Storm-2949 Cyberattack Targets Microsoft 365 and Azure Data

Storm-2949 Cyberattack Targets Microsoft 365 and Azure Data

First seen 19 May 2026, 07:18 UTC Blogs.MicrosoftThecyberexpressGbhackersBleepingcomputerScworld 79% similarity 71.0

Article Content

Browse articles
ThreatCluster

Microsoft has reported a significant cyberattack by the threat actor Storm-2949, which exploited Microsoft Entra ID accounts to conduct a large-scale data theft from Microsoft 365 and Azure environments. The attack involved social engineering tactics to compromise high-privilege user accounts, using the Self-Service Password Reset (SSPR) process to reset passwords and bypass multi-factor authentication (MFA). Once inside, the attackers utilized Microsoft Graph API and custom Python scripts to enumerate users and access sensitive data, including VPN configurations and operational files. They expanded their reach into Azure infrastructure, compromising virtual machines, storage accounts, and Azure Key Vaults to extract critical secrets and credentials. The attack exemplifies a shift towards using legitimate cloud management features for malicious purposes, avoiding traditional malware deployment. Microsoft has confirmed that multiple organizations have been affected, with ongoing investigations into the full scope of the breach.

Key Points: • Storm-2949 exploited Microsoft Entra ID accounts to steal sensitive data from Microsoft 365 and Azure. • Attackers used social engineering to bypass MFA and reset passwords of high-privilege accounts. • The breach involved extensive data theft, including VPN configurations and Azure Key Vault secrets.

ThreatCluster AI

Timeline

2026-05-18
Microsoft discloses Storm-2949 attack details
Microsoft revealed that Storm-2949 exploited identities to conduct a cloud-wide breach, focusing on data theft from Microsoft 365 and Azure.
Blogs.Microsoft
2026-05-19
BleepingComputer reports on SSPR abuse
BleepingComputer detailed how Storm-2949 abused the Self-Service Password Reset process to hijack accounts and exfiltrate data.
Bleepingcomputer
2026-05-19
Thecyberexpress covers attack methodology
Thecyberexpress outlined the attack's methodology, including the use of social engineering and cloud management tools to conduct the breach.
Thecyberexpress
2026-05-19
Gbhackers reports on data exfiltration
Gbhackers reported on the sophisticated techniques used by Storm-2949 to exploit Entra ID accounts and steal data.
Gbhackers

Community

Browse all →