// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
ColdRecon / Breach Radar / Microsoft
Breach Record

Microsoft

DISCLOSED 2024-01-20 · UNKNOWN

Microsoft detected a nation-state attack on its corporate systems on January 12, 2024, attributed to Russian state-sponsored actor Midnight Blizzard (NOBELIUM). The actor gained initial access via password spray on a legacy non-production test tenant without MFA, then abused OAuth applications to move laterally and access email accounts. This incident highlights risks from...

The record

What we know

Disclosed
2024-01-20
Sources

Cited reporting

This page is the permanent ColdRecon entry for the Microsoft disclosure. It updates if new public reporting emerges. All tracked breaches →

Microsoft just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →