Details of The Breach
Recently Hewlett-Packard Enterprise (HPE) disclosed a significant breach in its cloud-hosted email environment, which occurred in May 2023. This breach, carried out by the notorious Russian threat actor known as Midnight Blizzard, Nobleium, Cozy Bear, and APT29, resulted in the exfiltration of sensitive data from select company email accounts. This disclosure was made public through a Form 8-K SEC filing on January 19.
The targeted accounts belonged to a small but critical segment of HPE’s workforce, including individuals from cybersecurity, marketing, and business departments. HPE became aware of this intrusion on December 12, 2023, and has since been collaborating with external cybersecurity experts to gauge the full extent of this attack. This breach follows an earlier incident in June 2023, where unauthorized access to HPE’s SharePoint files was detected, pointing to a pattern of persistent cyber espionage by Midnight Blizzard.
This news comes on the heels of a similar admission by Microsoft, who, just last week, disclosed a breach of their corporate systems by the same group. According to a recent blog post by Microsoft, the attack was identified on January 12, with indications that the breach began in November 2023. The attackers focused on email accounts belonging to Microsoft’s senior leadership and employees in key areas such as cybersecurity and legal departments. Using a password spray attack, the threat actor accessed Microsoft’s network through a legacy non-production test account and subsequently targeted specific email accounts for information related to Midnight Blizzard and Russian cyber operations. Microsoft is now committed to overhauling its security protocols, particularly for its legacy systems.
Midnight Blizzard, linked to Russia’s Foreign Intelligence Service (SVR), has been active since 2009, initially focusing on political intelligence gathering. Its tactics have evolved over time, shifting towards technology companies post-2018, with a heightened focus following the notorious SolarWinds breach in December 2020. This shift was highlighted in a December 2023 advisory from the US Cybersecurity and Infrastructure Security Agency (CISA), which also identified CVE-2023-42793, a vulnerability in JetBrains TeamCity, as a recent target of the group.
The SVR’s exploitation of CVE-2023-42793 in JetBrains TeamCity poses a significant threat, granting them access to source code, signing certificates, and software compilation processes. While there has been no repeat of a SolarWinds-scale attack using this access, the potential for escalated privileges, lateral movement, and persistence within networks remains a concerning possibility.
The incidents at HPE and Microsoft underscore the heightened need for robust cybersecurity measures across the tech industry, amidst an increasingly complex and sophisticated threat landscape.


