Microsoft has disclosed that China-based hackers gained unauthorized access to approximately 25 organizations’ email accounts, including government agencies. While Microsoft did not specify the locations of the targeted government agencies, the US Department of Commerce confirmed that it was informed about the attack.
The breach reportedly impacted Secretary of Commerce Gina Raimondo and other individuals, although further details were not provided by Microsoft. The US Department of Commerce took immediate action upon receiving notification from Microsoft and stated that it would respond promptly to any further activity detected.
There are reports suggesting that the State Department was also targeted in the attack, although the department has not yet responded to inquiries.
Microsoft referred to the hacking group responsible as Storm-0558, stating that it primarily focuses on Western European government agencies for purposes such as espionage, data theft, and credential access. The hackers accessed email accounts by forging digital authentication tokens used to verify individuals’ identities.
The breach was detected in mid-May, and Microsoft has stated that it has since mitigated the attack and contacted affected customers. The company added automated detections for known indicators of compromise related to this specific attack and found no evidence of further access.
In May, Microsoft and Western spy agencies reported that Chinese hackers had deployed stealthy malware to target critical infrastructure on American military bases in Guam, marking one of the largest cyber espionage campaigns against the US. China has routinely denied involvement in hacking operations, dismissing the accusations as “disinformation.”
The incident underscores the ongoing challenge posed by state-sponsored cyberattacks and highlights the need for robust cybersecurity measures to protect sensitive information and critical infrastructure.


