Summer 2023 Microsoft Exchange Online Intrusion

Incident Impacts Data Theft
Affected Sector Ministries of Foreign Affairs, Technology, National Government
Associated Intrusion Sets Storm-0558

In May and June 2023, Microsoft Exchange Online was compromised by Storm-0558, a threat actor linked to the People's Republic of China. The actor accessed mailboxes using authentication tokens signed by a key created by Microsoft in 2016.

The intrusion affected 22 organizations and over 500 individuals globally, including senior U.S. government officials. The U.S. State Department first detected the intrusion on June 15, 2023.

Microsoft invalidated the stolen key used by the attackers and began notifying impacted parties. The company also updated its security measures to prevent similar incidents in the future.

The US Cyber Safety Review Board (CSRB) concluded that the intrusion was preventable and resulted from a series of security failures at Microsoft. The CSRB also found that Microsoft had been unable to confirm how the key was obtained by the intrusion set. Recommendations were issued for Microsoft and other cloud service providers to improve security practices.

Cyber Threat Graph Context

Explore how this cyber incident relates to the wider threat graph

Summer 2023 Microsoft Exchange Online Intrusion Threat Reports

Report

Review of the Summer 2023 Microsoft Exchange Online Intrusion

This report by the US Cyber Safety Review Board presents the findings of an investigation into compromise of Microsoft Exchange Online mailboxes ...

References