Desk live·
ForensicPost
Nation-state/Primary source/File 24-0112

Microsoft Says Password Spray on a Legacy Test Account Reached Leadership Email

Microsoft told the SEC that a Russian state actor reached the email of its senior leadership. The way in was a password spray against a legacy non-production test tenant — no exploit, no zero-day, and no second factor.

Constructed geometry · not a chart of case data
JurisdictionUSARedmond, Washingtonthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetMicrosoft
ActorMidnight Blizzard
D. Kennedy13 min readConfidence: high3 sources reviewed

On 12 January 2024 Microsoft detected that a nation-state actor had been inside its corporate systems since late November 2023 and had taken email from a small number of accounts — among them members of the senior leadership team and staff in the security and legal functions. It filed a Form 8-K under Item 1.05 seven days later and attached its own account of the incident as an exhibit.

This desk retrieved both from EDGAR. The exhibit is unusually specific about the route in, and the sentence is worth reading exactly as filed.

Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts.

Microsoft, Exhibit 99.1 to Form 8-K, filed 19 January 2024

What A Password Spray Actually Is

It is the inverse of a brute force. Rather than trying thousands of passwords against one account — which locks the account and raises an alarm — the attacker tries one common password against thousands of accounts, slowly. No individual account sees enough failures to trip a lockout, and in a large directory somebody is always using the weak password.

It requires no vulnerability, and Microsoft says so plainly: "The attack was not the result of a vulnerability in Microsoft products or services." Nothing was exploited. An account existed, it had a guessable password, and it had no second factor.

The Word Doing The Work Is "Legacy"

A legacy non-production test tenant is the kind of thing that exists in every organisation of any size. Somebody stood it up to try something, it served its purpose, and it was never decommissioned because decommissioning is nobody’s objective.

It sat outside whatever policy required multi-factor authentication on the accounts that mattered, because it was not an account that mattered. That judgement was correct about the account and wrong about its permissions, which is the entire incident in one line.

The corpus has filed variants of this repeatedly — access never revoked, a dormant integration, a token that outlived its purpose. What is unusual here is that the affected organisation described the mechanism itself, in a document it filed with a securities regulator.

Why This File Exists At All

Because password spray appears in no other file in this database, and it is not because it is rare. It is because almost nobody says how they were broken into.

The disclosure, as filedMicrosoft Form 8-K and Exhibit 99.1, SEC EDGAR — read by this desk
TimeEventEvidence
Late Nov 2023Password spray compromises a legacy test tenant accountCompany statement
12 Jan 2024Microsoft detects the intrusionForm 8-K, Item 1.05
≈13 Jan 2024Access to the email accounts removedForm 8-K, Item 1.05
19 Jan 2024Item 1.05 filed; blog attached as Exhibit 99.1Primary document

That is roughly six weeks between the foothold and the detection, at the company that sells the identity platform most of the organisations in this corpus depend on. The desk records that without relish: the disclosure is more candid than most, and candour is what makes the file possible.

And The Filing Says It Was Not Material

The Item 1.05 states that "the incident has not had a material impact on the Company’s operations" and that the company had not yet determined whether it was reasonably likely to affect financial condition or results.

Both things are true at once, and the corpus has recorded the same shape at 24-0821: materiality is indexed to the registrant, so an intrusion into the email of a company’s own senior leadership can be immaterial to a company of sufficient size. The rule measures the balance sheet, not the incident.

How we reported this

Built on two primary documents retrieved from the SEC EDGAR archive and read in full: Microsoft’s Form 8-K of 19 January 2024 filed under Item 1.05, and Exhibit 99.1 to it, being the company’s own published account of the incident. All quotations are verbatim from those filings. The attribution to Midnight Blizzard is Microsoft’s own and is reported as the company’s assessment, not as an independent finding by this desk. The description of how password spraying works is general technique, not a finding about this incident. No count of affected accounts has been published beyond "a very small percentage" and none is inferred. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Microsoft Corporation — Form 8-K, Item 1.05 Material Cybersecurity IncidentsU.S. Securities and Exchange Commission (EDGAR)
  2. Exhibit 99.1 — Microsoft actions following attack by nation state actor Midnight BlizzardU.S. Securities and Exchange Commission (EDGAR)
  3. Microsoft actions following attack by nation state actor Midnight BlizzardMicrosoft Security Response Center
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary