Summer 2023 Microsoft Exchange Online Intrusion
Incident Impacts | Data Theft |
---|---|
Affected Sector | Ministries of Foreign Affairs, Technology, National Government |
Associated Intrusion Sets | Storm-0558 |
In May and June 2023, Microsoft Exchange Online was compromised by Storm-0558, a threat actor linked to the People's Republic of China. The actor accessed mailboxes using authentication tokens signed by a key created by Microsoft in 2016.
The intrusion affected 22 organizations and over 500 individuals globally, including senior U.S. government officials. The U.S. State Department first detected the intrusion on June 15, 2023.
Microsoft invalidated the stolen key used by the attackers and began notifying impacted parties. The company also updated its security measures to prevent similar incidents in the future.
The US Cyber Safety Review Board (CSRB) concluded that the intrusion was preventable and resulted from a series of security failures at Microsoft. The CSRB also found that Microsoft had been unable to confirm how the key was obtained by the intrusion set. Recommendations were issued for Microsoft and other cloud service providers to improve security practices.
Cyber Threat Graph Context
Explore how this cyber incident relates to the wider threat graph
Summer 2023 Microsoft Exchange Online Intrusion Threat Reports
Review of the Summer 2023 Microsoft Exchange Online Intrusion
This report by the US Cyber Safety Review Board presents the findings of an investigation into compromise of Microsoft Exchange Online mailboxes ...