First it was "a very small percentage of Microsoft corporate email accounts" (their C-suite executives and security teams) and "To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems."
Then it was "access to some of the company's source code repositories and internal systems. To date we have found no evidence that Microsoft-hosted customer-facing systems have been compromised."
And now this.