How Russian spies read Microsoft executives' email: a forgotten test account
The company that sells security software to much of the world had its senior leaders' email read by foreign spies, and the way in was an old test account that nobody had protected with a second login step.[1][2] This case file covers what Microsoft disclosed in 2024, how the intruders moved from a forgotten account to executive inboxes, what it cost, and the one control that was missing.
What happened
On January 12, 2024, Microsoft's security team detected an attack on its corporate systems. A week later, on January 19, it told investors in a filing with the US Securities and Exchange Commission that a nation-state group had accessed a small share of its corporate email accounts, including those of members of its senior leadership team.[2][3]
Microsoft named the group Midnight Blizzard, also known as APT29 or Cozy Bear. The US and UK governments have attributed this group to Russia's Foreign Intelligence Service, the SVR.[1] Microsoft said the intruders appeared to be looking for information about what Microsoft knew about them.[3]
The story did not end there. In a March 8, 2024 update, Microsoft said the group had used information taken from the email to reach some of its source code repositories and internal systems, and had obtained secrets that customers had sent to Microsoft by email. It said its attempts to guess passwords had risen by as much as 10 times in February compared with January.[4]
How they got in
The intrusion began in late November 2023, weeks before anyone noticed.[6] Microsoft's own guidance for responders laid out the path.[1] The attackers began with password spraying: trying a few common passwords against many accounts, slowly, so as not to trip alarms. They sent the attempts through ordinary home internet connections to hide where they came from.
The account that fell was a legacy test account in a non-production setup, not a live employee's login. Microsoft said it did not have multi-factor authentication (MFA), the second step such as a phone prompt or code that stops a guessed password from being enough.[1]
That test environment still had a connection into Microsoft's real corporate environment. The attackers found an old test application, a piece of software authorized to act on the company's behalf, that had been given broad permissions. They used it to create new applications and an account to approve them, and gave those applications permission to read corporate mailboxes.[1] In short, a neglected test account led to a neglected test app, and that app had keys to the real building.
What it cost
Microsoft has not put a dollar figure on the breach. It said it found no evidence that the customer-facing systems it hosts had been compromised.[4] But secrets such as passwords and access keys that customers had shared by email were exposed, and Microsoft began contacting the affected customers.[4]
Some of those customers were US government agencies. In April 2024 the Cybersecurity and Infrastructure Security Agency issued an emergency directive ordering federal agencies to review the email they had exchanged with Microsoft and to reset any credentials that might have been exposed.[5]
The missing control
The missing control: MFA on every account, including test and legacy ones. Microsoft said plainly that the account the attackers guessed their way into did not have MFA enabled.[1]
Password spraying works only when a correct password is all an attacker needs. With a second factor on that test account, a guessed password would have led nowhere, and the attackers would have had to find another route. The second lesson rides on the first: test accounts and test apps that are old, forgotten and still connected to real systems should be removed or locked down to the same standard as production.
What to do in your business
- Find your forgotten accounts. Pull a list of every user account in your email and cloud services, including test, shared, trial and former-employee accounts, and disable the ones nobody uses.
- Turn on MFA for everyone. Require a second login step on every remaining account, with no exceptions for test or admin accounts.
- Review connected apps. Check which third-party apps have been granted access to your email or files, and remove any you do not recognize or no longer use.
- Keep secrets out of email. Share passwords and access keys through a password manager or secure portal, not in email where one breach exposes them.
- Watch for slow guessing. Ask your IT provider to alert on repeated failed logins across many accounts, even if each account sees only a few.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Microsoft Security Blog: Midnight Blizzard, guidance for responders on nation-state attack (January 25, 2024)
- CNN: Russian hackers accessed emails of Microsoft executives
- Microsoft Security Response Center: Microsoft actions following attack by nation state actor Midnight Blizzard
- Microsoft (SEC Form 8-K/A exhibit): Update on Microsoft actions following attack by nation state actor Midnight Blizzard (March 8, 2024)
- CISA: CISA directs federal agencies to immediately mitigate significant risk from Russian state-sponsored cyber threat
- Born's Tech and Windows World: Microsoft hacked by Russian Midnight Blizzard; emails exfiltrated since Nov. 2023