Skip to Main Content
PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Microsoft Alerts More Customers Exposed to Russian Hackers After Account Breach

Microsoft sends customers a link to a portal where they can see which of their emails with the company were accessed by 'Midnight Blizzard' hackers.

June 28, 2024
Microsoft logo sign outside its store in Portugal. (Credit: Bloomberg/Contributor via Getty Images)

Months after Russian hackers breached Microsoft's corporate email systems, the tech giant is now alerting more people who exchanged emails with Microsoft corporate accounts that some of their emails were accessed or compromised.

“This week we are continuing notifications to customers who corresponded with Microsoft corporate email accounts that were exfiltrated by the Midnight Blizzard threat actor, and we are providing the customers the email correspondence that was accessed by this actor,” a Microsoft rep said in a statement. "This is increased detail for customers who have already been notified and also includes new notifications."

Microsoft is letting impacted customers view their exposed correspondence through a link to a special-built portal. Microsoft has not yet shared which or how many organizations, businesses, or individuals are impacted by its latest discovery, but a Reddit user report sharing the Microsoft notification this week suggests some Microsoft 365 business admin accounts have been notified.

The Microsoft breach included sensitive emails between Microsoft and federal agencies. When the emails were swiped, this may have enabled subsequent attacks on US federal agencies, US cybersecurity agency CISA said in April.

The exposed Microsoft corporate emails also allowed the Russian hackers to access Microsoft's source code. Back in January, hackers accessed Microsoft's systems and corporate emails by determining the password for a “legacy, non-production test tenant account” that did not have two-factor authentication enabled.

Last year, Microsoft also saw a worrisome breach when Chinese hackers accessed 25 organizations' email accounts using a Microsoft cloud security flaw. This included US government accounts, prompting regulators to criticize Microsoft's lax security measures. In April, a CISA board urged Microsoft to make "fundamental" cybersecurity reforms and "adopt a new culture" around security.

Like What You're Reading?

Sign up for SecurityWatch newsletter for our top privacy and security stories delivered right to your inbox.

This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.


Thanks for signing up!

Your subscription has been confirmed. Keep an eye on your inbox!

Sign up for other newsletters

TRENDING

About Kate Irwin

Reporter

I’m a reporter covering early morning news. Prior to joining PCMag in 2024, I was a reporter and producer at Decrypt and launched its gaming vertical, GG. I have previous bylines with Input, Game Rant, and Dot Esports. I’ve been a PC gamer since The Sims (yes, the original). In 2020, I finally built my first PC with a 3090 graphics card, but also regularly use Mac and iOS devices as well. As a reporter, I’m passionate about uncovering scoops and documenting the wide world of tech and how it affects our daily lives.

Read Kate's full bio

Read the latest from Kate Irwin