A U.S. Cyber Safety Review Board report sharply criticized Microsoft’s response to the Storm-0558 intrusion that let China-linked attackers access Exchange Online mailboxes by forging authentication tokens with a stolen Microsoft consumer signing key. The campaign began in mid-May 2023 and affected more than 500 individuals across 22 organizations, including senior U.S. government officials; attackers reportedly stole about 60,000 unclassified emails from the U.S. Department of State over at least six weeks. The board said Microsoft still could not definitively explain how the key was obtained, despite earlier statements that tied the theft to crash dumps and a compromised engineer account associated with a prior 2021 intrusion.
The review said Microsoft’s security failures worsened the breach, including retaining a 2016 signing key that should have been revoked in 2021, relying on manual key rotation, and allowing an OIDC/SDK token validation flaw that let a consumer key sign tokens accepted for enterprise email accounts. The incident also exposed major visibility gaps because some customers lacked access to the logs needed to detect the intrusion; in response, Microsoft and CISA expanded access to critical logging, and Microsoft later extended default audit log retention while continuing its technical investigation into the key acquisition.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
In April 2024, the Department of Homeland Security's Cyber Safety Review Board issued a report sharply criticizing Microsoft's handling of the 2023 Exchange Online intrusion. The report said Microsoft still lacked definitive evidence for how the signing key was stolen and highlighted security, logging, and process failures.
On March 12, 2024, Microsoft revised its earlier statement that Storm-0558 likely obtained the key from crash dumps, clarifying that this was only a theory unsupported by evidence. The change came after pressure from the CSRB, according to the report.
In February 2024, Microsoft expanded the default Purview Audit standard log retention period from 90 days to 180 days and provided additional telemetry to federal agencies. This followed work with CISA to make critical logging more broadly available for detecting similar attacks.
In September 2023, Microsoft published results of its technical investigation into how Storm-0558 acquired the signing key. Microsoft said at the time that the actor likely obtained the key from crash dumps.
The U.S. Department of State alerted Microsoft to the intrusion on June 16, 2023. The incident ultimately led to disclosure that about 60,000 unclassified State Department emails were stolen over at least six weeks.
On June 15, 2023, the U.S. Department of State's security operations center observed anomalous access on its mail systems. It detected multiple alerts using a custom 'Big Yellow Taxi' rule based on MailItemsAccessed logs.
Beginning in mid-May 2023, Storm-0558 used forged authentication tokens signed with the 2016 consumer key to access Exchange Online email accounts. The campaign ultimately affected more than 500 individuals across 22 organizations.
A Microsoft Services Account consumer signing key created in 2016 should have been revoked in March 2021. The CSRB found that Microsoft's manual consumer key rotation process and lack of alerts left the old key active.
Microsoft investigated a theory that a 2021 compromise of its corporate network through an engineer's account led to the later theft of the signing key. The CSRB said Microsoft did not produce evidence supporting that theory.
Microsoft acquired Affirmed Networks in 2020. Microsoft later theorized that an engineer device involved in a 2021 compromise had already been compromised before the acquisition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcemsrc.microsoft.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.