Tuesday, Sep 29, 2026
English News
  • Hyderabad
  • Telangana
  • AP News
  • India
  • World
  • Entertainment
  • Sport
  • Science and Tech
  • Business
  • Rewind
  • ...
    • NRI
    • View Point
    • cartoon
    • My Space
    • Education Today
    • Reviews
    • Property
    • Lifestyle
E-Paper
  • NRI
  • View Point
  • cartoon
  • My Space
  • Reviews
  • Education Today
  • Property
  • Lifestyle
Home | Science & Tech | Microsoft Reveals How China Based Hackers Stole Its Consumer Email Key

Microsoft reveals how China-based hackers stole its consumer email key

China-backed hackers stole a digital consumer key from Microsoft to gain unfettered access to US government emails and the tech giant has detailed how the cyber criminals pulled off one of the biggest heists

By IANS
Published Date - 9 September 2023, 10:20 AM
Microsoft reveals how China-based hackers stole its consumer email key
whatsapp facebook twitter telegram

San Francisco: China-backed hackers stole a digital consumer key from Microsoft to gain unfettered access to US government emails and the tech giant has detailed how the cyber criminals pulled off one of the biggest heists in the corporate and government circles.

China-based threat actor, Storm-0558, used an acquired Microsoft account (MSA) consumer key to forge tokens to access OWA (Outlook Web App) and Outlook.com.

Also Read

  • Microsoft will address legal risks for copilot AI users in case of lawsuits: Brad Smith
  • Microsoft to remove WordPad in future release of Windows

“Our investigation found that a consumer signing system crash in April of 2021 resulted in a snapshot of the crashed process (crash dump). The crash dumps, which redact sensitive information, should not include the signing key,” the company said after a technical investigation.

In this case, a race condition allowed the key to be present in the crash dump (this issue has been corrected). “The key material’s presence in the crash dump was not detected by our systems (this issue has been corrected),” said Microsoft.

The hackers used that digital skeleton key to break into both the personal and enterprise email accounts of government officials hosted by Microsoft.

“We found that this crash dump, believed at the time not to contain key material, was subsequently moved from the isolated production network into our debugging environment on the internet connected corporate network,” explained the company.

After April 2021, when the key was leaked to the corporate environment in the crash dump, the Storm-0558 actor was able to successfully compromise a Microsoft engineer’s corporate account.

This account had access to the debugging environment containing the crash dump which incorrectly contained the key.

“Due to log retention policies, we don’t have logs with specific evidence of this exfiltration by this actor, but this was the most probable mechanism by which the actor acquired the key,” Microsoft added.

  • Follow Us :
  • Tags
  • China
  • hackers
  • Microsoft

Related News

  • 2 giant pandas set off to Atlanta zoo from China after Xi-Trump summit

    2 giant pandas set off to Atlanta zoo from China after Xi-Trump summit

  • Telangana targets 5 GW hyperscale data centre capacity by 2029: Sridhar Babu

    Telangana targets 5 GW hyperscale data centre capacity by 2029: Sridhar Babu

  • What happened was not because of me: Roshibina on selection controversy before Asiad

    What happened was not because of me: Roshibina on selection controversy before Asiad

  • Taiwan is watching closely as Xi, Trump meet and hopes US will keep up its arms sales

    Taiwan is watching closely as Xi, Trump meet and hopes US will keep up its arms sales

Latest News

  • Gold, diamonds and cash worth nearly Rs 1 crore stolen from content creator’s home

    6 minutes ago
  • OpenAI cancels GPT-6.1 Astra release over safety concerns

    19 minutes ago
  • Singapore sentences Indian IT vendor for endangering State Courts’ data

    27 minutes ago
  • Asian Games: India’s women’s trap team bags silver, shooting medal tally reaches 13

    43 minutes ago
  • Indian conglomerate Essar to build ‘largest US steel plant’ in Iowa​‌

    1 hour ago
  • FBI adds Goldy Brar to Ten Most Wanted List, announces $1 million reward

    2 hours ago
  • Ujjain’s historic Shahi Masjid to voluntarily remove portion for Simhastha road project

    2 hours ago
  • Indians faced average 346-day wait for US visitor visa interview: Audit

    2 hours ago

company

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

business

  • Subscribe

telangana today

  • Telangana
  • Hyderabad
  • Latest News
  • Entertainment
  • World
  • Andhra Pradesh
  • Science & Tech
  • Sport

follow us

  • Telangana Today Telangana Today
Telangana Today Telangana Today

© Copyrights 2024 TELANGANA PUBLICATIONS PVT. LTD. All rights reserved. Powered by Veegam

Telangana Today App