MICROSOFT CORP
Jan 2024 · Graded Verified · Technology and Software · Government record
Incident summary
MICROSOFT CORPJan 2024
Not yet quantified
VVerifiedThe intrusion ran through a legacy test tenant Microsoft had left standing with no multifactor authentication and a guessable password, which a password spray walked straight into. From there the attackers reached an old test OAuth app that still carried full access to corporate mailboxes, and read the email of senior leadership, cybersecurity, and legal. The perimeter that failed was not a network but a forgotten account the security giant never turned off; Microsoft named the actor as Midnight Blizzard, a Russian state group.
Technology and Software
SEC 8-K, Item 1.05
Initial attack type compromised credentials confirmed · Impact data theft confirmed · Actor Midnight Blizzard
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.