← Blog

Microsoft Data Breaches: Full Timeline Through 2026

Share on X

People search Microsoft data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 24 Microsoft-linked incidents, with headline counts up to 500M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why Microsoft breach history matters

Microsoft operates in Technology (United States). Across indexed rows, recurring themes include credential theft and social engineering, cloud and database misconfiguration, third-party and supply-chain exposure, zero-day exploitation and malware, unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2026 — LSHIY password-spray campaign bypasses MFA via ROPC (Jun)

Cataloged incident. Huntress reported an ongoing password-spray campaign targeting Microsoft Azure CLI and Entra ID tenants between June 12 and June 26, 2026, originating primarily from IPv6 ranges tied to LSHIY LLC (AS32167). The firm observed more than 81 million failed login attempts across its customer base and confirmed 78 user-account compromises spanning 64 organizations—spiking to 30 identities on June 22 alone. Attackers validated stolen username/password pairs via the deprecated OAuth Resource Owner Password Credentials (ROP Exposed categories include At least 78 compromised Microsoft 365 user accounts across 64 customer organizations in Huntress telemetry (June 12–26, 2026); attackers reused combo-list credentials not covered b. BreachHistory cites approximately 78 affected records in this row. See the microsoft-azure-cli-lshiy 2026 record and canonical BreachHistory entry.

2024 — Russian SVR group breach of corporate email (Cozy Bear)

Cataloged incident. Microsoft discovered a breach by a Russian SVR foreign intelligence group on January 12. The incident occurred in November 2023 via password spraying against Microsoft's corporate email system. Cozy Bear (linked to SolarWinds) compromised a legacy test account and accessed senior leadership accounts. Access was removed on January 13. Exposed categories include Email addresses, Passwords. No attested victim count is published for this row yet. See the tms2401 and canonical BreachHistory entry.

2024 — — Source code

Cataloged incident. Hacked. Source code. Exposed categories include Names, emails, addresses, and other PII. No attested victim count is published for this row yet. See the microsoft2024 and canonical BreachHistory entry.

2023 — 60k State Department emails stolen (Storm-0558)

Cataloged incident. Chinese hackers (Storm-0558) stole over 60,000 State Department emails. The breach occurred in July when errors allowed the group to steal a key granting broad access to Microsoft customer accounts, including U.S. government. Exposed categories include Email addresses. BreachHistory cites approximately 60K+ affected records in this row. See the tms2309 and canonical BreachHistory entry.

2023 — Chinese hackers breach U.S. agencies via Microsoft Cloud (Storm-0558)

Cataloged incident. Microsoft disclosed that Chinese group Storm-0558 spied on U.S. government agencies via a vulnerability in Microsoft cloud services. Attack detected in June; targeted State and Commerce department emails. Exposed categories include Email addresses. No attested victim count is published for this row yet. See the tms2307 and canonical BreachHistory entry.

2023 — — Outlook data

Cataloged incident. Hacked. Outlook data. Exposed categories include Names, emails, addresses, and other PII. No attested victim count is published for this row yet. See the microsoft-20232023 and canonical BreachHistory entry.

2022 — BlueBleed: 548k+ users exposed on misconfigured endpoint

Cataloged incident. SOCRadar identified over 2.4 TB of exposed data on a misconfigured Microsoft endpoint—customer emails, project info, signed documents. Microsoft secured the endpoint and disputed scope (duplicates). Exposed categories include Email addresses. BreachHistory cites approximately 548K+ affected records in this row. See the tms2210 and canonical BreachHistory entry.

2022 — Lapsus$ group breaches Microsoft (Azure DevOps)

Cataloged incident. Lapsus$ posted a screenshot from Azure DevOps indicating Bing, Cortana and other projects were compromised. Microsoft confirmed one account hijacked; no customer data compromised. Exposed categories include Details not publicly disclosed. No attested victim count is published for this row yet. See the tms2203 and canonical BreachHistory entry.

2022 — — Source code

Cataloged incident. Lapsus$. Source code. Exposed categories include Names, emails, addresses, and other PII. No attested victim count is published for this row yet. See the microsoft-20222022 and canonical BreachHistory entry.

2021 — 38M records exposed via Power Apps misconfiguration

Cataloged incident. Misconfigured Microsoft Power Apps portals led to at least 47 organizations exposing 38M+ records (American Airlines, Ford, NY MTA, etc.). Data included COVID-19 info, SSNs, addresses. Discovered by UpGuard. Exposed categories include Addresses, Social Security numbers. BreachHistory cites approximately 38M+ affected records in this row. See the tms2108a and canonical BreachHistory entry.

2021 — Azure Cosmos DB vulnerability exposes customer databases

Cataloged incident. Wiz researchers found Cosmos DB flaws allowing full access to customer databases and account data. Microsoft responsible for the loophole. Exposed categories include Details not publicly disclosed. No attested victim count is published for this row yet. See the tms2108b and canonical BreachHistory entry.

2021 — 500M LinkedIn users' data scraped and sold

Cataloged incident. Personal data on 500M+ LinkedIn users posted for sale. LinkedIn stated data was scraped from publicly available profiles; included emails and phone numbers. Exposed categories include Email addresses, Phone numbers. BreachHistory cites approximately 500M+ affected records in this row. See the tms2104 and canonical BreachHistory entry.

2021 — Exchange Server zero-days lead to 60k+ hacks worldwide

Cataloged incident. Four zero-day vulnerabilities in Microsoft Exchange led to widespread hacking—potentially 30k+ U.S. and 60k+ global organizations. Attackers could access data, deploy malware, hijack servers. Hafnium and others implicated. Exposed categories include Details not publicly disclosed. BreachHistory cites approximately 60K+ affected records in this row. See the tms2101 and canonical BreachHistory entry.

