오늘의 공시 미국 SEC 공시를 한국어로

MSFT 마이크로소프트 MICROSOFT CORP

FORM 8-K RECEIVED
ITEM 1.05 · 7.01 · 9.01 2024-01-19
0001193125-24-011295 16:39 EST
한국시간 2024-01-20 06:39 KST
  • 1.05 중대 사이버보안 사건 중요 항목
  • 7.01 Regulation FD 공시
  • 9.01 재무제표 및 첨부문서

한국어 요약

마이크로소프트, 러시아 정부 연계 해커의 이메일 침해 사건 공시

  • 마이크로소프트는 2024년 1월 12일, 러시아 정부가 후원하는 위협 행위자 'Midnight Blizzard'(일명 Nobelium)가 2023년 11월 말부터 소수의 임직원 이메일 계정에 접근해 일부 이메일과 첨부 문서를 유출했다는 사실을 탐지했다.
  • 공격은 비생산 테스트 계정에 대한 패스워드 스프레이 공격으로 시작됐으며, 마이크로소프트 제품이나 서비스의 취약점 때문은 아니고 현재까지 고객 환경, 프로덕션 시스템, 소스 코드, AI 시스템에 접근한 증거는 없다.
  • 이번 사건은 현재까지 회사 운영에 중대한 영향을 미치지 않았으며, 재무 상태나 영업 성과에 중대한 영향을 미칠 가능성은 아직 결정되지 않았다.

담은 것 이 8-K는 마이크로소프트가 탐지한 중대 사이버보안 사건(Item 1.05)과 관련 블로그 게시(Item 7.01)를 공시한다. 블로그 전문은 첨부문서(Exhibit 99.1)로 제출됐다.

담지 않은 것 이번 공시에는 침해된 이메일 계정의 정확한 수나 유출된 정보의 구체적 내용은 포함되지 않았다.

패스워드 스프레이 공격
여러 계정에 흔한 비밀번호를 반복 대입해 접근 권한을 얻는 공격 방식이다.
테넌트 계정
클라우드 서비스에서 조직 단위로 부여되는 계정으로, 이번 사건에서는 레거시 비생산 테스트 계정이 침해됐다.
원문 발췌 5건
  1. On January 12, 2024, Microsoft (the “Company” or “we”) detected that beginning in late November 2023, a nation-state associated threat actor had gained access to and exfiltrated information from a very small percentage of employee email accounts including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, on the basis of preliminary analysis.
  2. As of the date of this filing, the incident has not had a material impact on the Company’s operations. The Company has not yet determined whether the incident is reasonably likely to materially impact the Company’s financial condition or results of operations.
  3. Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium.
  4. Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.
  5. The attack was not the result of a vulnerability in Microsoft products or services. To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems.

원문

생성 deepseek/deepseek-v4-flash-0731 · 2026-08-07

이 사이트의 모든 내용은 SEC에 공시된 공개 자료를 AI가 요약한 것으로, 투자 자문이나 매매 권유가 아닙니다. AI 요약은 오류를 포함할 수 있으니 반드시 원문을 확인하세요. 투자 판단과 그 결과에 대한 책임은 이용자 본인에게 있습니다.