A report says the Microsoft key that Chinese hackers stole could have given them more access than originally assumed; Microsoft disputes the report
Microsoft is disputing a new report that claims hackers may have had access to more parts of victims' systems than previously known in a campaign … Source: Wiz Blog .
The RecordJonathan Greig
Context & Ripple Effects
The dispute follows reporting that Microsoft’s disclosures of Chinese hackers’ access to U.S. government email accounts left the role of its own vulnerabilities insufficiently clear. The new claim centers on whether a compromised signing key had a wider trust boundary than the affected email services Microsoft described.
Wiz researchers separately argued that the key could enable access beyond Outlook.com and Exchange Online, while Microsoft rejected that interpretation. The disagreement matters because the scope of a signing key determines whether an incident is treated as a contained service breach or a broader identity-control failure.
First-order effects
Microsoft must rebut or substantiate the reported limits of the stolen key, while affected customers face continued uncertainty over which systems and credentials warranted review.
Security teams using Microsoft cloud services have reason to reassess whether their incident-response assumptions were limited to email, rather than the key’s potential authorization reach.
Second-order effects
The conflicting accounts increase pressure for clearer technical disclosure from Microsoft and independent validation of cloud-provider breach scopes; customers may demand more evidence before accepting containment claims.
The episode reinforces scrutiny of Microsoft’s security controls after earlier reporting questioned its breach disclosures, including the account of the government-email intrusion.
Third-order effects
If cloud signing keys can create access paths spanning multiple services, security assurance will increasingly depend on how providers isolate signing authority, disclose blast radius, and enable customer-side detection.
Repeated disputes over state-linked intrusions could shift enterprise buying toward providers and architectures that make identity trust boundaries more independently auditable, though this report alone does not establish a market shift.
The trend: This is one data point in the growing focus on cloud identity and signing infrastructure as a concentrated source of systemic breach risk.
This @wiz_io blog post on the compromised Microsoft signing key (used by Storm-0558), confirms what many were worried about, but had no confirmation of: The scope the key was trusted in is MUCH larger than we thought. Let's review why that's an issue. 1/ https://www.wiz.io/...
This is a great and important blog post on some aspects of the Microsoft cloud breach that have been ascertained by open source analysis of info about the abused signing key and MS's auth systems. The implications for what is affected are worth thought. https://www.wiz.io/... [im…
😲 While Microsoft reported that the threat actors compromised Exchange Online and https://outlook.com/, the actual scope of at-risk applications was much broader!
@SwiftOnSecurity The Wiz's analysis is excellent. They got more detail than I would have superficially thought possible just by focusing on the what specific signing key was used and looking at the accompanying public info + information available about how Microsoft's cloud auth …
🔑 The compromised Microsoft signing key potentially allows the threat actors to forge access tokens for ALL Microsoft's personal account services and any Azure Active Directory (AAD) applications supporting both multi-tenancy and Microsoft's OpenID v2.0 implementation. [image]
The @wiz_io research team dug into Microsoft's recently disclosed compromise of an MSA key and discovered that the potential impact was much broader than many initially understood. Our new blog shares details & recommendations for Azure app owners: https://www.wiz.io/...
This is pretty high praise of the Wiz write up on the Microsoft compromise, which I found impressively detailed but could not judge technically. https://www.wiz.io/...
Vendors will jump on big events and sometimes not really contribute more than what's in the original blog post plus some commentary, this adds to the discussion.