Federal Criminal Record investigation
Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)

Russian Foreign Intelligence Service (SVR / Midnight Blizzard / APT29) compromised Microsoft corporate email systems via a password spray campaign against a legacy non-production test tenant lacking multi-factor authentication. Attackers leveraged the test account's permissions to grant full OAuth app-level access, reading executive emails and exfiltrating source code and customer cryptographic secrets.

Loss Amount $150M
Techniques 3 Mapped
Threat Actor Individual