Russian Hackers Win Big: Microsoft's Senior Exec Team Emails Breached
ID: 4f1dcb2a-4843-5f14-89a2-d9b4d5462b5d
STIX ID: report--4f1dcb2a-4843-5f14-89a2-d9b4d5462b5d
Feed Name: KnowBe4 Blog
Microsoft disclosed that Russian state-sponsored APT29 (Nobelium/Midnight Blizzard) compromised a legacy non-production test tenant via password-spraying beginning in November 2023, enabling access to a small percentage of corporate email accounts—including leadership and security/legal teams—detected on January 12, 2024; Microsoft reports no customer data theft or access to production systems and is working with CISA while urging enforcement of MFA/2FA to mitigate password-based attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
