Credential theft

Microsoft corporate email breach by Midnight Blizzard (Nobelium / APT29)

πŸ“… 2023-11-01 🏒 Microsoft corporate Office 365 email / source code repositories
Primary Source β†—

Incident Details

Midnight Blizzard (Russian SVR, also known as Nobelium/Cozy Bear/APT29) conducted a password spray attack against a legacy Microsoft test tenant account with no MFA enabled in November 2023. Using that account’s permissions, attackers accessed a small percentage of corporate email accounts including senior executives and staff in cybersecurity and legal departments. Detected 12 January 2024, disclosed 19 January 2024. Subsequent investigation (March 2024) revealed attackers also accessed some Microsoft source code repositories and internal systems using information exfiltrated from the corporate emails. CISA emergency directive issued. This was part of a broader Midnight Blizzard campaign targeting governments and tech companies.

Technical Details

Initial Attack Vector
CWE-307: Improper Restriction of Excessive Authentication Attempts (password spray attack against a legacy non-production test tenant account lacking MFA)
Vendor / Product
Microsoft corporate Office 365 email / source code repositories

Timeline

  1. 2023-11-01 Breach occurred
  2. 2024-01-19 Publicly disclosed
  3. 2024-03-08 Customers notified