FEDERALItem 1.05 · mandatoryHackingTechnologyInformationSoftwareStolen CredentialsCapture Stored DataMidnight BlizzardActor NamedNation State SuspectedTargetedMulti-Stage ChainLateral Movement ObservedData ExfiltratedEmployee Data InvolvedIPCREDENTIALSMETADATALowActive
Microsoft Corporation
bd_bfb10eaec0a6e100 · schema v1 · pii pii-v1
Full breach record for Microsoft Corporation →Microsoft filed an 8-K/A amending its January 19, 2024 disclosure of a cybersecurity incident attributed to nation-state threat actor Midnight Blizzard. Beginning in late November 2023, the actor accessed and exfiltrated information from a small percentage of corporate email accounts, including senior leadership, cybersecurity, and legal personnel. Microsoft has since determined the actor used that information to attempt unauthorized access to source code repositories and internal systems. Investigation remains active.
SEC clockMateriality determined Jan 17, 2024 → Filed Mar 8, 202451d ✗ SEC 4-day late
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_d660c617b3363d6dSEC 8-KMidnight Blizzardfiled 2024-01-19(49d gap)Candidate
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/789019/000119312524062997/d808756d8ka.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 8, 2024
- Raw hash
- 66ef5cb0574479ded15b1de0f56366c1de45dc3ec8d3c7bc7c5415dcf34edd96
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Microsoft Corporationnorm: microsoft
- SEC CIK
- 0000789019
- Domain
- microsoft.com
Victim entity
- Name
- Microsoft Corporationnorm: microsoft
- SEC CIK
- 0000789019
- Domain
- microsoft.com
- Industry
- TechnologyllmNAICS 513210 · Software Publishers
Incident
- Discovered
- —
- Materiality determined
- Jan 17, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IPCREDENTIALSMETADATA
- Attack vector
- Unauthorized Access· Midnight Blizzard
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- Midnight BlizzardExternalEspionage
- Regulator citations
- Coordinating with federal law enforcement on ongoing investigation
- Initial access
- valid_credentials
Compliance
- Compliance flags
- SEC 4-day late · 51d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jan 17, 2024→ Filed: Mar 8, 202451d cal. 4 business days SEC 4-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.