• News/
  • https://www.theregister.com/2024/03/08/microsoft_confirms_russian_spies_stole/

Microsoft confirms Russian spies stole source code

The Register
·
Jessica Lyons
·
Published Mar 8, 2024
·
Updated

Microsoft has now confirmed that the Russian cyberspies who broke into its executives' email accounts stole source code and gained access to internal systems. The Redmond giant also characterized the intrusion as "ongoing." In an updated US SEC filing and companion security post, Microsoft provided more details about the security breach, which it first disclosed in January. At that time, Microsoft said Midnight Blizzard — the Kremlin-backed crew also known as Cozy Bear and APT29 that was behind the SolarWinds supply chain attack — snooped around in "a very small percentage of Microsoft corporate email accounts" and stole internal messages and files belonging to the leadership team, and cybersecurity and legal employees. "There is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems," Redmond said in January. That has since changed. "In recent weeks, we have seen evidence that Midnight Blizzard is using information initially exfiltrated from our corporate email systems to gain, or attempt to gain, unauthorized access," according to the latest disclosure. "This has included access to some of the company's source code repositories and internal systems." Microsoft maintains there's "no evidence" so far that the Russian criminals compromised any customer-facing systems. But that's not for lack of trying. "It is apparent that Midnight Blizzard is attempting to use secrets of different types it has found," the Wind...

Read full article

Affected Software

1 affected component
Microsoft Azure
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the confirmation by Microsoft that Russian spies stole source code and gained access to its internal systems.

2

What security implications are discussed in the article?

The ongoing intrusion by Russian cyberspies poses significant risks to Microsoft and its users, potentially compromising sensitive data.

3

What products or software are affected by this breach?

The breach specifically affects Microsoft's Azure platform and other internal systems.

4

How has Microsoft responded to the security breach?

Microsoft characterized the intrusion as ongoing and is actively working to mitigate the effects.

5

What does this incident indicate about the threat landscape?

This incident underscores the persistent threat of state-sponsored cyber espionage targeting major technology companies.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203