Midnight Blizzard, a hacking group with suspected ties to Russia’s SVR intelligence agency, reportedly breached Home Office data last year following an attack on Microsoft, a corporate partner of the government department.
According to Freedom of Information requests, first reported by The Record, the Russian hacking group accessed corporate emails and data that had been shared with Microsoft, in what was described by officials as “nation state attack on [a] supplier” of government systems.
The data breach happened in January this year, with the Home Office reporting the incident to the Information Commissioner’s Office on May 2nd 2024. A spokesman for the department told The Record: “There is no evidence that Home Office systems were compromised. We take data security very seriously, with robust reporting mechanisms in place, and continuous monitoring to ensure data is protected.”
Although the Home Office has stressed that its own systems were not hacked, the news follows reports that Midnight Blizzard (also known as Nobelium, Cozy Bear, and APT29) had previously accessed the email accounts of senior leaders at Microsoft, along with its source code repositories and internal systems.
The attack on Microsoft formed part of a hacking campaign in which Midnight Blizzard took advantage of security gaps in the company’s legacy test OAuth application to grant elevated permissions allowing access to Office 365 accounts, including Microsoft corporate emails.
Those emails were not only between internal Microsoft executives, but also impacted corporate partners around the world, including in the United States where the U.S. Cybersecurity and Infrastructure Security Agency warned that federal government data had been exposed by the hack.
Since then, questions have been raised about both the internal and external security considerations of the company, with the US Department of Homeland Security’s Cyber Safety Review Board concluding in an incident report that Microsoft’s security culture was “inadequate and requires an overhaul”.
Recommended reading
- CrowdStrike Reveals Global Outage Details
- CrowdStrike Incident | Lessons Learned and Key Questions Answered
- Mass IT Outages Reported Worldwide
For its part, Microsoft says that customer-facing systems were not compromised after the January attack, noting that the hackers accessed a small percentage of Microsoft’s corporate email accounts and that affected customers were notified.
The threat posed to sensitive data and critical government systems has increased dramatically in recent years, especially the risks associated with hacking by hostile nations such as Russia. Vulnerabilities within the cyber-supply chain are routinely exploited by well funded and resourced groups such as Midnight Blizzard leading to potential real world consequences for individuals, national security, and critical infrastructure.
James Sullivan, the director of cyber-research at the Royal United Services Institute think tank, told The Record: “Similar to Crowdstrike, this incident affecting Microsoft shows how our use of just a few providers for critical services sets us up for single points of failure when there are breaches or outages. We may need to think about greater vendor diversity to spread the risk out and give organisations more resilience.”





