{
  "id": "case-hpe-midnight-blizzard",
  "slug": "hpe-midnight-blizzard-cloud-breach",
  "title": "Hewlett Packard Enterprise M365 Email Breach (Midnight Blizzard)",
  "summary": "State-sponsored cyber espionage campaign conducted by Russian Foreign Intelligence Service (SVR) unit Midnight Blizzard (APT29) infiltrating Hewlett Packard Enterprise cloud-hosted Microsoft Office 365 environment, accessing executive leadership and cybersecurity correspondence, disclosed under SEC Form 8-K filings.",
  "case_number": "SEC-8K-0001645590-24-000008",
  "court": "U.S. Securities and Exchange Commission EDGAR",
  "district": "S.D. Texas",
  "country": "Russia",
  "opened_at": "2023-12-12",
  "status": "alleged",
  "victim_sector": "Technology & Cloud Infrastructure",
  "victim_country": "United States",
  "loss_amount_usd": 25000000,
  "loss_amount_note": "Extensive cloud security remediation, tenant re-architecting, and forensic investigations.",
  "first_seen_at": "2023-05-01T00:00:00Z",
  "last_updated_at": "2026-10-06T10:00:00Z",
  "actor_slug": "apt29-svr",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Russian state actors utilized compromised credentials to authenticate directly into enterprise cloud email accounts.",
      "evidence_locator": "HPE SEC Form 8-K Item 8.01/1.05 Filing",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "SEC Form 8-K Hewlett Packard Enterprise",
      "source_url": "https://www.sec.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1114.002",
      "evidence_excerpt": "Midnight Blizzard queried Microsoft 365 Exchange mailboxes belonging to HPE cybersecurity, legal, and executive personnel, downloading message threads and attachments.",
      "evidence_locator": "CISA Advisory on SVR Targeting of Cloud Mailboxes",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA SVR Cloud Guidance",
      "source_url": "https://www.cisa.gov"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2023-05-01",
      "description": "SVR operatives gain initial persistent access to HPE cloud environment."
    },
    {
      "event_type": "discovery",
      "event_date": "2023-12-12",
      "description": "HPE is notified that Midnight Blizzard has compromised corporate email accounts."
    },
    {
      "event_type": "filing",
      "event_date": "2024-01-24",
      "description": "HPE publicly files SEC Form 8-K disclosing SVR exfiltration of corporate email messages."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Password spraying against legacy test and non-production accounts, granting Russian Foreign Intelligence Service (SVR) unit Midnight Blizzard initial entry to HPE cloud mailboxes.",
    "blast_radius": "Surveillance and exfiltration of executive leadership and cybersecurity correspondence spanning several months, disclosed under SEC Form 8-K.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Distributed Password Spraying Ingress",
        "description": "SVR operators executed distributed password spraying against a legacy cloud account lacking multi-factor authentication.",
        "technical_artifacts": [
          "Distributed residential proxy IPs",
          "Failed login telemetry"
        ],
        "mitre_technique_id": "T1110.003"
      },
      {
        "phase": "Privilege Escalation",
        "title": "Malicious OAuth Application Minting",
        "description": "Adversaries leveraged the compromised account to create new OAuth applications with broad full_access_as_app permissions across Exchange Web Services.",
        "technical_artifacts": [
          "Rogue OAuth application IDs",
          "Service principal role assignments"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Collection",
        "title": "Executive Mailbox Querying",
        "description": "Midnight Blizzard queried Microsoft 365 Exchange mailboxes belonging to HPE cybersecurity, legal, and executive staff without triggering user login alerts.",
        "technical_artifacts": [
          "Exchange Web Services API calls",
          "Mailbox search queries"
        ],
        "mitre_technique_id": "T1114.002"
      },
      {
        "phase": "Exfiltration",
        "title": "Encrypted Email Thread Exfiltration",
        "description": "Messages containing threat intelligence research, internal incident notes, and executive communications were exfiltrated over HTTPS channels.",
        "technical_artifacts": [
          "Encrypted HTTPS streams",
          "Foreign C2 endpoints"
        ],
        "mitre_technique_id": "T1041"
      },
      {
        "phase": "Regulatory Filing",
        "title": "SEC Form 8-K Public Disclosure",
        "description": "HPE disclosed the nation-state espionage campaign in SEC Form 8-K filings, noting unauthorized access to corporate email mailboxes.",
        "technical_artifacts": [
          "SEC Form 8-K filing 0001645590-24-000008"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multi-factor authentication across all non-production and legacy cloud accounts.",
      "Regularly audit application-level OAuth permissions and restrict full_access_as_app mailbox privileges.",
      "Deploy threat intelligence monitoring to flag rogue service principals and credential additions.",
      "Segregate non-production directory tenants completely from production corporate identities."
    ]
  }
}