Russian hackers stole Microsoft corporate emails in month-long breach
ID: d65626fb-6e8b-585f-9d88-7cf4d0b977d9
STIX ID: report--d65626fb-6e8b-585f-9d88-7cf4d0b977d9
Feed Name: Bleeping Computer
Microsoft disclosed that Russian state-sponsored group Nobelium (aka Midnight Blizzard / APT29) breached a legacy non-production test account in November 2023 using a password-spray attack, accessed a small percentage of corporate email accounts (including leadership and cybersecurity/legal staff), and exfiltrated emails and attachments; the company attributes the breach to weak account configuration and lack of MFA rather than a product vulnerability and is investigating and notifying affected employees.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
