Midnight Blizzard Data Sharing Request - Email Legitimacy?

Anonymous
2024-06-25T19:37:34+00:00

Hello,

Last night at around 1AM EST our organization received an email from "mbsupport@microsoft.com" with the following:

Action Required – Microsoft Email Data Sharing Request

"This notification is related to the prior attack against Microsoft by the threat actor known as Midnight Blizzard, as disclosed through our 8-K filings and ourMicrosoft blog.

You are receiving this notification because emails were exchanged between Microsoft and accounts in your organization, and those emails were accessed by the threat actor Midnight Blizzard as part of their cyber-attack on Microsoft.

As part of our commitment to transparency, we are proactively sharing these emails. We have custom built a secure system to enable the approved members of your organization to review the exfiltrated emails between Microsoft and your company.  

In order to grant access to the above-referenced emails, you are required to identify authorized individuals within your organization who can nominate reviewers. As needed, please reach out to the appropriate parties in your organization who have the authority to nominate reviewers to view these emails.

At the bottom of this email is a link which will take you to a secure form where you will be asked to provide the following information:

     • Your organization’s TenantID
              o If you do not know or are unsure of your TenantID, please follow the steps outlined here: https://aka.ms/gettenantid
     • The access code located at the bottom of this email
     • The email addresses for individuals within your organization who can nominate reviewers who will be granted access to the set of exfiltrated emails.

Once you complete this form, Microsoft will contact those who have been identified with instructions on how to identify reviewers. 

Should you or your organization require support during this process please work with your Customer Success Account Manager (CSAM) or account representative(s) to open a support case and reference Microsoft Email Data Sharing.  Microsoft continues to prioritize transparency and learnings from events like these to help protect customers and our own enterprise.

Our investigation is ongoing, if we discover new information, we will tell you as soon as practicable."

Secure Link: https://purviewcustomer.powerappsportals.com/?dnaynpyvmule

This email has several red flags for me, the request for the TenantID and essentially admin or high level email addresses, the powerapps page being barebones, and some quick Googling not finding anything related to the title of this email or it's contents. Can anyone confirm this is a legit Microsoft email request?

Thanks,

Zack Murray

Microsoft 365 and Office | Subscription, account, billing | For business | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2024-07-08T21:36:30+00:00

Yes, it is legit.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Zhangliu 375 Reputation points
    2024-06-25T20:36:24+00:00

    you should contact Microsoft support team for this case: Get support - Microsoft 365 admin | Microsoft Learn

    Was this answer helpful?

    0 comments No comments