/APT29) conducted a password spray attack against a legacy Microsoft test tenant account with no MFA enabled in November 2023. Using that account’s permissions, attackers accessed a small percentage of corporate email accounts including senior executives and staff in cybersecurity and legal departments. Detected 12 January 2024, disclosed 19 January 2024. Subsequent investigation (March 2024) revealed attackers also accessed some Microsoft source code repositories and internal systems using information exfiltrated from the corporate emails. CISA emergency directive issued. This was part of a broader Midnight Blizzard campaign targeting governments and tech companies.
Technical Details
- Initial Attack Vector
- CWE-307: Improper Restriction of Excessive Authentication Attempts (password spray attack against a legacy non-production test tenant account lacking MFA)
- Vendor / Product
- Microsoft corporate Office 365 email / source code repositories
Timeline
- 2023-11-01 Breach occurred
- 2024-01-19 Publicly disclosed
- 2024-03-08 Customers notified