News: 1689229570

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft admits unauthorized access to Exchange Online, blames Chinese gang

(2023/07/13)


US commerce secretary Gina Raimondo and other State and Commerce Department officials were [1]reportedly among the victims of a China-based group's attack on Microsoft's hosted email services.

The widespread reports cite "unnamed officials" as their source and note that the US State Department denies that any classified systems were breached or any data was stolen.

The US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI issued a [2]joint advisory detailing how a Federal Civilian Executive Branch (FCEB) agency was tipped off when it observed MailItemsAccessed events with an unexpected ClientAppID and AppID in Microsoft 365 Audit Logs – as the AppId did not normally access mailbox items in that manner.

[3]

The FCEB agency reported the activity to Microsoft, which confirmed threat actors accessed customer email accounts through Outlook Web Access in Exchange Online (OWA) and exfiltrated unclassified data. Microsoft said it was made aware of the hack on June 16, but had kept it under wraps while "working with the impacted customers and notifying them prior to going public with further details."

[4]

[5]

Redmond said the threat actor had operated since May 15, when it gained access to email data from around 25 organizations and other associated consumer accounts. Entry was forced by forging email authentication tokens with an acquired Microsoft accounts (MSA) consumer signing key.

[6]US and China trade chiefs aim for cool heads as chip wars heat up

[7]US authorities warn on China's new counter-espionage law

[8]Chinese spies blamed for data-harvesting raids on Barracuda email gateways

[9]Micron chips in $600M for China memory facility despite Beijing sanctions

Microsoft, which [10]reported the event on Tuesday, attributed the attacks to a China-based threat actor it tracks as Storm-0558.

"We assess this adversary is focused on espionage, such as gaining access to email systems for intelligence collection. This type of espionage-motivated adversary seeks to abuse credentials and gain access to data residing in sensitive systems," the software titan wrote.

US Department of State spokesperson Matthew Miller [11]said [VIDEO] on Wednesday the department "noted the attribution Microsoft has made" – but that the agency would not make a public attribution at this time.

[12]

CISA said Microsoft addressed the issue by blocking tokens issued with the acquired key and changing the key. Microsoft stated it has completed mitigation of this attack for all customers, including implementing automated detections for known indicators of compromise. It also asserted there is no evidence of further illicit access.

Secretary Raimondo [13]met with her Chinese counterpart, Wang Wentau, ten days following the May 15 breach to discuss strained relations.

China has an obvious interest in reading any thoughts she shared in email about that meeting.

[14]

On Wednesday, China's Foreign Ministry spokesperson Wang Wenbin used the agency's [15]regular press conference to point a finger back at the US – calling it "the world's biggest hacking empire and global cyber thief." ®

Get our [16]Tech Resources



[1] https://abcnews.go.com/Politics/commerce-secretary-gina-raimondos-emails-hacked-microsoft-cyber/story?id=101201179

[2] https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-193a

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZK-LR1IkuHbgIaGndRMwaQAAAMc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZK-LR1IkuHbgIaGndRMwaQAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZK-LR1IkuHbgIaGndRMwaQAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/05/26/us_china_trade_talks/

[7] https://www.theregister.com/2023/07/03/china_espionage_law_update_warning/

[8] https://www.theregister.com/2023/06/15/chinese_spies_behind_barracuda_esg/

[9] https://www.theregister.com/2023/06/16/micron_investment_china_plant/

[10] https://msrc.microsoft.com/blog/2023/07/microsoft-mitigates-china-based-threat-actor-storm-0558-targeting-of-customer-email/

[11] https://www.youtube.com/watch?v=2jLUQZVwiKY

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZK-LR1IkuHbgIaGndRMwaQAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2023/05/26/us_china_trade_talks/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZK-LR1IkuHbgIaGndRMwaQAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] http://us.china-embassy.gov.cn/eng/lcbt/wjbfyrbt/202307/t20230712_11112244.htm

[16] https://whitepapers.theregister.com/



I blame Microsoft

Anonymous Coward

It doesn't matter if we're talking about state actors or run-of-the-mill criminals: Microsoft should not make their life easier with shoddy coding.

Re: I blame Microsoft

Abominator

This is Microsoft. It's always going to be shoddy code.

Just look at the bloat that is Teams. Their modern, cutting edge messaging app.

Re: I blame Microsoft

Roland6

Part of the problem is cloud.

Before cloud criminals needed to search for individual exchange servers, with cloud they are all behind a publicly known address…

Aquired taste

CrackedNoggin

Entry was forced by forging email authentication tokens with an acquired Microsoft accounts (MSA) consumer signing key.

And how did an MSA consumer signing key get leaked? It doesn't help to revoke the one key if the leak isn't detected and plugged.

It's like picking up the quarter that fell out of the pocket with a hole in it, and putting it back in the same pocket.

Re: Aquired taste

Anonymous Coward

Microsoft’s messaging on this is dishonest.

How did their MSA signing key get “acquired”?

How could they have such a fundamental vulnerability as allowing tokens signed by a key for a consumer service access their enterprise service (OWA)?

Two massive and inexcusable fails.

I’ve been working with their cloud products, at scale, for years now and their constant dropping of the ball is starting to get me looking at competitors.

Stop focusing all your effort on AI and start fixing your dearth of HI Microsoft.

Splorf!

Yorick Hunt

If "senior US officials" decided to use Hotmail as their messaging system, they deserve everything they get (didn't they learn from Hillary's experiences?).

Re: Splorf!

Anonymous Coward

The problem is, they were using Exchange Online not the consumer service.

So a stolen consumer signing key was able to be used to sign forged access tokens for Outlook Web App!! This is a double fail.

Re: Splorf!

Roland6

“Acquired” doesn’t necessarily mean “stolen”…

Re: Splorf!

Anonymous Coward

Thanks for the English lesson. If Microsoft knowingly gave Chinese Intelligence a signing key for their consumer email service (and yes, we can all imagine scenarios where this might be required) without ensuring that same key was unable to be used to forge access tokens for their enterprise service in other geographies, then we’ve got a “fired C-Suite” level of fail right there.

Among the lucky, you are the chosen one.