logo

Microsoft email exfiltration by Nobelium (Incident)

ID: c47ff769-410a-5a11-8e98-b582e01a3f0d

STIX ID: report--c47ff769-410a-5a11-8e98-b582e01a3f0d

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2024-01-19

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Microsoft disclosed that Nobelium conducted a targeted campaign beginning in late November 2023 that used low-volume password spraying against a legacy test account, routed traffic through a residential proxy network to avoid detection, and abused compromised and newly-created OAuth apps (including granting Office 365 Exchange Online full_access_as_app) to access and exfiltrate email from a small set of senior and sensitive Microsoft corporate mailboxes. Microsoft identified the activity via Exchange Web Services and audit logs and reported no evidence of access to customer environments, production systems, source code, or AI systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.