2020 — SolarWinds supply chain (nation-state)

Cataloged incident. Nation-state actors compromised SolarWinds Orion software; Microsoft and other enterprises were targeted via the supply chain. Microsoft's own systems were accessed; scope of data access was limited but significant for government and tech targets. Exposed categories include Details not publicly disclosed. No attested victim count is published for this row yet. See the rydm and canonical BreachHistory entry.

2020 — SolarWinds supply chain attack (18k customers, including Microsoft)

Cataloged incident. Russian hackers used SolarWinds malicious updates to reach ~18k customers. Microsoft was among targets; Nobelium later used Microsoft systems to reach Microsoft customers. Malware found on support agent machine in June 2021. Exposed categories include Details not publicly disclosed. BreachHistory cites approximately 18K+ affected records in this row. See the tms2012 and canonical BreachHistory entry.

2020 — — Microsoft: Poor security / misconfiguration, 25,000,000 records

Cataloged incident. Customer support records spanning 14 years were left online without password protection. Exposed categories include Personal and demographic data. BreachHistory cites approximately 25M+ affected records in this row. See the microsoft2020-iib and canonical BreachHistory entry.

2019 — 250M+ customer support records exposed (misconfigured DB)

Cataloged incident. Misconfigured internal customer support database left 250M records exposed Dec 5–31, 2019. PII, support conversations, IPs; data from 2005–2019. Exposed categories include Passwords, Personal identifiable information, Internal documents. BreachHistory cites approximately 250M+ affected records in this row. See the tms1912 and canonical BreachHistory entry.

2019 — Compromised support agent credentials — webmail access

Cataloged incident. Hackers acquired a support agent's credentials and accessed webmail (Outlook, MSN, Hotmail) Jan 1–Mar 28, 2019. Limited dataset: addresses, subject lines, folder names; no content or passwords. Exposed categories include Passwords, Names, Addresses, Credentials. No attested victim count is published for this row yet. See the tms1904 and canonical BreachHistory entry.

2016 — Hundreds of Skype accounts hacked for spam

Cataloged incident. Compromised Skype accounts sent spam; two-factor bypass possible via legacy Skype password. Microsoft released guidance to merge Microsoft/Skype accounts. Exposed categories include Passwords. No attested victim count is published for this row yet. See the tms1611 and canonical BreachHistory entry.

2016 — 33M Hotmail credentials found for sale online

Cataloged incident. 272M stolen credentials found; ~33M were Hotmail. Cache surfaced when a Russian hacker advertised the trove for under $1. Exposed categories include Credentials. BreachHistory cites approximately 33M+ affected records in this row. See the tms1605 and canonical BreachHistory entry.

2014 — — Microsoft: Microsoft Xbox Live networks were hacked by a group…

Cataloged incident. Microsoft Xbox Live networks were hacked by a group called LizardSquad, preventing users from playing games over the holiday. The assault was a DDoS attack (distributed denial-of-service) which harness the Internet connectivity of many hacked or misconfigured systems so that those systems are forced to simultaneously flood target network with junk Internet traffic. The goal, of course, is to prevent legitimate visitors from being able to load the site or use the service under attack.More Informa Exposed categories include Personal information. No attested victim count is published for this row yet. See the microsoft2014 and canonical BreachHistory entry.

2013 — Internal bug-tracking database compromised

Cataloged incident. Internal database used to track bugs in Microsoft products was compromised in 2013 (disclosed 2017). Contained descriptions of vulnerabilities in Windows and other software. Exposed categories include Internal documents. No attested victim count is published for this row yet. See the tms1310 and canonical BreachHistory entry.

2013 — — Microsoft: Microsoft security discovered that a number of…

Cataloged incident. Microsoft security discovered that a number of employee devices were affected by malware.  The employees had visited unsafe websites and downloaded material. It is unclear if the employee devices spread the infection to other areas of Microsoft's network, but Microsoft found no evidence of customer data being affected. Facebook, Twitter, and Apple were affected by a similar issue around the same time. Exposed categories include Personal information. No attested victim count is published for this row yet. See the microsoft2013 and canonical BreachHistory entry.

2010 — IE zero-day used to breach major U.S. companies (e.g. Google)

Cataloged incident. Internet Explorer zero-day allowed attackers to gain admin-level access; used against Google, Adobe and others. Microsoft had been aware months prior; accelerated patch. Exposed categories include Dates of birth. No attested victim count is published for this row yet. See the tms1001 and canonical BreachHistory entry.

Patterns and analysis

  • Credential theft and social engineering — appears across multiple Microsoft catalog entries; prioritize controls that address this class of failure.
  • Cloud and database misconfiguration — appears across multiple Microsoft catalog entries; prioritize controls that address this class of failure.
  • Third-party and supply-chain exposure — appears across multiple Microsoft catalog entries; prioritize controls that address this class of failure.
  • Zero-day exploitation and malware — appears across multiple Microsoft catalog entries; prioritize controls that address this class of failure.
  • Unverified actor or scraping claims — appears across multiple Microsoft catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Review OAuth app permissions and revoke unused third-party integrations.
  5. Step 5: Bookmark the Microsoft company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/microsoft · Latest: microsoft-azure-cli-lshiy2026.

Sources: BreachHistory catalog (24 rows for Microsoft), company and regulator disclosures cited in individual breach records.