Incident · 8-K Item 1.05
Microsoft discloses nation-state access to senior leadership email accounts
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
Microsoft told investors on January 19, 2024 that a nation-state associated threat actor had been inside a very small percentage of its corporate email accounts since late November 2023, including mailboxes of senior leaders. The company detected the activity on January 12, 2024, a week before filing.
The original disclosure
The accounts belonged to members of the senior leadership team and to staff in cybersecurity, legal and other functions. Microsoft said it cut off the intruder's email access on or about January 13. At filing, the company reported no material impact on operations and had not determined whether its finances would be materially affected.
March 2024 amendment
The 8-K/A filed March 8, 2024 widened the account. Microsoft said the actor had used what it took from the mailboxes to reach, or try to reach, source code repositories and internal systems, and that the effort was continuing. The company described increased security spending and said further unauthorized access could occur.
What is not in the filings
Neither filing names the actor or gives a count of affected accounts beyond the percentage wording.
Sources
- 2024-01-19 · AMicrosoft Corporation, Form 8-K (SEC EDGAR), published January 19, 2024
- 2024-03-08 · AMicrosoft Corporation, Form 8-K/A (SEC EDGAR), published March 8, 2024
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.