Midnight Blizzard Breach Exposes Security Risks in Legacy Systems
A nation-state backed threat actor group called Midnight Blizzard gained access to some Microsoft corporate emails and documents in November 2023. The attackers used a password spray attack to compromise a legacy test tenant account, which gave them permissions to access a small number of email accounts belonging to senior leadership team members.
The investigation by Microsoft's Security Response Center found that the attackers were initially targeting email accounts for information related to Midnight Blizzard itself. However, there is no evidence that they had any access to customer environments, production systems, source code, or AI systems.
Much like HPE, which was also breached by Midnight Blizzard in May 2023, Microsoft's incident has highlighted the need for thorough incident response plans and threat intelligence monitoring. Microsoft has stated that it will act immediately to apply its current security standards to Microsoft-owned legacy systems and internal business processes, even if these changes might cause disruption.