CRITICALApt
Verified
Europe

APT29 Targets European Cloud Service Providers in Operation CloudJack

Sunday, March 22, 2026 at 12:00 PM UTC·Source: Microsoft / ANSSI

Updated: Monday, March 23, 2026 at 08:00 AM UTC

Executive Summary

APT29 compromises two European cloud hosting providers to access customer environments. Hundreds of EU government and enterprise tenants at risk.

Analysis

Microsoft and ANSSI report that APT29 compromised administrative access at two mid-tier European cloud hosting providers, gaining potential access to hundreds of EU government and enterprise customer environments. The operation, dubbed CloudJack, used stolen admin OAuth tokens to move laterally through customer tenants. Affected providers have initiated incident response and customer notifications.

Timeline

Discovered
Mar 15, 2026
Exploitation Detected
Mar 15, 2026
Published
Mar 22, 2026
Source Attribution

Originally published by Microsoft / ANSSI on Mar 22, 2026. Verified by: Microsoft, ANSSI, ENISA.

Related Threats