logo

Microsoft breach allowed Russian spies to steal emails from US government

ID: c2934540-515e-5133-b561-a2624964dc9f

STIX ID: report--c2934540-515e-5133-b561-a2624964dc9f

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-04-12

Date Updated: 2026-04-26

Author: Dan Robinson

...
...

CISA issued Emergency Directive ED 24-02 after Russian-linked APT Midnight Blizzard (Cozy Bear) breached Microsoft’s corporate email, exfiltrating email correspondence — including authentication details — between Microsoft and federal agencies; agencies must analyze exfiltrated emails, reset compromised credentials, secure privileged Azure authentication, and report remediation status to CISA on an expedited schedule.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.