/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says Chinese hackers who in June breached US government email accounts stole an MSA key from a crash dump after hacking a Microsoft engineer's account

Microsoft says Storm-0558 Chinese hackers stole a signing key used to breach government email accounts from a Windows crash dump …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

The June incident had already established that attackers used a Microsoft key to reach email at roughly 25 organizations, after the State Department alerted Microsoft to the compromise. This account narrows the reported path to that key: a compromised engineer account and a Windows crash dump.

The explanation also arrives amid disagreement over the key's possible reach: [[a:842371|researchers had warned that the compromised signing key might enable access beyond the initially described email services]], a claim Microsoft disputed. That makes the provenance of the key central to assessing both the incident and its boundaries.

First-order effects

  • Microsoft can tie the government-email intrusion to a specific chain involving an engineer-account compromise and a crash dump containing an MSA signing key, rather than an unexplained key exposure.
  • Affected government customers gain a more concrete account of how the attackers obtained the credential used in the email breach, which had remained undetected for at least part of a month in earlier reporting.

Second-order effects

  • The finding puts greater scrutiny on how highly privileged signing material can persist in diagnostic artifacts and on the controls around employee accounts that can reach them.
  • The unresolved scope debate remains consequential: earlier reporting on the key's potentially broader access means Microsoft and customers must distinguish the documented email impact from any wider exposure.

Third-order effects

  • If crash-dump handling and employee-access paths repeatedly become routes to cloud signing material, cloud-security assessments will increasingly focus on operational telemetry and internal identity controls, not only customer-facing service defenses.
  • The episode reinforces a shift toward treating identity-signing infrastructure as critical shared-cloud risk; the extent of that shift will depend on whether providers disclose and remediate comparable key-management failures.

The trend: Major cloud breaches are increasingly being assessed through the security of internal identity and signing-key operations, where a single credential can bridge provider systems and many customers.

Discussion

  • @erikkannike Erik Kannike on x
    This is a case study on really how advanced the advanced persistent threats are. Impressive capability by Chinese actors to jump through hoops in order to compromise high value targets:
  • @lopp Jameson Lopp on x
    A crash dump in Microsoft's production environment accidentally included their highly sensitive signing key and was copied to their less secure debugging environment, which threat actors gained access to by compromising an engineer's corporate account. https://msrc.microsoft.com/…
  • @ericgeller Eric Geller on x
    As for how a consumer signing key could access enterprise accounts, Microsoft says that when it introduced a new key authentication system in 2018, it failed to require automatic validation of consumer vs. enterprise access. Email platform was updated to use that system in 2022. …
  • @rayredacted @rayredacted on x
    Yikes [image]
  • @bing_chris Chris Bing on x
    All things equal: Connecting the dots back to a crash dump from ... 2021.. seems like some impressive investigative work.
  • @arekfurt @arekfurt on x
    Microsoft has posted a blog saying it has found the likely explanation (though it deleted via log rotation the logs that would have proved this😬) for loss of its token signing key in the MS cloud breach earlier this year: Bloody crash dumps: https://msrc.microsoft.com/... [image]
  • @mattjay Matt Johansen on x
    Holy shit is right. This write up is great and unsettling. Either the attacker got extremely lucky or they are good enough to have found the key in the trash that was missed multiple times.
  • @hackinglz Justin Elze on x
    Does this qualify as “series of unfortunate events” seems more like a group with a goal finding a way
  • @joshgnosis Josh Taylor on x
    Jeez, this is a journey. Quite good seeing Microsoft being this transparent about things.
  • @swiftonsecurity @swiftonsecurity on x
    Holy shit Microsoft figured out how their signing key was leaked https://msrc.microsoft.com/...
  • @lindellyehuda Yehuda Lindell on x
    This is a fascinating read and a confirmation of MPC systems that don't have any key whole on any machine. https://msrc.microsoft.com/...
  • @tomlawrencetech @tomlawrencetech on x
    How Microsoft lost keys which lead to a much larger compromise. There are five “this issue has been corrected” events in this write up: https://msrc.microsoft.com/... [image]
  • @a_greenberg Andy Greenberg on x
    Two months ago, Microsoft admitted Chinese hackers had obtained a cryptographic key that let them forge access tokens and get into 25 organizations' emails. Now they've revealed how they think it happened, and it is truly a Series of Unfortunate Events. https://msrc.microsoft.com…
  • @ericgeller Eric Geller on x
    Chinese email hack update: Microsoft says a system failure created a crash dump that improperly contained a consumer signing key, which was then moved to an internet-connected network, which was accessible to an engineer whose account was compromised. https://msrc.microsoft.com/.…
  • @johnhultquist John Hultquist🌻 on x
    Good job by MSFT getting to the bottom of this. Was the adversary after debugging info for exploit development and got lucky? Maybe a wider lesson here on the value of this info. https://msrc.microsoft.com/...
  • @arekfurt @arekfurt on x
    So the post outlines several engineering mistakes that allowed this probable vector for the key to leak to a developer's ordinary-security level PC. And allowed that consumer key to then be used to steal enterprise emails. But what concerns me far more are architectural issues.
  • @bettersafetynet @bettersafetynet on x
    How the signing key got stolen. IMO a must read for all infosec practitioners https://msrc.microsoft.com/... I am very appreciative of MSFT for the level of detail they've released here. I wish it were a little faster, but IDK? maybe it took them a while to get this done?
  • @swiftonsecurity @swiftonsecurity on x
    [image]
  • @lopp Jameson Lopp on x
    This really goes to show how difficult it is to keep keys secure when they are stored on networked machines. https://twitter.com/...
  • @bettersafetynet @bettersafetynet on x
    Side tweet: I'm already seeing some snarky and frankly stupid takes about this report. I frequently do table top assessments. Had I run this as a scenario, most orgs would find this threat unrealistic. That MSFT could even tell how this happened puts them in the 0.01% 1
  • @bettersafetynet @bettersafetynet on x
    After chatting w/ someone who wants OPSEC. This MSFT signing attack targeted a dev. They're now *the* target. They've been special for so long they don't have the controls needed that others I think we need to rethink dev systems. 1
  • r/technology r on reddit
    Microsoft finally explains cause of Azure breach: An engineer's account was hacked
  • r/InfoSecNews r on reddit
    Hackers stole Microsoft signing key from Windows crash dump