On 12 January 2024 Microsoft detected that a nation-state actor had been inside its corporate systems since late November 2023 and had taken email from a small number of accounts — among them members of the senior leadership team and staff in the security and legal functions. It filed a Form 8-K under Item 1.05 seven days later and attached its own account of the incident as an exhibit.
This desk retrieved both from EDGAR. The exhibit is unusually specific about the route in, and the sentence is worth reading exactly as filed.
Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts.
Microsoft, Exhibit 99.1 to Form 8-K, filed 19 January 2024
What A Password Spray Actually Is
It is the inverse of a brute force. Rather than trying thousands of passwords against one account — which locks the account and raises an alarm — the attacker tries one common password against thousands of accounts, slowly. No individual account sees enough failures to trip a lockout, and in a large directory somebody is always using the weak password.
It requires no vulnerability, and Microsoft says so plainly: "The attack was not the result of a vulnerability in Microsoft products or services." Nothing was exploited. An account existed, it had a guessable password, and it had no second factor.
The Word Doing The Work Is "Legacy"
A legacy non-production test tenant is the kind of thing that exists in every organisation of any size. Somebody stood it up to try something, it served its purpose, and it was never decommissioned because decommissioning is nobody’s objective.
It sat outside whatever policy required multi-factor authentication on the accounts that mattered, because it was not an account that mattered. That judgement was correct about the account and wrong about its permissions, which is the entire incident in one line.
The corpus has filed variants of this repeatedly — access never revoked, a dormant integration, a token that outlived its purpose. What is unusual here is that the affected organisation described the mechanism itself, in a document it filed with a securities regulator.
Why This File Exists At All
Because password spray appears in no other file in this database, and it is not because it is rare. It is because almost nobody says how they were broken into.
That is roughly six weeks between the foothold and the detection, at the company that sells the identity platform most of the organisations in this corpus depend on. The desk records that without relish: the disclosure is more candid than most, and candour is what makes the file possible.
And The Filing Says It Was Not Material
The Item 1.05 states that "the incident has not had a material impact on the Company’s operations" and that the company had not yet determined whether it was reasonably likely to affect financial condition or results.
Both things are true at once, and the corpus has recorded the same shape at 24-0821: materiality is indexed to the registrant, so an intrusion into the email of a company’s own senior leadership can be immaterial to a company of sufficient size. The rule measures the balance sheet, not the incident.
Built on two primary documents retrieved from the SEC EDGAR archive and read in full: Microsoft’s Form 8-K of 19 January 2024 filed under Item 1.05, and Exhibit 99.1 to it, being the company’s own published account of the incident. All quotations are verbatim from those filings. The attribution to Midnight Blizzard is Microsoft’s own and is reported as the company’s assessment, not as an independent finding by this desk. The description of how password spraying works is general technique, not a finding about this incident. No count of affected accounts has been published beyond "a very small percentage" and none is inferred. Graded high. Corrections: corrections@forensicpost.com.
- Microsoft Corporation — Form 8-K, Item 1.05 Material Cybersecurity IncidentsU.S. Securities and Exchange Commission (EDGAR)
- Exhibit 99.1 — Microsoft actions following attack by nation state actor Midnight BlizzardU.S. Securities and Exchange Commission (EDGAR)
- Microsoft actions following attack by nation state actor Midnight BlizzardMicrosoft Security Response Center