ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Data Breaches

Microsoft Confirms Ongoing Security Breach by Russian Threat Actors

Kyle by Kyle
March 9, 2024
in Data Breaches
Reading Time: 3 mins read
Microsoft confirms ongoing cybersecurity breach by Russian cyber spies, Midnight Blizzard. Details on the impact and industry reactions.
27
SHARES
439
VIEWS
Share on FacebookShare on Twitter

Microsoft has officially acknowledged that Russian cyber spies, known as Midnight Blizzard, have infiltrated their internal systems. The breach, which is still ongoing, has resulted in the theft of source code and unauthorized access to internal systems.

Details of the Breach

In an updated filing with the US Securities and Exchange Commission (SEC), Microsoft has provided additional information about the security breach, which was initially disclosed in January.

Midnight Blizzard, also known as Cozy Bear and APT29, is a Kremlin-backed group that was previously implicated in the SolarWinds supply chain attack. The group has been found snooping on a small percentage of Microsoft’s corporate email accounts, stealing internal messages and files from the leadership team, as well as cybersecurity and legal employees.

While Microsoft initially stated in January that there was no evidence of the threat actor accessing customer environments, production systems, source code, or AI systems, this has since changed.

Recent evidence suggests that Midnight Blizzard is using information initially exfiltrated from Microsoft’s corporate email systems to gain, or attempt to gain unauthorized access. This includes access to some of the company’s source code repositories and internal systems.

Customer-Facing Systems Remain Safe

Despite these developments, Microsoft maintains that there is no evidence so far that the Russian criminals have compromised any customer-facing systems. However, this is not due to a lack of effort on the part of Midnight Blizzard.

Microsoft has admitted that Midnight Blizzard is attempting to use various types of secrets it has discovered. Some of these secrets were shared between customers and Microsoft via email. As these secrets are discovered in the exfiltrated email, Microsoft has been reaching out to these customers to assist them in taking mitigating measures.

Ongoing Attempts at Unauthorized Access

The break-in, which began in November, used password spray attacks to compromise an internal account that did not have multi-factor authentication enabled. The spies are still attempting to access additional Microsoft accounts, and the volume of password sprays increased ten-fold in February compared to January.

According to Microsoft’s updated SEC Form 8-K, the security breach has not had any financial impact on operations so far.

Industry Reactions

Adam Meyers, the head of counter-adversary operations at CrowdStrike, has noted that Microsoft’s recent 8-K filing raises more questions for customers and the industry than it answers. He has also stated that this breach highlights the broader authentication issues with Azure, Microsoft’s cloud service.

Meyers, who had previously criticized Microsoft soon after the email intrusion was disclosed in January, pointed out that Microsoft has been breached by both China and Russia in the past year. The latter incident was enabled by sensitive Microsoft key material exfiltrated from within Microsoft’s sensitive systems.

This latest disclosure introduces uncertainty about Microsoft’s ability to evict Cozy Bear, serving as a stark reminder of the deeper issues seemingly affecting Azure’s authentication and security mechanisms.

You might also like

Panera Bread Hacked – Exposes 5.1 Million Customer Records

KPMG Netherlands Listed as Victim by Nova Ransomware Group

RansomHouse Claims Breach of Key Apple Assembler Luxshare

Global Implications

In a year where 42 percent of the world’s population is electing new leadership, there are growing concerns about how potential access to Microsoft’s sensitive data and AI models may be misused by hostile nation states. This concern is particularly relevant given the upcoming elections across the globe in 2024.

Ongoing Investigation

Microsoft, also known as Redmond, has stated that its investigation is ongoing and has promised to share updates as they become available.

Characteristics of the Attack

The ongoing attack by Midnight Blizzard is characterized by a sustained, significant commitment of the threat actor’s resources, coordination, and focus. The group may be using the information it has obtained to accumulate a picture of areas to attack and enhance its ability to do so. This situation reflects what has become more broadly an unprecedented global threat landscape, especially in terms of sophisticated nation-state attacks.

Tags: Cozy BearRussia
Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Panera Bread Hacked – Exposes 5.1 Million Customer Records

Panera Bread Hacked – Exposes 5.1 Million Customer Records

February 8, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026

Tennessee Man Pleads Guilty to Posting Stolen SCOTUS Docs on Instagram

January 19, 2026

BreachForums Database Leak Exposes Over 320,000 Users

January 14, 2026

Betterment Investment Users Targeted by “Triple Crypto” Scam Notification

January 11, 2026
Next Post
Unveiling cybersecurity threats: In-depth analysis of one-day vulnerabilities exploited by hacker group Magnet Goblin in Ivanti software.

Magnet Goblin Hackers Found Deploying NerbianRAT Utilizing Ivanti Vulnerabilities

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.