Skip to main content

Midnight Blizzard accesses Microsoft corporate emails

Microsoft reported that the Russian state actor Midnight Blizzard accessed a small number of corporate email accounts.

CybersecuritySeintec Team2-3 min read
Midnight Blizzard accesses Microsoft corporate emails

News summary

Microsoft reported that the Russian state actor Midnight Blizzard accessed a small number of corporate email accounts. Initial access was gained through password spraying against a legacy account in a test environment. The company stated there was no evidence of access to customer environments, production systems, source code, or AI systems.

This case demonstrates that a legacy account can become the gateway to a modern organisation. It is advisable to review old identities, MFA, least privilege, and accounts that should no longer remain active.

Source: Microsoft Security Response Center — 19 January 2024

What happened

Microsoft disclosed in January 2024 that the Russian state-linked actor identified as Midnight Blizzard had accessed a small percentage of the company's corporate email accounts, including accounts belonging to senior leadership and to cybersecurity and legal teams.

According to Microsoft, initial access was gained through a password spray attack against an old test-environment account that lacked multi-factor authentication. The company said it found no evidence of access to customer environments, production systems, source code or AI systems.

What it means for a mid-sized business

The case shows that even a large technology company can have legacy, forgotten or test-environment accounts sitting outside the reach of its usual security policies, and that such accounts can become the entry point to far more sensitive systems.

It also confirms that password spraying, a relatively simple technique that tries common passwords across many accounts, remains effective wherever multi-factor authentication is not enforced universally.

What to review

After a case like this, it's worth checking within your own organisation:

  • Whether test-environment or old-project accounts still exist and remain active with access to other systems.
  • Whether multi-factor authentication is enforced without exceptions, including service and admin accounts.
  • Whether there is a regular process to deactivate identities and access no longer needed.
  • Whether strong password policies and lockouts after failed attempts are in place to slow down password spraying.

Frequently Asked Questions

How did the attacker gain initial access?
Through password spraying against an old test-environment account that had no multi-factor authentication.
Were Microsoft's customers affected?
Microsoft stated it found no evidence of access to customer environments, production systems, source code or AI systems.
What lesson applies to any business?
That old or test-environment accounts must be removed or protected just like any active account, with multi-factor authentication enforced without exceptions.

At Seintec, we can help you assess how a similar scenario would affect your business and define the most appropriate technical measures. Contact us and an expert will study your case.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.