• News/
  • https://www.theregister.com/2024/04/03/cisa_microsoft_exchange_online_china_report/

Microsoft slammed for lax security that led to China's cyber-raid on Exchange Online

The Register
·
Simon Sharwood
·
Published Apr 3, 2024
·
Updated

A review of the June 2023 attack on Microsoft's Exchange Online hosted email service – which saw accounts used by senior US officials compromised by a China-linked group called "Storm-0558" – has found that the incident would have been preventable save for Microsoft's lax infosec culture and sub-par cloud security precautions. The review, conducted by the US government's Cybersecurity and Infrastructure Security Agency's Cyber Safety Review Board (CSRB), calls for "rapid cultural change" at Microsoft. Among the Board's recommendations: That strong language was offered in light of the attack, which it attributed to a "cascade of Microsoft's avoidable errors." The CSRB report [PDF] pins the attack on key rotation practices used to secure the Microsoft Services Account (MSA) – the identity management system underpinning the software giant's cloudy services for consumers. MSA was designed in the early 2000s, without a process for automated signing key rotation or deactivation. Microsoft therefore managed keys manually – but stopped doing so in 2021 after the practice caused a major cloud outage. Between 2021 and the breach in 2023, Microsoft did not employ any tool that would alert it to keys that should be retired. So when Storm-0558 obtained a key created in 2016, which should have been retired, it gained the ability to access the version of Outlook Web Access offered to consumers. Things escalated from there because a flaw in Microsoft's systems meant that the 2016 MSA key cou...

Read full article

Affected Software

3 affected components
Microsoft Exchange Online
Microsoft Outlook Web Access
Microsoft Microsoft Services Account (MSA)
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a cyber-attack on Microsoft's Exchange Online service by a China-linked group and the subsequent criticism of Microsoft's security measures.

2

What security implications are discussed in the article?

The article highlights the vulnerabilities in Microsoft's security that allowed state-sponsored actors to compromise accounts of senior US officials.

3

What groups are implicated in the cyber-raid mentioned in the article?

The cyber-raid is attributed to a group known as 'Storm-0558', which is linked to China.

4

What products or software are affected according to the article?

The affected products include Microsoft Exchange Online, Outlook Web Access, and Microsoft Services Account (MSA).

5

What was the date of the cyber-attack reviewed in the article?

The cyber-attack on Microsoft Exchange Online occurred in June 2023.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203