By Top Class Actions  |  July 17, 2023

Category: Data Breach
Close up of Microsoft signage, representing the government email breach.
(Photo Credit: The Art of Pics/Shutterstock)

Microsoft government email breach overview: 

  • Who: Microsoft has disclosed a breach of its email systems that is being attributed to bad actors from the China-backed hacking group Storm-0558. 
  • Why: The breach impacted consumers — along with at least one unnamed federal government agency — with accounts on the Microsoft 365 email cloud environment. 
  • Where: Nationwide. 
  • What are my options: Norton LifeLock carries many options when it comes to data security.

Microsoft has disclosed that a group of China-backed hackers were recently able to break into the email systems of some of its customers, in what the tech giant called an attempt to gather intelligence.

The company said in a blog post on Tuesday that it began investigating unusual activity in its email systems within a few weeks of the initial attack, however, bad actors were repeatedly able to gain access to accounts during that time. 

In a related advisory, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) said a federal government agency — which it did not name — detected unusual activity on its Microsoft 365 email cloud environment in June. 

The agency immediately reported the unusual activity to Microsoft, according to the CISA, which said the company “determined that advanced persistent threat (APT) actors accessed and exfiltrated unclassified Exchange Online Outlook data.” 

It is unclear at this time how many government agencies were affected by the breach, reports NPR, however, the CISA said any data that was taken from the unnamed federal agency was unclassified. 

Microsoft connects breach to Chinese hacking group Storm-0558

Microsoft said it has connected the breach to a Chinese hacking group it calls Storm-0558 and that “primarily targets government agencies in Western Europe and focuses on espionage, data theft, and credential access.” 

The company determined Storm-0558 was able to infiltrate customer email accounts on Outlook Web Access in Exchange Online and Outlook.com by using a stolen managed service account (MSA) key to forge authentication tokens. 

The actor exploited a token validation issue to impersonate Azure AD users and gain access to enterprise mail,” Microsoft said. 

Microsoft said it was able to mitigate the breach by blocking the usage of tokens signed with the acquired MSA key, before replacing the key entirely “to prevent the threat actor from using it to forge tokens.” 

The company said it also blocked usage of tokens that were issued with the acquired MSA key for all of its impacted consumer customers.

Microsoft disclosed a separate data breach to the public last year that it warned exposed the sensitive information of some of its customers. The breach was blamed on a misconfigured internet-accessible Microsoft server

Have you been impacted by a Microsoft data breach? Let us know in the comments!


Don’t Miss Out!

Check out our list of Class Action Lawsuits and Class Action Settlements you may qualify to join!


Read About More Class Action Lawsuits & Class Action Settlements:

We tell you about cash you can claim EVERY WEEK! Sign up for our free newsletter.

80 thoughts onMicrosoft discloses breach of gov’t email accounts

  1. Loretta Clark says:

    Yes please add me to the Microsoft class action lawsuit

  2. Carnella Marks says:

    Add me

  3. Phyllis Saunders says:

    Please add me.

  4. George Chiampas says:

    Add me

  5. Rose Angel says:

    Please add me I have been with them some years now

  6. Dwayne Miller says:

    ADD ME

  7. PHYLLIS V LIDDELL says:

    ADD ME

    1. Trudy Bengel says:

      ASD ME

  8. Tammy Godfinon says:

    Add me

1 6 7 8

Leave a Reply

Your email address will not be published. By submitting your comment and contact information, you agree to receive marketing emails from Top Class Actions regarding this and/or similar lawsuits or settlements, and/or to be contacted by an attorney or law firm to discuss the details of your potential case at no charge to you if you qualify. Required fields are marked *

Please note: Top Class Actions is not a settlement administrator or law firm. Top Class Actions is a legal news source that reports on class action lawsuits, class action settlements, drug injury lawsuits and product liability lawsuits. Top Class Actions does not process claims and we cannot advise you on the status of any class action settlement claim. You must contact the settlement administrator or your attorney for any updates regarding your claim status, claim form or questions about when payments are expected to be mailed out.