What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

The U.S. Cyber Safety Review Board (CSRB) said the 2023 intrusion into Microsoft Exchange Online was preventable and exposed serious failures in Microsoft’s security culture, key protection, detection and incident communications. The China-linked group Storm-0558 used a Microsoft signing key created in 2016, together with a flaw in Microsoft’s authentication system, to access email accounts at 22 organizations and those of more than 500 individuals worldwide.

What the Cyber Safety Review Board found

The CSRB is a government-private-sector body established under Executive Order 14028 to review significant cyber incidents and recommend improvements. Its review of the Exchange Online incident was its third completed review.

The board’s central finding was blunt: “The Board finds that this intrusion was preventable and should never have occurred.” It also concluded that “Microsoft’s security culture was inadequate and requires an overhaul.” Those judgments appear in the board’s Review of the Summer 2023 Microsoft Exchange Online Intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The report described a cascade of avoidable failures, rather than a single isolated mistake. In particular, it faulted Microsoft for failing to detect compromise of a highly sensitive signing key, for weaknesses in authentication controls that magnified the key’s reach, and for not identifying an employee-laptop compromise before that device connected to Microsoft’s corporate network. The board also criticized Microsoft’s delayed correction of an inaccurate public explanation of the incident.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How Storm-0558 got into Exchange Online

A stolen signing key enabled forged tokens

Storm-0558, which the CSRB assessed as affiliated with the People’s Republic of China and pursuing espionage objectives, used a Microsoft account signing key created in 2016 to issue authentication tokens. A signing key is used to establish that a token is valid; if an attacker obtains a key and can exploit weaknesses in how tokens are accepted, the attacker may be able to impersonate authorized users.

In this case, the key’s reach was amplified by another flaw in Microsoft’s authentication system. Together, the key and that flaw allowed the actor to access essentially any Exchange Online account within the scope of the vulnerability, according to the CSRB. The board treated signing keys as among a cloud provider’s most sensitive assets because compromise can undermine the identity checks that protect many accounts at once.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Customers first surfaced suspicious activity

Microsoft did not detect the key compromise on its own. The Department of State identified anomalous activity and notified Microsoft, prompting a joint investigation. The board’s account says Microsoft invalidated the stolen key on June 24, 2023, and observed attempts to regain access afterward. It also places Microsoft’s determination that the stolen key was being used to issue tokens at about June 26. Those two dates are presented here as stated in the board’s timeline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who was affected and when

The CSRB assessed the campaign’s scope as 22 organizations and more than 500 individuals worldwide. Among the victims were senior U.S. officials, including Commerce Secretary Gina Raimondo, Ambassador R. Nicholas Burns and Congressman Don Bacon. The board described Storm-0558 as an espionage actor with a history of targeting cloud providers and stealing authentication keys.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Date Milestone
May to early June 2023 Storm-0558 compromised Exchange Online mailboxes.
June 15, 2023 The Department of State detected anomalous activity.
June 16, 2023 State notified Microsoft and began a joint investigation.
June 23, 2023 Microsoft notified the Commerce Department that it was a victim.
June 24, 2023 Microsoft invalidated the stolen key and observed attempts to regain access.
About June 26, 2023 Microsoft determined that Storm-0558 was using the stolen 2016 key to issue access tokens.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the board’s criticism means for cloud customers

Assess identity and key management together

A cloud service’s identity security depends on more than passwords or multifactor authentication. Customers should ask how the provider protects signing keys and other authentication secrets, limits their use, rotates them, and validates tokens. A key’s potential impact also depends on whether a token can be accepted outside its intended scope.

Check whether logs are independently useful

The State Department’s detection shows why customers should not assume a provider will discover every compromise first. CISA’s contemporaneous guidance argued that access to key logging data can help customers detect suspicious activity sooner, limit damage and identify additional victims. Ask which identity, mailbox and administrative logs are available, how long they are retained, and whether access depends on a higher licensing tier.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Evaluate response and disclosure practices

Incident response includes more than containing an attacker. Customers should assess how quickly a provider investigates, invalidates compromised credentials, communicates scope and corrects an explanation when the technical facts change. The CSRB specifically criticized Microsoft for delaying correction of a public root-cause statement it knew was inaccurate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Compare security programs across the full control chain

When evaluating a cloud provider or reviewing an existing contract, use questions that follow the incident’s failure points:

  • Key protection: How are signing keys stored, monitored, rotated and restricted?
  • Token and identity design: How does the service limit token scope and prevent a valid signature from granting unintended access?
  • Independent detection: What telemetry can customers use to identify account compromise without waiting for provider notification?
  • Logging: Which logs are retained, how quickly are they available, and what licensing or configuration is required?
  • Incident response: How does the provider revoke compromised credentials, investigate attempted re-entry and notify affected customers?
  • Governance: How are security failures escalated to leadership and the board, and how are corrective actions tracked?

The CSRB’s review is a case study in why cloud security should be judged across identity architecture, cryptographic key management, monitoring, response, logging and accountability—not by a feature list alone.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.