Microsoft Confirms Russian Hackers Stole Source Code, Some Customer Secrets

Share:

Microsoft on Friday revealed that the Kremlin-backed threat actor known as Midnight Blizzard (aka APT29 or Cozy Bear) managed to gain access to some of its source code repositories and internal systems following a hack that came to light in January 2024.

“In recent weeks, we have seen evidence that Midnight Blizzard is using information initially exfiltrated from our corporate email systems to gain, or attempt to gain, unauthorized access,” the tech giant said.

“This has included access to some of the company’s source code repositories and internal systems. To date we have found no evidence that Microsoft-hosted customer-facing systems have been compromised.”

Redmond, which is continuing to investigate the extent of the breach, said the Russian state-sponsored threat actor is attempting to leverage the different types of secrets it found, including those that were shared between customers and Microsoft in email.

It, however, did not disclose what these secrets were or the scale of the compromise, although it said it has directly reached out to impacted customers. It’s not clear what source code was accessed.

Stating that it has increased in its security investments, Microsoft further noted that the adversary ramped up its password spray attacks by as much as 10-fold in February, compared to the “already large volume” observed in January.

“Midnight Blizzard’s ongoing attack is characterized by a sustained, significant commitment of the threat actor’s resources, coordination, and focus,” it said.

“It may be using the information it has obtained to accumulate a picture of areas to attack and enhance its ability to do so. This reflects what has become more broadly an unprecedented global threat landscape, especially in terms of sophisticated nation-state attacks.”

The Microsoft breach is said to have taken place in November 2023, with Midnight Blizzard employing a password spray attack to successfully infiltrate a legacy, non-production test tenant account that did not have multi-factor authentication (MFA) enabled.

The tech giant, in late January, revealed that APT29 had targeted other organizations by taking advantage of a diverse set of initial access methods ranging from stolen credentials to supply chain attacks.

Midnight Blizzard is considered part of Russia’s Foreign Intelligence Service (SVR). Active since at least 2008, the threat actor is one of the most prolific and sophisticated hacking groups, compromising high-profile targets such as SolarWinds.

“Microsoft’s breach by Midnight Blizzard is a strategic blow,” Tenable CEO Amit Yoran said in a statement shared with The Hacker News. “Midnight Blizzard isn’t some small-time criminal gang. They are a highly professional, Russian-backed outfit that fully understands the value of the data they’ve exposed and how to best use it to inflict maximum harm.”

“Microsoft’s ubiquity requires a much higher level of responsibility and transparency than what they’ve consistently shown. Even now they’re not sharing the full truth – for instance we don’t yet know which source code has been compromised. These breaches aren’t isolated from each other and Microsoft’s shady security practices and misleading statements purposely obfuscate the whole truth.”

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:32 pm, Jun 21, 2025
weather icon 31°C
L: 30° | H: 33°
scattered clouds
Humidity: 39 %
Pressure: 1018 mb
Wind: 9 mph SSE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 44%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
30° | 33°°C 0.73 mm 73% 10 mph 56 % 1017 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 26°°C 1 mm 100% 15 mph 78 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
15° | 24°°C 0.2 mm 20% 14 mph 82 % 1015 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
13° | 25°°C 0 mm 0% 15 mph 79 % 1016 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 26°°C 0.34 mm 34% 12 mph 87 % 1011 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 31°°C 0 mm 0% 8 mph 37 % 1017 mb 0 mm/h
Today 7:00 pm
weather icon
28° | 29°°C 0 mm 0% 10 mph 34 % 1015 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0.73 mm 73% 7 mph 56 % 1013 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 1 mm 100% 7 mph 77 % 1013 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 10 mph 78 % 1013 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 10 mph 67 % 1014 mb 0 mm/h
Tomorrow 10:00 am
weather icon
23° | 23°°C 0 mm 0% 12 mph 46 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 14 mph 32 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€90,167.94
-1.93%
Ethereum(ETH)
€2,120.05
-4.25%
Tether(USDT)
€0.87
0.01%
XRP(XRP)
€1.86
-1.57%
Solana(SOL)
€123.22
-3.99%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.141468
-4.69%
Shiba Inu(SHIB)
€0.000010
-3.52%
Pepe(PEPE)
€0.000009
-3.91%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top