Chinese hackers stole 60,000 US government emails in Microsoft breach

A laptop showing lots of email notifications
(Image credit: Shutterstock)

When the Storm-0558 Chinese hackers breached Microsoft’s cloud-based Exchange email platform last May, they stole 60,000 unclassified emails from the employees of the US State Department.

The breach was confirmed at a recently held Senate staff briefing which added the compromised personnel were located in East Asia, the Pacific, and Europe, and focused mostly on Indo-Pacific diplomacy work. The threat actors also found a list of all the email accounts of the department. 

"We need to harden our defenses against these types of cyberattacks and intrusions in the future, and we need to take a hard look at the federal government's reliance on a single vendor as a potential weak point," Senator Eric Schmitt said in a statement.

Espionage and data theft

In a media conference, State Department spokesperson Matthew Miller stressed that classified systems were not breached. Discussing the attackers, it was said that the State Department would confirm Microsoft’s earlier conclusions that Storm-0558 was behind the intrusion.

"We have not made an attribution at this point, but, as I said before, we have no reason to doubt the attribution that Microsoft has made publicly. Again this was a hack of Microsoft systems that the State Department uncovered and notified Microsoft about."

When the news of the hack first broke in mid-July 2023, it was reported that hackers gained access to some 25 accounts belonging to U.S. government employees. It was the State Department that tipped Microsoft off on the breach, and the software giant took a few weeks to discover exactly how the hackers obtained a consumer key that was necessary to pull the hack off. 

Storm-0558 is a threat actor usually focused on espionage, data theft, and credential access, against entities in Western Europe.

Via BleepingComputer

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
US critical infrastructure hit once again by a new group on the scene
China
US Treasury declares ‘major incident’ after apparent state-sponsored Chinese hack
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
An American flag flying outside the US Capitol building against a blue sky
More alleged Chinese intrusions into the US Treasury revealed
Cyber warfare
Microsoft says Russia is hacking Ukrainian military tech by stealing points of entry from third-parties
A red padlock image against a digital map of the earth in blue.
Midnight Blizzard hacking group hijacks RDP proxies to launch malware attacks
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection
iPad Air M3
Apple makes one hardware change to the iPad Air that might be the best indicator of its true lightweight tablet intentions
Shure MoveMic 88+ lifestyle image
Shure's tiny MoveMic 88+ gives creators a cheap and easy way to record crystal clear audio on a smartphone
An operator fires a saw blade from a weapon
Call of Duty: Black Ops 6 Season 3 gets two-week delay, will now release in April
Apple iPad A16
Apple's new entry-level iPad ups the performance for the same price, but doesn't support Apple Intelligence