Back to all incidents

Microsoft

microsoft.com
CONFIRMED

Microsoft disclosed an intrusion by Russian foreign intelligence threat group Midnight Blizzard (APT29), accessing senior leadership corporate emails and source code.

Observable Status CONFIRMED
Industry / Sector Technology
Incident Classification Nation-State Password Spray & Cloud Access
Attributed Threat Actor Midnight Blizzard (APT29)
Affected Population Scope Under Audit
First Seen 2024-01-12
Last Updated 2026-10-01
Senior Leadership Corporate Email Accounts Cybersecurity Strategy Communications Source Code Repositories
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE

Confidence & Source Corroboration

100% CONFIDENCE
1. Primary Authority CONFIRMED BY REGULATOR Base weight: 65%
2. Evidence Specificity +19% Statutory Filing Verified
3. Corroboration Curve +17% 3 independent domains
4. Timeline & Staleness +3% 4 milestones logged
Corroborated Source Domains:
msrc.microsoft.com sec.gov bleepingcomputer.com
STATUTORY REGULATORY DISCLOSURES

Official Regulatory Filings & Legal Compliance Records

1 Verified Statutory Filing
Regulatory Ground Truth Standard: The disclosures below represent formal statutory filings and enforcement records submitted to government regulatory authorities (SEC, State Attorneys General, HHS OCR, CISA). In accordance with repository principles, this data is captured exactly as filed by the reporting entity and is never modified, overridden, or synthesized by AI models.
U.S. Securities and Exchange Commission (SEC)

Form 8-K Item 1.05 (Material Cybersecurity Incidents)

CONFIRMED BY REGULATOR
Docket / Accession ID 0000789019-24-000004
Statutory Filing Date 2024-01-19
Disclosed Impact Scope Under Audit
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Item 1.05 Material Cybersecurity Incident disclosure filed by Microsoft Corporation regarding Russian state-sponsored threat actor Midnight Blizzard accessing senior leadership email accounts and internal cybersecurity communications.

View Official Regulatory Filing Document https://www.sec.gov/Archives/edgar/data/789019/000078901924000004/msft-20240119.htm

Technical Forensic Briefing

Incident Overview

Microsoft disclosed an intrusion by Russian foreign intelligence threat group Midnight Blizzard (APT29), accessing senior leadership corporate emails and source code.

Compromised Assets & Data Scope

  • Primary Data Classes: Senior Leadership Corporate Email Accounts, Cybersecurity Strategy Communications, Source Code Repositories.

Statutory Disclosures & Compliance

  • Statutory filing submitted to SEC (Form 8-K (Item 1.05)) under accession 0000789019-24-000004.

Milestone Timeline (4 events logged)

2024-01-12 18:00 UTC
CONFIRMED BY TARGET

Microsoft security team detects Russian state-sponsored threat actor Midnight Blizzard accessing corporate email systems via legacy OAuth tenant test account.

2024-01-19 21:00 UTC
CONFIRMED BY REGULATOR

Microsoft files Form 8-K Item 1.05 detailing Midnight Blizzard intrusion into senior executive email accounts and cybersecurity staff communications.

2024-03-08 17:00 UTC
CONFIRMED BY REGULATOR

Microsoft Form 8-K update discloses threat actor used exfiltrated email secrets to gain unauthorized access to internal source code repositories.

2026-10-01 19:32 UTC
INDEPENDENT VERIFICATION

Microsoft says threat actors are ahead in the early AI race

Have updated information or a new verifiable source?

This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.

Propose Update via GitHub