logo

Microsoft Key Breach Incident by Storm-0558 | Cyera Blog

ID: f999cc8f-2140-5364-8759-5f0a47eae8cc

STIX ID: report--f999cc8f-2140-5364-8759-5f0a47eae8cc

Feed Name: Cyera Blogs

Threat Score
90/100

Date Published: 2025-02-28

Date Updated: 2026-05-12

...
...

A China-based threat actor (Storm-0558) exploited consumer signing keys that were accidentally included in a crash dump and moved to a less-secure environment; after compromising a Microsoft engineer's account with access to that environment, the actor forged authentication tokens to access Outlook/Exchange accounts of about 25 organizations including government agencies. Microsoft contacted affected organizations and faced regulatory scrutiny; the report emphasizes how data-centric secrets discovery and controls could have prevented the exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.