iTnews Asia
  • Home
  • News
  • Security

Microsoft says Chinese hackers used code flaw to steal emails from US agencies

Microsoft says Chinese hackers used code flaw to steal emails from US agencies

'Misappropriated' a digital key, though unclear how.

By Raphael Satter on Jul 17, 2023 2:54PM

Microsoft said Chinese hackers misappropriated one of its digital keys and used a flaw in the company's code to steal emails from US government agencies and other clients.

The company said in a blog post that the hackers were able to use the key - which they acquired under undisclosed circumstances - and take advantage of "a validation error in Microsoft code" to carry out their cyberespionage campaign.

The blog provided the most fulsome explanation yet for a hack that rattled both the cybersecurity industry and China-US relations.

Beijing has denied any involvement in the spying.

Microsoft and US officials said last week that Chinese state-linked hackers had been secretly since May accessing email accounts at around 25 organisations.

US officials said those included at least two government agencies: the State and Commerce Departments.

Secretary of State Antony Blinken told China's top diplomat, Wang Yi, in a meeting in Jakarta that any action that targets the US government, US companies or American citizens "is of deep concern to us, and that we will take appropriate action to hold those responsible accountable," according to a senior State Department official.

Microsoft's blog post did not explain how the hackers got their hands on one of the company's digital keys, leading some experts to speculate that Microsoft itself had been hacked ahead of the thefts.

The company did not immediately respond to questions about the key.

The breach has thrown Microsoft's security practices under scrutiny, with officials and lawmakers calling on the Redmond, Washington-based company to make its top level of digital auditing, also called logging, available to all its customers free of charge.

Microsoft said in a statement late last week that it was taking the criticism on board.

"We are evaluating feedback and are open to other models," the company said, adding that it was "actively engaged" with US officials on the matter.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright Reuters
© 2019 Thomson Reuters. Click for Restrictions.
Tags:
hack m365 microsoft security

Related Articles

  • Beware the rise of ‘vishing’ as a cyber threat in APAC
  • Proofpoint CEO: A tool-based approach for cybersecurity is impractical
  • Akamai: AI-security is both a security imperative and an economic necessity
  • The real-life Tom & Jerry chase
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

Beware the rise of ‘vishing’ as a cyber threat in APAC

Beware the rise of ‘vishing’ as a cyber threat in APAC

Akamai: AI-security is both a security imperative and an economic necessity

Akamai: AI-security is both a security imperative and an economic necessity

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.