Other

Storm-0558 Microsoft Exchange Online hack β€” US State Department and 22 organisations

πŸ“… 2023-05-15 🏒 Microsoft Exchange Online / Microsoft Azure AD (Entra ID)
Primary Source β†—

Incident Details

Storm-0558, a Chinese state-sponsored threat actor (attributed to MSS), acquired a Microsoft MSA consumer token signing key (method of acquisition still unclear as of CSRB review) and used it to forge authentication tokens granting access to Exchange Online mailboxes at 22 organisations and 503+ individuals globally. Attack began 15 May 2023. US State Department discovered the intrusion 15 June 2023 via anomaly detection and alerted Microsoft. Approximately 60,000 State Department emails downloaded. US Commerce Department Secretary Gina Raimondo’s email also compromised. CSRB review (March 2024) concluded the breach was ’entirely preventable’ and cited a ‘cascade of Microsoft security failures.’ Separate from the November 2023 Midnight Blizzard/Cozy Bear attack on Microsoft.

Technical Details

Initial Attack Vector
CWE-287: Improper Authentication (forged authentication tokens using a stolen Microsoft MSA consumer signing key; used to access Exchange Online accounts across enterprise and personal tenants)
Vendor / Product
Microsoft Exchange Online / Microsoft Azure AD (Entra ID)

Timeline

  1. 2023-05-15 Breach occurred
  2. 2023-07-11 Publicly disclosed
  3. 2023-07-11 Customers notified