Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft said Russia-linked Midnight Blizzard (also known as NOBELIUM) broke into a legacy, non-production test-tenant account in late November 2023 by password spraying. The actor then used that account’s permissions to reach a very small percentage of Microsoft corporate email accounts and exfiltrate some messages and attachments. Microsoft detected the activity on January 12, 2024, disclosed it on January 19, and reported a broader set of findings on March 8—including access to some internal systems and source-code repositories using information first stolen from email.

What happened in the Microsoft Midnight Blizzard cyberattack?

The incident unfolded in stages, and Microsoft’s description changed as its investigation progressed. The January disclosure was a time-bounded assessment: Microsoft said it had no evidence then of access to source code, customer environments, production systems, or AI systems. In its March update, Microsoft said it had found access to some source-code repositories and internal systems. Those statements concern different investigation dates and should not be treated as contradictory descriptions of the same moment.

Microsoft identified the actor as Midnight Blizzard, also called NOBELIUM. Microsoft Threat Intelligence says U.S. and U.K. governments attribute the Russia-based group to Russia’s Foreign Intelligence Service (SVR); other threat-intelligence names include APT29, UNC2452, and Cozy Bear. Microsoft’s January 25 responder guidance explains the attribution and attack methods.

Timeline of disclosures

Date What Microsoft or CISA reported
Late November 2023 Midnight Blizzard used password spraying against a legacy, non-production test-tenant account. Microsoft’s January 25 technical account says the account lacked multifactor authentication (MFA). The actor used its permissions to reach corporate email.
January 12, 2024 Microsoft’s security team detected the activity.
On or about January 13, 2024 Microsoft’s January 19 Form 8-K says access to the affected email accounts had been removed by around this date.
January 19, 2024 Microsoft publicly disclosed the incident and filed a Form 8-K. It said the investigation was continuing, operations had not been materially affected as of the filing, and it had not determined that a material financial impact was reasonably likely. Microsoft’s disclosure and the SEC filing provide the dated statements.
January 25, 2024 Microsoft published responder guidance describing password spraying, distributed residential proxies, OAuth abuse, and email collection, along with defensive checks.
March 8, 2024 Microsoft said stolen email information was being used to gain or attempt unauthorized access to some internal systems and source-code repositories. It said some customer-shared secrets appeared in exfiltrated email and that it was contacting those customers. It also reported that some attack activity, such as password spraying, had increased by as much as 10-fold in February compared with the already high volume observed in January.
April 11, 2024 CISA issued Emergency Directive 24-02 for affected U.S. Federal Civilian Executive Branch agencies, requiring analysis of exfiltrated correspondence, resets of compromised credentials, and additional protection for privileged Azure accounts.

How did Midnight Blizzard get into Microsoft?

Password spraying against a neglected identity

Password spraying tests a small number of common or likely passwords across many accounts, rather than repeatedly guessing one account’s password. Microsoft said the initial target was a legacy test-tenant account that did not have MFA. The actor limited attempts against targeted accounts and used distributed residential proxies, making simple source-IP blocking a less reliable detection method.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OAuth and mailbox permissions expanded access

After obtaining the account, the actor abused permissions associated with a legacy test OAuth application that had elevated access. Microsoft said Midnight Blizzard created additional malicious applications and used application permissions to access Exchange Online mailboxes. The compromise therefore depended on identity and application authorization—not a demonstrated vulnerability in a Microsoft product or service.

Microsoft’s January disclosure said the actor reached a very small percentage of corporate email accounts, including some senior leaders and personnel in cybersecurity, legal, and other functions. Some emails and attachments were exfiltrated. Microsoft has not published an exact mailbox count or a comprehensive list of affected individuals.

Did the hackers access Microsoft customer data?

Microsoft’s January 19 statement said that, at that point in the investigation, it had no evidence of access to customer environments, production systems, source code, or AI systems. On March 8, Microsoft said it had found no evidence that Microsoft-hosted customer-facing systems were compromised. That later statement does not mean no customer-related information was present: Microsoft also said some secrets that customers had shared by email were found among the stolen material and that it was contacting those customers.

The reviewed public statements do not quantify the number of customer secrets, identify every affected customer, or establish a final forensic scope. “A very small percentage” is Microsoft’s wording for the corporate email accounts involved; it is not a published percentage for customers or organizations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What changed in March?

Microsoft’s March 8 update said Midnight Blizzard was using information first exfiltrated from corporate email to gain or attempt unauthorized access to some internal systems and source-code repositories. Microsoft also observed a sharp increase in portions of the campaign: it said the volume of some activity, including password sprays, was as much as 10-fold higher in February than in January. This is a comparison of Microsoft’s observed attack activity, not a count of accounts, systems, or victims. Read the update at Microsoft’s March 8 statement.

What defenders should learn from the incident

Close gaps in legacy and non-production tenants

  • Inventory test tenants, service accounts, service principals, and OAuth applications.
  • Apply current identity policies—including MFA—to non-production identities rather than treating them as harmless exceptions.
  • Remove dormant accounts and permissions that are no longer required.

Review application and mailbox authorization

  • Check privileged users, service principals, and applications for excessive or unexplained permissions.
  • Review OAuth grants, Exchange impersonation settings, and mailbox-access permissions.
  • Investigate unusual Exchange Web Services activity, identity alerts, and audit-log events.

Harden against password spraying

  • Use stronger, unique passwords and reset credentials for accounts targeted by spraying.
  • Use sign-in risk controls and monitor for distributed attempts, not just repeated requests from one IP address.
  • Correlate identity, application-consent, mailbox, and endpoint telemetry so proxy-distributed activity is visible.

Microsoft Threat Intelligence wrote on January 25: “If the same team were to deploy the legacy tenant today, mandatory Microsoft policy and workflows would ensure MFA and our active protections are enabled to comply with current policies and guidance, resulting in better protection against these sorts of attacks.” This is Microsoft’s counterfactual assessment of its policies, not an independent guarantee that MFA alone would have stopped every stage of the intrusion.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What affected organizations should do

CISA’s Emergency Directive 24-02 applies to affected Federal Civilian Executive Branch agencies, not automatically to every company. Those agencies were directed to inspect the content of exfiltrated correspondence, reset compromised credentials, and take additional steps to secure privileged Azure accounts. Other organizations can use the same actions as incident-response practices, while following their own legal and regulatory requirements. The directive is described at CISA’s April 11, 2024 alert.

Organizations that exchanged secrets by email with Microsoft should determine whether those values remain valid, rotate them where appropriate, and review access logs for related systems. They should preserve relevant identity, Exchange, OAuth-consent, and audit evidence before making broad changes that could erase investigative context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What remains unknown

  • The public statements do not give a final number of affected mailboxes or people.
  • They do not quantify the total volume or sensitivity of exfiltrated material or customer secrets.
  • They do not provide a comprehensive final list of internal repositories or systems accessed.
  • The cited materials do not establish whether Microsoft later issued a final forensic account that revised the March findings.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.