logo

Microsoft slammed for lax security that led to China's cyber-raid on Exchange Online

ID: 3b8975f9-d897-5289-92aa-a98b882b84e7

STIX ID: report--3b8975f9-d897-5289-92aa-a98b882b84e7

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-04-03

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

The CSRB review of the June 2023 Microsoft Exchange Online intrusion finds that China-linked APT "Storm-0558" exploited a long-lived Microsoft Services Account (MSA) signing key—created in 2016 and not retired—to forge tokens that accessed enterprise mailboxes, enabling the theft of roughly 60,000 Department of State emails and employee addresses; the board attributes the incident to avoidable failures in Microsoft’s key rotation, detection, and security culture and urges senior-led, timeline-driven reforms across the company’s cloud services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.