Midnight Blizzard and the SolarWinds Lesson We Forgot
Microsoft's disclosure that Midnight Blizzard accessed its corporate email in early 2024 through a password spray attack is a reminder that nation-state actors do not always need zero-days. Sometimes a weak password on a legacy test account is enough.
Introduction
In January 2024, Microsoft disclosed that Midnight Blizzard, the Russian SVR-linked threat actor also known as Cozy Bear, had accessed a small percentage of corporate email accounts including those of senior leadership and security teams. The initial access vector was not a zero-day exploit or a sophisticated supply chain attack. It was a password spray against a legacy non-production test tenant account that did not have multi-factor authentication enabled.
The Attack Chain
Midnight Blizzard identified a legacy OAuth test application with elevated permissions within Microsoft's environment. By compromising the test account through password spraying, they were able to use that application's permissions to access Microsoft 365 email accounts.
This is a textbook example of what security teams call a forgotten asset problem. The account existed from an earlier period, had never been cleaned up, lacked MFA, and had permissions that should not have existed on a non-production account.
Why This Matters Beyond Microsoft
The instinct when reading about a breach at a company like Microsoft is to think it does not apply to smaller organisations. The opposite is true. Microsoft has more security resources than almost any organisation on earth. If a legacy test account without MFA can be the entry point there, it can absolutely be the entry point at your company.
Every organisation accumulates forgotten assets over time. Test accounts created for integrations that were later abandoned. Service accounts whose owners left the company. OAuth applications granted broad permissions for a proof of concept that never got cleaned up.
What Midnight Blizzard Did After Getting In
Once inside, the actor focused on intelligence collection rather than destructive activity. They accessed emails related to Midnight Blizzard itself, looking to understand what Microsoft knew about their operations and TTPs. This is a consistent pattern with SVR operations — they are patient, methodical, and focused on long-term intelligence value.
Defensive Lessons
Audit your OAuth applications. Know every application that has permissions in your Microsoft 365 or Google Workspace environment. Revoke anything that is not actively used and justified.
Eliminate legacy authentication. Block basic authentication protocols across your environment. Password spraying works because legacy auth bypasses MFA.
MFA on everything. There is no category of account that is too unimportant for MFA. Test accounts, service accounts, shared mailboxes — all of them.
Privileged Access Workstations. Accounts with elevated permissions should only be accessible from dedicated, hardened devices.
Conclusion
Midnight Blizzard did not beat Microsoft with sophisticated malware. They found a door that should have been locked years ago and walked through it. The lesson is not that we need better zero-day defences. The lesson is that hygiene matters more than we want to admit.