Microsoft says Chinese hackers who in June breached US government email accounts stole an MSA key from a crash dump after hacking a Microsoft engineer's account
Microsoft says Storm-0558 Chinese hackers stole a signing key used to breach government email accounts from a Windows crash dump …
BleepingComputer Sergiu Gatlan
Context & Ripple Effects
The June incident had already established that attackers used a Microsoft key to reach email at roughly 25 organizations, after the State Department alerted Microsoft to the compromise. This account narrows the reported path to that key: a compromised engineer account and a Windows crash dump.
The explanation also arrives amid disagreement over the key's possible reach: [[a:842371|researchers had warned that the compromised signing key might enable access beyond the initially described email services]], a claim Microsoft disputed. That makes the provenance of the key central to assessing both the incident and its boundaries.
First-order effects
- Microsoft can tie the government-email intrusion to a specific chain involving an engineer-account compromise and a crash dump containing an MSA signing key, rather than an unexplained key exposure.
- Affected government customers gain a more concrete account of how the attackers obtained the credential used in the email breach, which had remained undetected for at least part of a month in earlier reporting.
Second-order effects
- The finding puts greater scrutiny on how highly privileged signing material can persist in diagnostic artifacts and on the controls around employee accounts that can reach them.
- The unresolved scope debate remains consequential: earlier reporting on the key's potentially broader access means Microsoft and customers must distinguish the documented email impact from any wider exposure.
Third-order effects
- If crash-dump handling and employee-access paths repeatedly become routes to cloud signing material, cloud-security assessments will increasingly focus on operational telemetry and internal identity controls, not only customer-facing service defenses.
- The episode reinforces a shift toward treating identity-signing infrastructure as critical shared-cloud risk; the extent of that shift will depend on whether providers disclose and remediate comparable key-management failures.
The trend: Major cloud breaches are increasingly being assessed through the security of internal identity and signing-key operations, where a single credential can bridge provider systems and many customers.
Related: Microsoft · MSA · Windows · State Department email breach and stolen Microsoft key · Wiz analysis of the compromised MSA signing key
Related Coverage
- Results of Major Technical Investigations for Storm-0558 Key Acquisition Microsoft Security Response Center
- Microsoft finally explains cause of Azure breach: An engineer's account was hacked Ars Technica · Dan Goodin
- Microsoft offers an explanation for the hack of its cloud Ghacks · Martin Brinkmann
- Chinese Hacker Steals Microsoft Signing Key, Spies on US Government Infosecurity · Kevin Poireault
- Microsoft reveals 2021 crash dump led to US State Department hacks ITPro · Ross Kelly
- Microsoft: Storm-0558 Key Acquisition Incident Was Caused by Chinese Crash Dump Hack WinBuzzer · Luke Jones
- Microsoft thinks it knows how Chinese hackers were able to breach US government accounts TechRadar
- Microsoft finds Storm-0558 exploited crash dump to steal signing key ComputerWeekly.com · Alex Scroxton
- Storm-0558: Microsoft breaks its silence on the Chinese threat actor MSPoweruser · Rafly Pratama
- Microsoft explains how a Chinese hacker group was able to access government email accounts Neowin · John Callaham
- The Comedy of Errors That Let China-Backed Hackers Steal Microsoft's Signing Key Wired · Lily Hay Newman
- Microsoft reveals hackers compromised engineer account to gain access to government accounts SiliconANGLE · Duncan Riley
- Microsoft's results of major technical investigations for Storm-0558 key acquisition OSnews · Thom Holwerda
- Microsoft: China stole secret key that unlocked US govt email from crash debug dump The Register · Jessica Lyons Hardcastle
- Crash log exposed Microsoft Outlook keys to threat actor iTnews · Richard Chirgwin
- Crash Dump Error: How a Chinese Espionage Group Exploited Microsoft's Mistakes SecurityWeek · Ryan Naraine
- Microsoft details a chain of mishaps leading to Outlook hack on government officials The Record · Joe Warminsky
- Microsoft Details How Chinese Hackers Acquired Signing Key for Outlook Breach PCMag · Michael Kan
- A Rube Goldberg chain of failures led to breach of Microsoft-hosted government emails The Verge · Wes Davis
- Microsoft: Flaw In Windows Crash Process Enabled Cloud Email Breach CRN · Kyle Alspach
- Mystery solved? Microsoft thinks it knows how Chinese hackers stole its signing key CyberScoop · Eliasgroll
- Breach of Microsoft Engineer's Account Likely Led to Hack of US Officials Bloomberg · William Turton
- This is absolutely crazy stuff. Chinese hackers were able to get into a bunch of government email accounts by forging Microsoft access tokens, but how it happened is wild. — Apparently an internal Microsoft system responsible for signing consumer access tokens crashed, then a bug in the crash dump generator caused the secret key to be written to the crash dump. … @malwaretech@infosec.exchange
- Microsoft's post-mortem into how China-linked attackers accessed cloud email accounts for US gov't organisations is an incredible read, and it shows how a chain of mistakes and vulnerabilities in the cloud can lead to a real mess. The attackers probably couldn't believe their luck. … @jkirk@infosec.exchange · Jeremy Kirk
