• News/
  • https://www.theregister.com/2024/04/03/cisa_microsoft_exchange_attack_report/

Microsoft slammed for lax infosec that led to Exchange crack

The Register
·
Simon Sharwood
·
Published Apr 3, 2024
·
Updated

A review of the June 2023 attack on Microsoft's Exchange Online hosted email service – which saw accounts used by senior US officials compromised by a China-linked group called "Storm-0558" – has found that the incident would have been preventable save for Microsoft's lax infosec culture and sub-par cloud security precautions. The review, conducted by the Cybersecurity and Infrastructure Security Agency's Cyber Safety Review Board, calls for "rapid cultural change" at Microsoft. Among the Board's recommendations: That strong language was offered in light of the attack, which it attributed to a "cascade of Microsoft's avoidable errors." The CSRB report [PDF] pins the attack on key rotation practices used to secure the Microsoft Services Account (MSA) – the identity management system underpinning the software giant's cloudy services for consumers. MSA was designed in the early 2000s, without a process for automated signing key rotation or deactivation. Microsoft therefore managed keys manually – but stopped doing so in 2021 after the practice caused a major cloud outage. Between 2021 and the breach in 2023, Microsoft did not employ any tool that would alert it to keys that should be retired. So when Storm-0558 obtained a key created in 2016, which should have been retired, it gained the ability to access the version of Outlook Web Access offered to consumers. Things escalated from there because a flaw in Microsoft's systems meant that the 2016 MSA key could create tokens that a...

Read full article

Affected Software

3 affected components
Microsoft Exchange Online
Microsoft MSA
Microsoft Outlook Web Access
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a review of a security breach in Microsoft's Exchange Online service linked to a Chinese hacking group.

2

What security implications are discussed in the article?

The article discusses the vulnerabilities in Microsoft's information security practices that led to the compromise of senior US officials' accounts.

3

What group is responsible for the attack mentioned in the article?

The hacking group responsible for the attack is identified as "Storm-0558," which is linked to Chinese state-sponsored actors.

4

What products are specifically affected by the security incident?

The affected products include Microsoft Exchange Online, Microsoft MSA, and Microsoft Outlook Web Access.

5

What recommendations are suggested in the article to improve security?

The article suggests that Microsoft needs to enhance its security measures to prevent similar incidents in the future.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203