• News/
  • https://www.bleepingcomputer.com/news/security/russian-hackers-breached-microsoft-to-steal-corporate-emails/

Russian hackers breached Microsoft to steal corporate emails

BleepingComputer
·
Lawrence Abrams
·
Published Jan 20, 2024
·
Updated

Microsoft disclosed Friday night that some of its corporate email accounts were breached and data stolen by the Russian state-sponsored hacking group Midnight Blizzard. The company detected the attack on January 12th, with Microsoft initiating its response to investigate, disrupt, and mitigate the breach. Their investigation has determined that they were breached by the threat actor known as Midnight Blizzard, aka Nobelium or APT29. Microsoft says that the threat actors breached their systems in November 2023 when they conducted a password spray attack to gain access to a legacy non-production test tenant account. Using this account's permissions, Nobelium was able to access a small percentage of Microsoft's corporate email accounts for over a month, including members of the leadership team and those in the cybersecurity and legal departments. This access allowed the attackers to steal emails and attachments from the corporate accounts. "The investigation indicates they were initially targeting email accounts for information related to Midnight Blizzard itself," the Microsoft Security Response Center shared in a report on the incident. "We are in the process of notifying employees whose email was accessed." Microsoft reiterates that this breach was not caused by a vulnerability in their products and services but rather by a brute force password attack on their accounts. While Microsoft is still investigating the breach, they said they will share additional details as appropr...

Read full article

Affected Software

4 affected components
Microsoft Azure
Microsoft Intune
Microsoft Exchange
Microsoft Outlook
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203