FEDERALItem 1.05 · mandatoryHackingTechnologyInformationSoftwareStolen CredentialsCapture App DataMidnight BlizzardActor NamedNation State SuspectedData ExfiltratedEmployee Data InvolvedTargetedDelayed DiscoveryOTHERLowContained
Microsoft Corporation
bd_d660c617b3363d6d · schema v1 · pii pii-v1
Full breach record for Microsoft Corporation →Microsoft disclosed via SEC Form 8-K Item 1.05 that on January 12, 2024 it detected a nation-state associated threat actor (Midnight Blizzard) had, beginning in late November 2023, gained access to and exfiltrated information from a very small percentage of employee email accounts, including senior leadership and staff in cybersecurity and legal functions. Access was removed on or about January 13, 2024. The incident had no material operational impact as of the filing date.
SEC clockMateriality determined Jan 17, 2024 → Filed Jan 19, 20242d ✓ SEC 4-day OK7 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_bfb10eaec0a6e100SEC 8-KMidnight Blizzardfiled 2024-03-08(49d gap)Candidate
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/789019/000119312524011295/d708866d8k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 19, 2024
- Raw hash
- 9e47379ea22d69508a44b4183a4b0589002ad99696b24382029ea8859a7aa933
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Microsoft Corporationnorm: microsoft
- SEC CIK
- 0000789019
- Domain
- microsoft.com
Victim entity
- Name
- Microsoft Corporationnorm: microsoft
- SEC CIK
- 0000789019
- Domain
- microsoft.com
- Industry
- TechnologyllmNAICS 513210 · Software Publishers
Incident
- Discovered
- Jan 12, 2024
- Materiality determined
- Jan 17, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- OTHER
- Attack vector
- Unauthorized Access· Midnight Blizzard
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- Midnight BlizzardExternalEspionage
- Regulator citations
- Notifying relevant regulatory authorities with respect to unauthorized access to personal informationFiled SEC Form 8-K under Item 1.05
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 2d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jan 17, 2024→ Filed: Jan 19, 20242d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.