Site icon Auspreneur

Hackers gained access to US government Exchange Online email accounts

Chinese state-linked hackers have been engaged in a covert cyberespionage campaign since May, infiltrating email accounts at approximately 25 organizations, including US government accounts, according to Microsoft and US officials.

The US government swiftly detected the breach of federal government accounts and successfully prevented further intrusions, stated White House national security adviser Jake Sullivan during an interview with ABC’s “Good Morning America.”

An anonymous source familiar with the investigation revealed that the US State Department was among the government agencies affected.

Microsoft referred to the hacking group as Storm-0558 and disclosed that they used forged digital authentication tokens to gain unauthorized access to webmail accounts operating on the company’s Outlook service. The campaign began in May, as confirmed by Microsoft.

In response, Microsoft has directly contacted the targeted or compromised organizations, providing them with vital information to aid in investigation and response efforts. However, Microsoft did not disclose the specific organizations or governments impacted, emphasizing that the hacking group primarily targets entities in Western Europe.

White House National Security Council spokesman Adam Hodge acknowledged that the intrusion into Microsoft’s cloud security impacted “unclassified systems.” Immediate measures were taken to identify the source and vulnerability in the cloud service in coordination with Microsoft.

The State Department detected abnormal activity and promptly implemented measures to secure its systems, according to a department spokesperson.

In light of the cyberattack, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) jointly issued an advisory to enhance monitoring of Microsoft Exchange Online environments, particularly emphasizing the importance of enabling both basic and premium logging and ensuring the logs are easily searchable.

CISA is reportedly collaborating with Microsoft to provide premium logs to customers at no cost.

Cybersecurity experts in the private sector have noted that this recent wave of hacking activity demonstrates the evolving capabilities of Chinese cyber groups. John Hultquist, chief analyst for Mandiant, stated that Chinese cyber espionage has advanced significantly from the crude tactics typically associated with such activities.

The Chinese embassy in London dismissed the accusations as “disinformation” and labeled the US government as “the world’s biggest hacking empire and global cyber thief.”

China consistently denies involvement in hacking operations, irrespective of the available evidence or context.

Exit mobile version