logo

Microsoft sheds some light on Russian email heist – and how to learn from Redmond's mistakes

ID: 79353d64-e3c1-55f6-8355-3845bf35f684

STIX ID: report--79353d64-e3c1-55f6-8355-3845bf35f684

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-01-27

Date Updated: 2026-04-26

Author: Jessica Lyons Hardcastle

...
...

Microsoft disclosed that Kremlin-backed espionage group Midnight Blizzard (APT29/Cozy Bear) used password-spray attacks to breach a legacy, non-production test tenant that lacked multi-factor authentication, then leveraged a compromised legacy OAuth application to access and steal emails and files from corporate executives and staff; attackers also used residential broadband proxies to blend their traffic, prompting Microsoft to accelerate MFA and legacy-system remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.