Hewlett Packard Enterprise (HPE) and Microsoft have reported breaches by a nation-state-associated threat actor, known as Midnight Blizzard or Cozy Bear, which was previously responsible for the SolarWinds hack in 2020.

The disclosures by HPE and Microsoft in their regulatory filings followed the U.S. Securities and Exchange Commission's (SEC’s) newly enacted rules, mandating publicly traded companies to report material cybersecurity incidents.

HPE disclosed in its recent Form 8-K that the company was notified on December 12, 2023, that a suspected nation-state actor, identified as Midnight Blizzard, gained unauthorized access to HPE's cloud-based email environment.

Based on its investigation with the assistance of external cybersecurity experts, the breach involved the exfiltration of data from “a small percentage of HPE mailboxes”, targeting individuals in its cybersecurity, go-to-market, business segments and other functions, beginning in May 2023.

HPE added the incident is likely related to an earlier activity by the same hacking group that involved unauthorized access and exfiltration of SharePoint files dating back to May last year. The company claims it took immediate containment and remediation measures intended to eradicate the activity.

While the full impact and scope of the incident remains under investigation, HPE said it has been cooperating with law enforcement and is assessing regulatory notification obligations.

“As of the date of this filing, the incident has not had a material impact on the company’s operations, and the company has not determined the incident is reasonably likely to materially impact the company’s financial condition or results of operations,” HPE wrote.

The same group hacked Microsoft

Similarly, Microsoft disclosed its breach in a Form 8-K filed earlier this month. The tech giant detected unauthorized access and information exfiltration from “a very small percentage of employee email accounts” in late November 2023. This hack targeted members of the senior leadership team and employees in cybersecurity, legal and other functions.

Microsoft's security team identified the perpetrator as Midnight Blizzard. The company wrote in a blog post that the threat actor used a password spray attack to compromise a legacy non-production test tenant account to gain a foothold, then used the account’s permissions to access the breached Microsoft corporate email accounts.

The investigation also showed the hacking group was targeting email accounts for information related to Midnight Blizzard itself.

Microsoft emphasized that the breach did not result from a vulnerability in its products or services. “To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or artificial intelligence (AI) systems,” it wrote.

The company warns the incident highlighted the continued risks posed to all organizations by well-resourced nation-state threat actors like Midnight Blizzard. “For Microsoft, this incident has highlighted the urgent need to move even faster. We will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes, even when these changes might cause disruption to existing business processes.”