The Russian state-sponsored group Midnight Blizzard exploited a legacy non-production test tenant account via a password spray attack. The group used this initial footprint to compromise senior leadership mailboxes, extracting proprietary corporate communications and system defense notes.