Chinese hackers breach U.S. government email through Microsoft cloud

Discussion in 'other security issues & news' started by hawki, Jul 12, 2023.

  1. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "Chinese cyberspies exploited a fundamental gap in Microsoft’s cloud, enabling them to conduct a targeted hack of unclassified U.S. email accounts — a troubling vulnerability officials said was discovered by the U.S. government.

    The security problem was discovered last month after the U.S. government identified a hole in Microsoft’s cloud security, which affected unclassified systems, according to the White House...

    Microsoft disclosed late Tuesday that it had mitigated an attack by “a China-based threat actor” [Storm-0558] that primarily targets government agencies in Western Europe and focuses on espionage and data theft...

    They did this by using forged authentication tokens to access user email using an acquired Microsoft account consumer signing key..."

    https://www.msn.com/en-us/news/tech...ent-email-through-microsoft-cloud/ar-AA1dKgTx
     
  2. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    107,930
    Location:
    U.S.A.
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    OK, so this was probably yet again a successful phishing attack, that allowed hackers to get access to some MS employee account. It's really time to make the switch to phishing-resistant MFA, because it's getting out of control.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.