Microsoft Data Breach Investigation

Data Breach Blog

Data Breach

Microsoft Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

July 26, 2026

by: Almeida Law Group

Almeida Law Group is investigating a data breach at Microsoft. The breach occurred on an unspecified date and was discovered on an unspecified date. If you were affected, contact Almeida Law Group.

About Microsoft

Microsoft is a global technology company headquartered in Redmond, Washington. It develops software, cloud computing platforms (Azure), productivity suites (Microsoft 365), operating systems (Windows), and enterprise services. The company is one of the largest in the world by revenue. The ransomware group ExfilSquad has alleged that approximately 8 million records were taken, purportedly including employee and customer contact information, authentication data, password hashes, and related corporate data, but these are unverified attacker claims and Microsoft has not confirmed any such incident.

What Happened?

Microsoft was listed in a corroborated ransomware report attributed to a group calling itself ExfilSquad. The claim, first observed on July 26th, 2026, alleges that roughly 8 million records were exfiltrated, described by the attacker as containing significant personally identifiable information, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions. No breach date, discovery date, consumer notification date, or confirmed affected-person count has been reported. These allegations should be treated with considerable skepticism: ExfilSquad does not appear in any known threat intelligence database, security vendor report, or ransomware tracking platform, and Microsoft has not confirmed or disclosed any incident matching this claim.

The two independent sources cited as corroboration do not confirm the ExfilSquad claim. They describe entirely separate threat campaigns targeting Microsoft 365 customers, not Microsoft Corporation itself. The first, reported by BleepingComputer, describes an aggressive password-spraying campaign that generated more than 81 million login attempts against Microsoft 365 customer environments between approximately June 12th, 2026 and June 26th, 2026, compromising 78 accounts across 64 organizations and attributed to infrastructure operated under the name LSHIY LLC. The second describes an ongoing vishing campaign, active since approximately April 2026, by a threat group tracked as O-UNC-066 or Pink, which uses fake security calls to trick Microsoft 365 users into enrolling attacker-controlled Entra passkeys for data extortion purposes. Neither article mentions ExfilSquad or a direct breach of Microsoft’s own systems or data. Microsoft has a documented history of security incidents, including a January 2024 disclosure that Russian state-backed hackers known as Midnight Blizzard compromised corporate email accounts via password spraying beginning in November 2023.

Key Facts at a Glance

  • Company or Organization: Microsoft
  • Industry: Technology
  • Location: Redmond, Washington, United States
  • Incident type: Unverified ransomware claim (ExfilSquad); separately confirmed password-spraying and vishing campaigns targeting Microsoft 365 customers
  • Prior breach: January 2024 — Midnight Blizzard (Russian state-backed) compromised Microsoft corporate email accounts via password spraying beginning November 2023
  • Source: Ransomware.live corroborated ransomware report (record 8ffb19cd99315db2ddf3e643); https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-365-accounts-with-81-million-login-attempts/; https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/

What Should You Do?

If you use Microsoft 365 or other Microsoft services and are concerned about your account security, there are practical steps you can take now. Enable multi-factor authentication on all Microsoft accounts if you have not already done so, and review your account’s recent sign-in activity for any unfamiliar locations or devices. Place a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — and monitor your credit reports for free at AnnualCreditReport.com. Be alert to unsolicited phone calls asking you to enroll a new passkey or approve any security request you did not initiate, as vishing campaigns are actively targeting Microsoft 365 users. If you believe your identity has already been misused, visit IdentityTheft.gov for step-by-step recovery guidance.

Your Legal Rights

If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.