Skip to content
Microsoft · Cloud and hostingFiled Jan 19, 2024

Microsoft discloses a material cybersecurity incident

Material cybersecurity incidentSecurityUpdated 17h ago
Disclosed
Jan 19, 2024
Records
Not stated
Industry
Software and IT services
Filings
2
Data involved
Not listed by the filing.
SEC filing

What the filing says

On January 12, 2024, Microsoft (the "Company" or "we") detected that beginning in late November 2023, a nation-state associated threat actor had gained access to and exfiltrated information from a very small percentage of employee email accounts including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, on the basis of preliminary analysis. We were able to remove the threat actor's access to the email accounts on or about January 13, 2024. We are examining the information accessed to determine the impact of the incident.

Timeline

  1. Amended filing · Mar 8, 00:00 UTC
    8-K/A: As disclosed in the Original Filing, the Company detected that beginning in late November 2023, a nation-state threat actor had gained access to and exfiltrated information from a very small percentage of employee email accounts including members of our senior leadership team and employees in our cybersecurity, legal, and other functions. Since the date of the Original Filing, the Company has determined that the threat actor used and continues to use information it obtained to gain, or attempt to gain, unauthorized access to some of the Company's source code repositories and internal systems. The threat actor's ongoing attack is characterized by a sustained, significant commitment of the thr

From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.

Weekly: the week's major outages, postmortems and breaches, Saturday mornings.