Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2023, the China-affiliated group Storm-0558 used a stolen Microsoft account-signing key to forge authentication tokens that opened targeted Exchange Online mailboxes. The Cyber Safety Review Board later called the intrusion preventable, faulting Microsoft’s identity checks, key management, monitoring and security risk management. The incident also exposed a practical problem for customers: some logs useful for finding and investigating the activity were not available with lower-tier Microsoft 365 licensing.

What was the Chinese Microsoft hack?

Storm-0558 gained access to targeted Microsoft Exchange Online mailboxes by using a stolen 2016 Microsoft account (MSA) signing key to create forged authentication tokens. The key was intended for Microsoft consumer accounts, but a flaw in Exchange Online’s token validation allowed forged tokens to be accepted in an enterprise context as well.

This was a cloud identity and authentication failure, not evidence that every Microsoft 365 account or mailbox was compromised. Contemporaneous reporting by CyberScoop described at least two dozen targeted entities, including the U.S. commerce secretary. The Cyber Safety Review Board’s 2024 account records that the U.S. State Department initially identified six affected accounts by June 19, with additional accounts found later.

How did Storm-0558 get into Exchange Online?

  1. It used a stolen signing key. A signing key lets a service verify that an authentication token is legitimate. Storm-0558 used the 2016 MSA key to forge tokens.
  2. Exchange Online accepted tokens across account contexts. A token associated with Microsoft’s consumer account environment could be used to gain enterprise mailbox access because of a token-validation flaw.
  3. Some customers had limited visibility into the activity. Logs that helped investigators detect suspicious access and identify victims were not equally available across licensing tiers, according to CISA and contemporaneous reporting.

The key’s theft mechanism was not conclusively established in the CSRB review. Microsoft had previously proposed that a crash dump might have exposed it, but the board said that theory lacked supporting evidence. The available account therefore explains how the key was abused, not exactly how Storm-0558 obtained it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened, and when?

Date Event
June 15, 2023 The U.S. State Department detected anomalous activity, according to the CSRB review.
June 16, 2023 The State Department notified Microsoft.
June 19, 2023 The State Department had identified six affected email accounts; more were identified afterward.
June 23, 2023 Microsoft identified the Commerce Department as a victim.
June 24, 2023 Microsoft invalidated the stolen key and changed token-acceptance behavior.
July 4–14, 2023 Microsoft notified 63 high-profile individuals in the United Kingdom, according to the CSRB.

Microsoft’s July 2023 technical disclosure said it had “hardened key issuance systems since” the stolen key was issued. The company also rotated keys and enhanced monitoring; notifications to affected organizations and individuals continued after the initial containment steps.

Why did the CSRB call the breach preventable?

The CSRB’s 2024 review connected the incident to weaknesses in Microsoft’s key management, identity validation, monitoring, logging availability and risk management. In its assessment, the failure was not simply that an attacker had obtained a credential. Microsoft’s systems accepted a forged token in a context where it should not have granted enterprise access, and gaps in monitoring and logs made detection and investigation more difficult.

The board also criticized Microsoft’s security culture and risk management. That matters because a security control can fail at several stages: protecting the signing key, validating which identity a token represents, detecting unusual access, and preserving enough evidence to determine what happened. The CSRB’s conclusion was that this chain of weaknesses made the intrusion preventable.

Why were Microsoft security logs part of the controversy?

The State Department’s access to Microsoft logging data helped it detect suspicious activity and gave investigators information to limit the damage and identify other victims. CISA said that key logging data was important to those efforts. Yet CyberScoop reported that the investigation depended on a premium Microsoft logging service and that less expensive E3 licensing did not provide equivalent investigative visibility.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA Executive Assistant Director for Cybersecurity Eric Goldstein wrote on July 19, 2023: “Having access to key logging data is important to quickly mitigating cyber intrusions.” A senior CISA official told CyberScoop that “Every organization using a technology service like Microsoft 365 should have access to logging and other security data out of the box.” CISA’s concern was that restricting useful logs to higher licensing levels can make it harder for organizations to investigate an incident quickly—not that a particular license would itself have prevented the attack.

What did Microsoft do to contain the incident?

Microsoft invalidated the compromised signing key on June 24, 2023, changed Exchange Online’s token-acceptance behavior, fixed the flaw that allowed a consumer-account key to enable enterprise access, rotated keys and enhanced monitoring. These measures addressed the known key and the cross-context validation problem. They do not resolve the separate question of how Storm-0558 first obtained the key, which the CSRB review said remained undetermined.

What should Microsoft 365 customers do after Storm-0558?

The incident is historical, but its lessons apply to cloud identity incidents generally. Customers should verify what their current Microsoft 365 licensing and configuration actually expose, rather than assume that all security-relevant audit data is available by default.

  • Confirm logging coverage. Ask your Microsoft 365 administrator or provider which audit and identity logs are enabled, which are retained, and whether your plan exposes the events needed to investigate mailbox access and token activity. Confirm whether any additional licensing or configuration is required.
  • Review monitoring and response ownership. Establish who reviews alerts, how quickly suspicious sign-ins or mailbox activity are escalated, and who can preserve logs and coordinate with Microsoft during an incident.
  • Assess identity controls. Review how users and administrators authenticate, how unusual sign-ins and mailbox access are monitored, and whether phishing-resistant multifactor authentication is appropriate for your organization’s risk. These measures reduce identity risk but would not by themselves correct a cloud provider’s token-validation flaw.
  • Prepare for provider-side incidents. Keep an incident-response contact and process for Microsoft support, understand how your organization will identify affected accounts, and follow Microsoft security advisories for current actions. Do not treat this 2023 compromise as evidence that your tenant was affected.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the incident says about cloud security plans

Storm-0558 is a case study in why customers should evaluate security visibility as part of a cloud service, not as an optional convenience. For any provider or plan, ask whether essential audit logs are available to all customers or reserved for premium tiers; how identity and token-signing protections are handled; how quickly customers can investigate access; and how key rotation and incident disclosures are communicated. The CSRB’s 2024 review documents a Microsoft logging-tier controversy in this incident, but does not provide comparable plan details for other cloud providers, so a provider-by-provider ranking would not be justified.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.