logo

Microsoft reveals how hackers breached its Exchange Online accounts

ID: ca74d01c-6e3a-5369-ae45-355df6597985

STIX ID: report--ca74d01c-6e3a-5369-ae45-355df6597985

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-01-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft confirmed that the Russian-linked APT group Midnight Blizzard (Nobelium/APT29) compromised a legacy non-production Microsoft account in November 2023 using password-spray attacks and residential proxies, abused OAuth application permissions to create malicious apps and obtain Office 365 full_access_as_app to access and exfiltrate corporate mailboxes, and that similar techniques impacted other organizations (HPE among them); Microsoft published detection and hunting guidance focused on identity, OAuth activity, and Exchange Web Services telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.