Russian hackers have implicated Microsoft further than initially reported.

The company has begun notifying additional individuals that emails shared have been accessed, according to Bloomberg.

The group who orchestrated the attack is known as Midnight Blizzard or Nobelium. They also orchestrated the 2020 SolarWinds hack.

This group has been previously linked to the Russian Foreign Intelligence Service.

Microsoft has already informed some individuals about their emails being accessed, however, now specifics are being shared.

A spokesperson said, “This week we are continuing notifications to customers who corresponded with Microsoft corporate email accounts that were exfiltrated by the Midnight Blizzard threat actor, and we are providing the customers the email correspondence that was accessed by this actor.”

“This is increased detail for customers who have already been notified and also includes new notifications.”

Microsoft has been notifying customers via email, which initially led to concern about phishing scams.

The hack was first disclosed by Microsoft in January. They revealed a password spray attack provided the group with access to “a very small percentage of Microsoft corporate email accounts,” back in late 2023.

Compromised employees included members of the senior leadership, cybersecurity, and legal teams.

Microsoft revealed at the time that system vulnerabilities were not to blame for the attack but said it would improve security.

The US Government is now watching Microsoft following a report by the Cyber Safety Review Board, which found the company’s “security culture was inadequate and requires an overhaul.”

An order was issued by the US Cybersecurity and Infrastructure Security Agency (CISA) in April, which required federal agencies to analyse email hackings and secure cloud accounts.

All impacted agencies were notified and required to provide regular updates on steps taken to prevent the “grave and unacceptable risk.”