- After every flight, we did our maintenance paperwork, walked upstairs, put our phones in a wood cubby, and walked into the Mission Planning Room. … Vishal Amin
- Transparency remains a key pillar of how Microsoft does business. Today we published our third blog that describes our learnings about how Storm 0558 … Kelli Andrews
- Microsoft Security Response Center (MSRC) has published the key results of our comprehensive internal investigation into how China-based threat actor … Jeremy Dallman
- On July 11, 2023, Microsoft Security published a blog post which details how the China-Based threat actor, Storm-0558, used an acquired Microsoft account … Vasu Jakkal
- Results of technical investigations for Storm-0558 key acquisition Hacker News
Discussion
-
@erikkannike
Erik Kannike
on x
This is a case study on really how advanced the advanced persistent threats are. Impressive capability by Chinese actors to jump through hoops in order to compromise high value targets:
-
@lopp
Jameson Lopp
on x
A crash dump in Microsoft's production environment accidentally included their highly sensitive signing key and was copied to their less secure debugging environment, which threat actors gained access to by compromising an engineer's corporate account. https://msrc.microsoft.com/…
-
@ericgeller
Eric Geller
on x
As for how a consumer signing key could access enterprise accounts, Microsoft says that when it introduced a new key authentication system in 2018, it failed to require automatic validation of consumer vs. enterprise access. Email platform was updated to use that system in 2022. …
-
@rayredacted
@rayredacted
on x
Yikes [image]
-
@bing_chris
Chris Bing
on x
All things equal: Connecting the dots back to a crash dump from ... 2021.. seems like some impressive investigative work.
-
@arekfurt
@arekfurt
on x
Microsoft has posted a blog saying it has found the likely explanation (though it deleted via log rotation the logs that would have proved this😬) for loss of its token signing key in the MS cloud breach earlier this year: Bloody crash dumps: https://msrc.microsoft.com/... [image]
-
@mattjay
Matt Johansen
on x
Holy shit is right. This write up is great and unsettling. Either the attacker got extremely lucky or they are good enough to have found the key in the trash that was missed multiple times.
-
@hackinglz
Justin Elze
on x
Does this qualify as “series of unfortunate events” seems more like a group with a goal finding a way
-
@joshgnosis
Josh Taylor
on x
Jeez, this is a journey. Quite good seeing Microsoft being this transparent about things.
-
@swiftonsecurity
@swiftonsecurity
on x
Holy shit Microsoft figured out how their signing key was leaked https://msrc.microsoft.com/...
-
@lindellyehuda
Yehuda Lindell
on x
This is a fascinating read and a confirmation of MPC systems that don't have any key whole on any machine. https://msrc.microsoft.com/...
-
@tomlawrencetech
@tomlawrencetech
on x
How Microsoft lost keys which lead to a much larger compromise. There are five “this issue has been corrected” events in this write up: https://msrc.microsoft.com/... [image]
-
@a_greenberg
Andy Greenberg
on x
Two months ago, Microsoft admitted Chinese hackers had obtained a cryptographic key that let them forge access tokens and get into 25 organizations' emails. Now they've revealed how they think it happened, and it is truly a Series of Unfortunate Events. https://msrc.microsoft.com…
-
@ericgeller
Eric Geller
on x
Chinese email hack update: Microsoft says a system failure created a crash dump that improperly contained a consumer signing key, which was then moved to an internet-connected network, which was accessible to an engineer whose account was compromised. https://msrc.microsoft.com/.…
-
@johnhultquist
John Hultquist🌻
on x
Good job by MSFT getting to the bottom of this. Was the adversary after debugging info for exploit development and got lucky? Maybe a wider lesson here on the value of this info. https://msrc.microsoft.com/...
-
@arekfurt
@arekfurt
on x
So the post outlines several engineering mistakes that allowed this probable vector for the key to leak to a developer's ordinary-security level PC. And allowed that consumer key to then be used to steal enterprise emails. But what concerns me far more are architectural issues.
-
@bettersafetynet
@bettersafetynet
on x
How the signing key got stolen. IMO a must read for all infosec practitioners https://msrc.microsoft.com/... I am very appreciative of MSFT for the level of detail they've released here. I wish it were a little faster, but IDK? maybe it took them a while to get this done?
-
@swiftonsecurity
@swiftonsecurity
on x
[image]
-
@lopp
Jameson Lopp
on x
This really goes to show how difficult it is to keep keys secure when they are stored on networked machines. https://twitter.com/...
-
@bettersafetynet
@bettersafetynet
on x
Side tweet: I'm already seeing some snarky and frankly stupid takes about this report. I frequently do table top assessments. Had I run this as a scenario, most orgs would find this threat unrealistic. That MSFT could even tell how this happened puts them in the 0.01% 1
-
@bettersafetynet
@bettersafetynet
on x
After chatting w/ someone who wants OPSEC. This MSFT signing attack targeted a dev. They're now *the* target. They've been special for so long they don't have the controls needed that others I think we need to rethink dev systems. 1
-
r/technology
r
on reddit
Microsoft finally explains cause of Azure breach: An engineer's account was hacked
-
r/InfoSecNews
r
on reddit
Hackers stole Microsoft signing key from Windows crash dump