{
  "id": "case-microsoft-midnight-blizzard",
  "slug": "microsoft-midnight-blizzard-email-breach",
  "title": "Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)",
  "summary": "Russian Foreign Intelligence Service (SVR / Midnight Blizzard / APT29) compromised Microsoft corporate email systems via a password spray campaign against a legacy non-production test tenant lacking multi-factor authentication. Attackers leveraged the test account's permissions to grant full OAuth app-level access, reading executive emails and exfiltrating source code and customer cryptographic secrets.",
  "case_number": "SEC-2024-8K-MSFT",
  "court": "U.S. Securities and Exchange Commission & CISA Emergency Directive 24-02",
  "district": "W.D. Wash.",
  "country": "United States",
  "opened_at": "2024-01-19",
  "status": "investigation",
  "victim_sector": "Information Technology, Cloud Services",
  "victim_country": "United States",
  "loss_amount_usd": 150000000,
  "loss_amount_note": "System-wide architectural overhaul (Secure Future Initiative), token revocations, and CISA Emergency Directive 24-02 compliance.",
  "first_seen_at": "2023-11-20T00:00:00Z",
  "last_updated_at": "2026-09-01T00:00:00Z",
  "actor_slug": "apt29",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1110",
      "evidence_excerpt": "Adversaries executed a slow, distributed password spray against a non-production legacy tenant account that did not enforce multi-factor authentication.",
      "evidence_locator": "Microsoft Security Response Center (MSRC) Investigation Update",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "MSRC Blog Post on Midnight Blizzard",
      "source_url": "https://www.microsoft.com/security/blog",
      "technique_name": "Brute Force",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "After authenticating to the legacy test tenant, Midnight Blizzard created new OAuth credentials with high-privilege application permissions (full_access_as_app) to query Exchange Web Services.",
      "evidence_locator": "CISA Emergency Directive 24-02: Mitigating SVR Compromise",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Emergency Directive 24-02",
      "source_url": "https://www.cisa.gov/news-events/directives/ed-24-02",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Adversaries exfiltrated emails and attachments belonging to Microsoft senior executive leadership and cybersecurity personnel over encrypted HTTPS channels.",
      "evidence_locator": "Microsoft SEC Form 8-K Disclosure",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "SEC Form 8-K Microsoft Corp",
      "source_url": "https://www.sec.gov",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2023-11-20",
      "description": "SVR operators begin distributed password spraying against legacy Microsoft non-production tenants."
    },
    {
      "event_type": "discovery",
      "event_date": "2024-01-12",
      "description": "Microsoft internal security discovers unauthorized nation-state access to corporate mailboxes."
    },
    {
      "event_type": "disclosure",
      "event_date": "2024-01-19",
      "description": "Microsoft publicly discloses the intrusion via an SEC Form 8-K filing."
    },
    {
      "event_type": "directive",
      "event_date": "2024-04-02",
      "description": "CISA issues Emergency Directive 24-02 ordering federal agencies to remediate exposed credentials."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Russian Foreign Intelligence Service (SVR / Midnight Blizzard) conducted a password spray attack against a legacy, non-production test tenant account that lacked multi-factor authentication.",
    "blast_radius": "Adversaries gained unauthorized access to corporate email accounts of Microsoft senior leadership, cybersecurity teams, and legal counsel. Operatives exfiltrated source code repositories, communication secrets, and customer authentication secrets shared in emails, prompting CISA Emergency Directive 24-02 for all federal civilian agencies.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Distributed Password Spraying Against Legacy Tenant",
        "description": "SVR operators launched a slow, distributed password spray across multiple residential IP proxies against a non-production test tenant that lacked MFA.",
        "technical_artifacts": [
          "Distributed residential proxy network",
          "Single-factor test tenant account"
        ],
        "mitre_technique_id": "T1110"
      },
      {
        "phase": "Privilege Escalation",
        "title": "OAuth Application Creation and Role Assignment",
        "description": "After compromising the test account, Midnight Blizzard leveraged its permissions to create high-privilege OAuth applications and assign the full_access_as_app role for Exchange Web Services.",
        "technical_artifacts": [
          "Malicious OAuth enterprise application",
          "AppRoleAssignment to Exchange",
          "full_access_as_app permission"
        ],
        "mitre_technique_id": "T1098"
      },
      {
        "phase": "Persistent Access",
        "title": "Exchange Web Services (EWS) API Ingress",
        "description": "Attackers authenticated via the newly minted OAuth applications to query the Microsoft corporate Exchange environment, querying mailboxes silently without user interaction.",
        "technical_artifacts": [
          "Exchange Web Services (EWS) API calls",
          "OAuth bearer tokens"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Targeted Exfiltration",
        "title": "Executive Mailbox and Source Code Theft",
        "description": "Adversaries searched for and exfiltrated emails containing cybersecurity threat research, source code snippets, and customer credentials shared with Microsoft support teams.",
        "technical_artifacts": [
          "Corporate executive email threads",
          "Source code repository secrets",
          "Encrypted HTTPS exfiltration"
        ],
        "mitre_technique_id": "T1041"
      }
    ],
    "defensive_takeaways": [
      "Enforce 100% multi-factor authentication across all non-production, test, development, and legacy cloud tenants without exception.",
      "Strictly audit and restrict application-level OAuth permissions (such as full_access_as_app) that grant broad mailbox access.",
      "Segregate non-production directory tenants completely from production identity providers and corporate directories.",
      "Deploy continuous threat intelligence monitoring to identify suspicious credential creation within OAuth applications."
    ]
  }
}