Business
Chinese hackers accessed US govt emails by exploiting bug: Microsoft
San Francisco, July 12
Microsoft has revealed that Chinese hackers have exploited a flaw in its cloud email service to gain access to email accounts affecting approximately 25 organisations including government agencies as well as related consumer accounts of individuals likely associated with these organisations.
The tech giant has published details of activity by a China-based actor it is tracking as "Storm-0558".
"We have been working with the impacted customers and notifying them prior to going public with further details. At this stage -- and in coordination with customers -- we are sharing the details of the incident and threat actor to benefit the industry," said Charlie Bell, Executive Vice President, Microsoft Security.
This China-based hacking group is focused on espionage, such as gaining access to email systems for intelligence collection. This type of espionage-motivated adversary seeks to abuse credentials and gain access to data residing in sensitive systems.
"Our investigation revealed that beginning on May 15, 2023, Storm-0558 gained access to email data from approximately 25 organizations, and a small number of related consumer accounts of individuals likely associated with these organizations," the company said in its latest blog post.
They did this by using forged authentication tokens to access user email using an acquired Microsoft account (MSA) consumer signing key. Microsoft said it has completed mitigation of this attack for all customers.
"We added substantial automated detections for known indicators of compromise associated with this attack to harden defenses and customer environments, and we have found no evidence of further access," said the company.
"We've also been partnering with relevant government agencies like the Department of Homeland Security's (DHS) Cybersecurity and Infrastructure Security Agency (CISA). We are thankful they and others are working with us to help protect affected customers and address the issue," the tech giant added.
7 hours ago
AAPI Global Health Summit 2026 in Odisha Showcases Cutting‑Edge Resuscitation Training, AI‑Driven Clinical Education, and India’s National Emergency Life Support Program
7 hours ago
Inany conducts health fair in Staten Island
7 hours ago
EAM Jaishankar and visiting Greek defence minister discuss key strategic and security issues
7 hours ago
PM Modi very charismatic and phenomenal leader: Polish Secretary of State
8 hours ago
India–EU FTA ‘game-changing development’ in bilateral ties, says EAM Jaishankar
8 hours ago
Delighted to participate in the India-Seychelles Business Forum in Chennai today during the State Visit of H.E. Dr. Patrick Herminie, President of Seychelles.
13 hours ago
Sonam Kapoor says 'Fantastic dad' after witnessing Anil Kapoor's teaser poster for 'Subedaar'
13 hours ago
Shalmali Kholgade reveals how she flipped the narrative of love with her new song ‘Impression’
13 hours ago
Rohit Shetty firing case: IMPPA writes to CM Devendra Fadnavis requesting immediate intervention
13 hours ago
CM Omar Abdullah presents Rs 1,13,767 crore budget in J&K Assembly; focusing on investment, innovation
13 hours ago
Naveen Patnaik expresses concern over missing Odia merchant navy cadet, appeals for urgent action
13 hours ago
Oppn protests outside Bihar Legislative Council; Rabri Devi raises farmers' issues
13 hours ago
Search and rescue operation underway as tiger prowls near Rajahmundry in Andhra Pradesh
