Microsoft
Disclosed Jul 11, 20233 years agoConfirmed
China-based Storm-0558 forges tokens with stolen Microsoft key to read government email
Beginning May 15, 2023, the China-based group Storm-0558 used an acquired Microsoft account consumer signing key to forge tokens and read Exchange Online and Outlook.com email at about 25 organizations, including US government agencies. A customer alerted Microsoft on June 16, 2023; the US Cyber Safety Review Board later faulted Microsoft's security culture.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 11, 2023 |
| Discovered | Jun 16, 2023 |
| Attack | Hacking |
| Data exposed | Emails, Messages |
| Sector | Tech · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Microsoft reveals how hackers stole its email signing key, kind oftechcrunch.com · News | News |
| Analysis of Storm-0558 techniques for unauthorized email accessmicrosoft.com · The organization | The organization |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jul 11, 2023 |
Other breaches at Microsoft
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.