Russian State-Sponsored Hackers Breach Microsoft Emails
A nation-state backed threat actor group called Midnight Blizzard accessed some Microsoft corporate emails and documents through compromised email accounts in November 2023.
The attack was not the result of a vulnerability in Microsoft products or services, but rather a password spray attack that used commonly used passwords against many different accounts.
The attackers gained access to a legacy test tenant account, which allowed them to use its permissions to access a small number of corporate email accounts - some belonging to senior leadership team members and others on the cybersecurity and legal teams.
Microsoft has stated that there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems. The company will notify customers if any action is required.