City
Epaper

Chinese hackers accessed US govt emails by exploiting bug: Microsoft

By IANS | Updated: July 12, 2023 19:00 IST

San Francisco, July 12 Microsoft has revealed that Chinese hackers have exploited a flaw in its cloud email ...

Open in App

San Francisco, July 12 Microsoft has revealed that Chinese hackers have exploited a flaw in its cloud email service to gain access to email accounts affecting approximately 25 organisations including government agencies as well as related consumer accounts of individuals likely associated with these organisations. 

The tech giant has published details of activity by a China-based actor it is tracking as "Storm-0558".

"We have been working with the impacted customers and notifying them prior to going public with further details. At this stage -- and in coordination with customers -- we are sharing the details of the incident and threat actor to benefit the industry," said Charlie Bell, Executive Vice President, Microsoft Security.

This China-based hacking group is focused on espionage, such as gaining access to email systems for intelligence collection. This type of espionage-motivated adversary seeks to abuse credentials and gain access to data residing in sensitive systems.

"Our investigation revealed that beginning on May 15, 2023, Storm-0558 gained access to email data from approximately 25 organizations, and a small number of related consumer accounts of individuals likely associated with these organizations," the company said in its latest blog post.

They did this by using forged authentication tokens to access user email using an acquired Microsoft account (MSA) consumer signing key. Microsoft said it has completed mitigation of this attack for all customers.

"We added substantial automated detections for known indicators of compromise associated with this attack to harden defenses and customer environments, and we have found no evidence of further access," said the company.

"We've also been partnering with relevant government agencies like the Department of Homeland Security's (DHS) Cybersecurity and Infrastructure Security Agency (CISA). We are thankful they and others are working with us to help protect affected customers and address the issue," the tech giant added.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Microsoft accountCharlie bellmicrosoftMicrosoft TheaterMicrosoft IndiaMicrosoft HololensMicrosoft TeamsMicrosoft OfficeMicrosoft ResearchMicrosoft AzureMicrosoft Azure CloudMicrosoft Research India
Open in App

Related Stories

InternationalIsrael: Massive Fire After Iranian Missile Hits Building Near Microsoft Office in Beer Sheva (Watch Videos)

TechnologyIT Layoffs 2025: Microsoft, Google, Apple Among 284 Tech Companies That Cut Jobs in First 5 Months

TechnologyMicrosoft Layoffs: Satya Nadella-led Company Sacks Over 6,000 Employees Across Key Positions

TechnologyWhy Is Skype Shutting Down? Microsoft's Video-Calling Platform to Retire on May 5

Business‘Microsoft Is a Digital Weapons Manufacturer’: Indian-American Engineer Calls Out Gates, Ballmer, Nadella Over AI Ties to Gaza War (Watch Video)

International Realted Stories

InternationalPakistan: Karachi's water crisis deepens as power outage halts key pumping station

InternationalTrump administration escalates legal battles with Los Angeles

InternationalChina continues to persecute its Uyghur populace

InternationalPakistani security forces abduct another Baloch woman in Turbat, marking alarming pattern of enforced disappearances

InternationalWithout EV subsidies, Musk to close up shop, head back home to South Africa: Trump