Microsoft says Chinese hackers gained access to US government email accounts and had access to at least some accounts for a month before the breach was detected
https://www.cisa.gov/... JosephMenn / @JosephMenn@infosec.exchange : Friday night news dump came on Tuesday this week. Free gift link: Chinese hackers breach gov email accounts via Microsoft cloud. https://wapo.st/3PPopsz Twitter: Laura Rozen / @lrozen : 🧵State Dept spox: “The Dept of State detected anomalous activity, took immediate steps to secure our systems, & will continue to closely monitor & quickly respond to any further activity. As a matter of cybersecurity policy, we do not discuss details of our response & https://twitter.com/... Scott Piper / @0xdabbad00 : Regarding this Storm-0558 news, I'm more interested in how the actor acquired the MSA key and the mitigations for that. https://msrc.microsoft.com/... Eric Geller / @ericgeller : Potentially big: Microsoft says Chinese hackers accessed the email accounts of people at 25 organizations, including government agencies, by forging authentication tokens with a stolen signing key. https://msrc.microsoft.com/... https://blogs.microsoft.com/ ... [image] @arekfurt : Just a little bit more detail on the MS cloud breach in this official blog post. But a key sentence: “They did this by using forged authentication tokens to access user email using an acquired Microsoft account (MSA) consumer signing key.” 😲 https://blogs.microsoft.com/ ... @arekfurt : Redmond's PR people and lobbyists must be absolutely losing their minds right now. Just read this, for example: https://www.washingtonpost.com/ ... @wavesblog : “Inside the government, the attack showed a significant cybersecurity gap in Microsoft's defenses and raised serious questions about the security of cloud computing, the person briefed on the intrusion said.” https://twitter.com/... Adam Levin / @adam_k_levin : “We need to have some serious conversations about how much hacking we'll tolerate before taking action.” https://www.nytimes.com/... Forums: r/neoliberal : Chinese intelligence hacked U.S. government emails in ‘significant’ breach r/technews : Chinese hackers raided US government email accounts by exploiting Microsoft cloud bug r/technology : Chinese hackers raided US government email accounts by exploiting Microsoft cloud bug r/cybersecurity : Chinese Hackers Breached Government Email Accounts, Microsoft Says r/China : Chinese hackers breach U.S. government email through Microsoft cloud
Context & Ripple Effects
This report put a major cloud identity failure at the center of a government espionage incident. Subsequent coverage indicated the affected mailbox set included the U.S. ambassador to China and a senior East Asia official, raising the operational significance beyond a generic account compromise.
The episode later acquired a more concrete technical explanation: Microsoft said the attackers used a consumer signing key taken from a crash dump after an engineer’s account was compromised. That links the government exposure to controls over signing keys and internal engineering environments.
First-order effects
- Microsoft and the affected U.S. agencies must contain the unauthorized mailbox access, investigate its scope, and assess what information may have been exposed during the roughly month-long access window.
- The State Department’s detection and system-securing response makes government email tenants an immediate focus for credential, token, and audit-log review.
Second-order effects
- The incident increases pressure on Microsoft to demonstrate stronger protection, isolation, and monitoring around identity-signing infrastructure used by cloud customers.
- Government cloud customers are likely to scrutinize whether a provider-side identity failure can bypass their own account protections, especially for sensitive diplomatic users.
Third-order effects
- If comparable compromises continue, cloud identity systems will be treated less as interchangeable IT infrastructure and more as critical security dependencies subject to deeper government oversight and assurance demands.
- The later Midnight Blizzard access to Microsoft source-code repositories and internal systems suggests the broader issue is persistent state interest in provider internals, not only end-user mailboxes.
The trend: State-linked cyber operations are increasingly targeting the identity and internal control planes of major cloud providers to reach high-value government and enterprise users.