MSFT 마이크로소프트 MICROSOFT CORP
FORM 8-K/A AMENDED
ITEM 1.05 · 7.01 · 9.01 2024-03-08
0001193125-24-062997 08:58 EST
한국시간 2024-03-08 22:58 KST
- 1.05 중대 사이버보안 사건 중요 항목
- 7.01 Regulation FD 공시
- 9.01 재무제표 및 첨부문서
이 공시는 앞서 제출된 공시의 정정본입니다. 내용은 이 문서를 기준으로 확인하세요.
한국어 요약
MS, 러시아 해커 '미드나잇 블리자드' 공격 관련 8-K/A 제출…소스코드 접근 시도 확인
- 마이크로소프트는 2024년 1월 19일 제출한 8-K를 정정하는 8-K/A를 2024년 3월 8일 제출했다. 정정공시에서 회사는 국가 후원 공격자가 2023년 11월 말부터 일부 임직원 이메일 계정에 접근해 정보를 빼갔으며, 이후 이 정보를 이용해 일부 소스 코드 저장소와 내부 시스템에 대한 무단 접근을 얻거나 시도하고 있다고 밝혔다.
- 회사는 이번 사건이 현재까지 운영에 중대한 영향을 미치지 않았으며, 재무 상태나 영업 결과에 중대한 영향을 미칠 것으로 합리적으로 예상되지는 않는다고 판단하고 있다.
- 마이크로소프트는 2024년 3월 8일 이번 공격에 관한 블로그를 게시했고, 이를 8-K/A의 Exhibit 99.1로 첨부했다. 블로그에서 회사는 공격 주체를 러시아 정부 후원 해커 그룹 '미드나잇 블리자드(Midnight Blizzard, 일명 NOBELIUM)'로 식별했으며, 2월 들어 비밀번호 스프레이 공격(패스워드 스프레이) 규모가 1월 대비 최대 10배로 증가했다고 밝혔다.
담은 것 이 공시는 마이크로소프트가 앞서 제출한 8-K(2024년 1월 19일)를 정정·보완하는 8-K/A로, 중대 사이버보안 사건(Item 1.05)의 진행 상황과 Regulation FD 공시(Item 7.01) 및 첨부문서(Item 9.01)를 담고 있다. 회사가 공격자에 의해 유출된 정보가 소스 코드 저장소와 내부 시스템에 대한 무단 접근에 사용되고 있다는 추가 조사 결과를 공개하고, 관련 블로그를 첨부한 문서다.
담지 않은 것 이번 공시에는 공격으로 유출된 구체적인 데이터의 종류나 규모, 고객 피해 사례에 대한 세부 정보는 포함되지 않았다.
- nation-state threat actor
- 국가 후원 공격자
- Midnight Blizzard
- 러시아 정부 후원 해커 그룹(일명 NOBELIUM)
- source code repositories
- 소스 코드 저장소
- password sprays
- 비밀번호 스프레이 공격
원문 발췌 3건
- As disclosed in the Original Filing, the Company detected that beginning in late November 2023, a nation-state threat actor had gained access to and exfiltrated information from a very small percentage of employee email accounts including members of our senior leadership team and employees in our cybersecurity, legal, and other functions. Since the date of the Original Filing, the Company has determined that the threat actor used and continues to use information it obtained to gain, or attempt to gain, unauthorized access to some of the Company’s source code repositories and internal systems.
- As of the date of this filing, the incident has not had a material impact on the Company’s operations. The Company has not yet determined that the incident is reasonably likely to materially impact the Company’s financial condition or results of operations.
- On March 8, 2024, the Company posted a blog regarding the incident. A copy of the blog is furnished as Exhibit 99.1 to this report.
원문
이 사이트의 모든 내용은 SEC에 공시된 공개 자료를 AI가 요약한 것으로, 투자 자문이나 매매 권유가 아닙니다. AI 요약은 오류를 포함할 수 있으니 반드시 원문을 확인하세요. 투자 판단과 그 결과에 대한 책임은 이용자 본인에게 있습니다.