Microsoft disclosed via SEC Form 8-K Item 1.05 that on January 12, 2024 it detected a nation-state associated threat actor (Midnight Blizzard) had, beginning in late November 2023, gained access to and exfiltrated information from a very small percentage of employee email accounts, including senior leadership and staff in cybersecurity and legal functions. Access was removed on or about January 13, 2024. The incident had no material operational impact as of the filing date.