The U.S. Department of Homeland Security's Cyber Safety Review Board (CSRB) has released a scathing report on how Microsoft handled its 2023 Exchange Online attack, warning that the company needs to do better at securing data and be more truthful about how threat actors stole an Azure signing key. Microsoft believes that last May's Exchange Online hack is linked to a threat actor known as 'Storm-0558' stealing an Azure signing key from an engineer's laptop that was previously compromised by the hackers at an acquired company. Storm-0558 is a cyberespionage actor affiliated with China that has been active for more than two decades targeting a wide range of organizations. Almost 10 months after Microsoft started the investigation, the CSRB states there isn’t any definitive evidence on how the threat actor obtained the signing key, regardless of what Microsoft previously claimed. The CSRB conducted its analysis of the Microsoft Exchange Online hack in 2023 based on details obtained from impacted organizations, cybersecurity companies and experts, law enforcement agencies, and meetings with Microsoft representatives. The report notes that Microsoft learned of the intrusion after being alerted by the U.S. State Department on June 16, 2023. Signs of the intrusion on the State Department’s mail systems appeared a day earlier when the organization’s security operations center (SOC) observed anomalous access. Multiple security alerts appeared the next day thanks to a custom rule, int...
Microsoft still unsure how hackers stole MSA key in 2023 Exchange attack
BleepingComputer
·Ionut Ilascu
·Published Apr 4, 2024
·Updated
Affected Software
7 affected components
Microsoft Exchange Online
Microsoft Azure
Microsoft Microsoft Services Account (MSA)
Microsoft Microsoft 365 Government G5
Microsoft Purview Audit
Microsoft OpenID Connect (OIDC) endpoint service
Microsoft Microsoft Entra
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the recent findings of the Cyber Safety Review Board regarding the 2023 Exchange Online attack on Microsoft.
2
What security implications are discussed in the article?
The article highlights concerns about Microsoft's data security practices and the unanswered questions surrounding the breach.
3
What specific Microsoft products are affected by the security incident?
Affected Microsoft products include Exchange Online, Azure, Microsoft Services Account (MSA), Microsoft 365 Government G5, Purview Audit, OpenID Connect endpoint service, and Microsoft Entra.
4
Who released the report critiquing Microsoft’s security handling?
The report was released by the U.S. Department of Homeland Security's Cyber Safety Review Board (CSRB).
5
What recommendations were made to Microsoft in the report?
The report urges Microsoft to improve its data security measures to better protect against future breaches.