Skip to content

Microsoft

Disclosed Dec 31, 20205 years agoConfirmed

Official notice

SolarWinds attackers view Microsoft source code repositories

Microsoft found malicious SolarWinds Orion code in its environment and later said the actor viewed files in some source code repositories and downloaded component code for small subsets of Azure, Intune and Exchange, with no access to production services or customer data found.

What is known

People affectedNot stated in the sources we have
DisclosedDec 31, 2020
AttackSupply chain
Data exposedSource code
SectorTech · US
StatusConfirmed
Part ofSolarwinds (2020)

Sources

Source
Important steps for customers to protect themselves from recent nation-state cyberattacksblogs.microsoft.com · The organization
Microsoft Internal Solorigate Investigation Updateweb.archive.org · The organization
Microsoft Internal Solorigate Investigation: Final Updateweb.archive.org · The organization

Notices filed

WhereFiledPeople
ResearchtotalDec 31, 2020

Same campaign

Other breaches at Microsoft

BreachAffected
Hijacked Microsoft GitHub repos pushed password stealers to AI coding tool usersJun 83 months agoSupply chainUnverifiedUnknown
Microsoft 365 Copilot Chat bug processed confidential-labeled emails for weeksFeb 187 months agoAI or modelUnverifiedUnknown
Storm-2139 used stolen customer credentials to hijack Azure OpenAI accountsFeb 26, 20251 year agoCredential stuffingUnknown
Russian state hackers access Microsoft senior leadership email accountsJan 19, 20242 years agoHackingUnknown
AI research team's overly permissive SAS token exposed 38TB of internal dataSep 18, 20233 years agoExposed dataUnverifiedUnknown
China-based Storm-0558 forges tokens with stolen Microsoft key to read government emailJul 11, 20233 years agoHackingUnknown
Misconfigured Microsoft storage exposes prospective customer business dataOct 19, 20223 years agoExposed dataUnverifiedUnknown
Lapsus$ compromises a Microsoft account and leaks Bing and Cortana source codeMar 22, 20224 years agoHackingUnknown
Hafnium exploits Exchange Server zero-days to breach on-premises mail serversMar 2, 20215 years agoHackingUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Microsoft

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.