The U.S. Department of Homeland Security released a Cyber Safety Review Board report concluding that the Summer 2023 intrusion into Microsoft Exchange Online by Storm-0558, a threat group linked to the People’s Republic of China, was preventable and resulted from a cascade of Microsoft security failures. The breach affected 22 organizations and 503 individuals worldwide, including senior U.S. officials, and led to the theft of about 60,000 State Department emails. The board said Microsoft still does not know how the attackers obtained a critical signing key, rejected the company’s earlier crash-dump explanation as unproven, and faulted Microsoft for weak logging, delayed remediation, and failing to detect the intrusion itself.
The review said Microsoft’s operational and strategic decisions reflected a corporate culture that deprioritized enterprise security investment and rigorous risk management, and it called for direct CEO and board oversight of security, accountability for senior officers, and stronger protections across Microsoft’s cloud products. The report also issued broader recommendations for cloud providers and government, including stronger identity and authentication controls, default audit logging, improved disclosure and victim notification, and updates to federal cloud security frameworks; DHS said CISA will convene major cloud service providers to align on those practices.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2024-05-03, Microsoft CEO Satya Nadella said security would become the company's top priority in response to the CSRB's findings on the Storm-0558 incident. He said Microsoft would expand its Secure Future Initiative across core security domains and tie security performance to hiring, rewards, and part of senior leadership compensation.
Alongside the report’s release, the board recommended stronger identity controls, default audit logging, better disclosure and victim notification, and updates to federal cloud security frameworks. DHS said CISA would convene major cloud service providers to align on security practices based on the report’s recommendations.
On 2024-04-02, DHS released the Cyber Safety Review Board’s report on the summer 2023 Microsoft Exchange Online intrusion. The board concluded the incident was preventable, criticized Microsoft’s security culture and operational decisions, and said the company still did not know how the attackers obtained the key.
In summer 2023, attackers attributed to Storm-0558 infiltrated Microsoft-hosted email accounts by abusing a signing key, affecting 22 organizations and 503 individuals worldwide. Victims included senior U.S. officials, and about 60,000 State Department emails were stolen.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
blogs.microsoft.com
Open sourcetechtarget.com
Open sourcetherecord.media
Open sourcedhs.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.