Skip to content

ThePawn02

Gaming and Streaming Content

  • Blog
  • Editor's Picks
  • eSports
  • Guides
  • Headlines
  • News
  • Reviews
  • Uncategorized
  • Website Update
Primary Menu
  • Home
  • Watch Live
  • News
  • eSports
  • Blog
  • Reviews
  • Guides
  • Guild Login
    • Guild Mentality
    • The Zealots
    • Malign
  • Socials
    • Youtube Channel
    • Twitch Channel
    • Kick.com
    • Twitter
    • Instagram
    • Facebook
Subscribe
  • Home
  • 2024
  • April
  • US Gov report slams Microsoft over email hack—’The Board finds that this intrusion was preventable and should never have occurred’
  • News

US Gov report slams Microsoft over email hack—’The Board finds that this intrusion was preventable and should never have occurred’

The Cyber Safety Review Board has released its assessment of last years Microsoft security breach, and it makes for uncomfortable reading.
April 4, 2024 3 min read
US Gov report slams Microsoft over email hack—’The Board finds that this intrusion was preventable and should never have occurred’

The Cyber Safety Review Board has released its assessment of last years Microsoft security breach, and it makes for uncomfortable reading.

Last year, Microsoft disclosed that a Chinese hacking group referred to as “Storm-0558” was responsible for a security breach that led to the access of the email accounts of around 25 organisations, including some US government agencies. The federal Cyber Safety Review Board has just released its report on the incident, identifying a “cascade of Microsoft’s avoidable errors that allowed this intrusion to succeed”. Ouch.

The Cyber Safety Review Board is composed of multiple officials from several US government departments including the Department of Homeland Security, the NSA and the FBI (via Ars Technica) and several industry leaders, and was tasked with creating the report [pdf] under a mandate from President Biden in response to the attack. 

In a somewhat scathing review, the board found that not only were Microsoft’s security practices “lacking” in comparison to other cloud providers, but that public statements released surrounding the attack were “inaccurate” and not corrected in a timely manner. 

Microsoft said at the time that a consumer signing key was acquired by Storm-0558 which was used to forge tokens for the cloud service that stores login keys, and that this was caused by a validation error in its codebase, later changing this explanation to a claim that an engineers account was hacked, and that “human errors” were to blame for allowing an expired signing key to be used to forge tokens.

However, the report revealed that Microsoft has still yet to determine the exact root cause of the breach, and noted that the company only updated its blog posts discussing the attack in March of this year, roughly at the same time the board was concluding its review and “only after the Boards repeated questioning about Microsoft’s plan to issue a correction”.

The attack itself was originally detected by State Department officials in June of last year, who then went on to notify Microsoft about the breach. The report cites that this was only possibly because the department had paid for a higher tier of Microsoft cloud services that allowed them to set up an alert for notable mail access—called rather charmingly “Big Yellow Taxi”—which was then triggered when the hackers attempted to download more than 60,000 emails.

In summation, the report makes several recommendations to prevent future security failings, including a renewed focus on security culture, a shift from the prioritisation of feature developments to security improvements, a move towards taking accountability for the security outcomes of customers, and a focus on providing customers with tools that allow them to detect, prevent or quantify a future intrusion.

Your next machine

(Image credit: Future)

Best gaming PC: The top pre-built machines.
Best gaming laptop: Great devices for mobile gaming.

“Microsoft’s products and services are ubiquitous. It is one of the most important technology companies in the world, if not the most important.”

“Unfortunately, throughout this review, the Board identified a series of operational and strategic decisions that collectively point to a corporate culture in Microsoft that deprioritized both enterprise security investments and rigorous risk management. These decisions resulted in significant costs and harm for Microsoft customers around the world. The Board is convinced that Microsoft should address its security culture.”

While this report is damning in its findings, Microsoft is not the only victim of the hacking group’s attempts to breach major security networks. Storm-0558 was noted as having a history of stealing authentication keys for cloud services from global providers, and making something of a menace of itself in the process. 

Still, a significant slap on the wrist for Microsoft, and a summation that doesn’t hold back on its critique of its security practices. Given that Microsoft’s Azure cloud platform is used by vast numbers of major companies and institutions to handle potentially very sensitive data, this may serve as a wakeup call for the company to focus on security concerns in order to prevent customers from looking elsewhere. 

About Post Author

See author's posts

Continue Reading

Previous: Sea of Thieves on PS5 Has Progress and Item Transfer, and PlayStation-Only Servers
Next: Helldivers 2 player drops 16 consecutive 500kg payloads on the game’s new gunship factory for science—discovers hellbombs are their only reliable kryptonite

Related News

‘I don’t particularly think the game will be very good’: The fans trying to get a never-released Chinese Borderlands MMO working are doing something so absurd that I love them for it
2 min read
  • News

‘I don’t particularly think the game will be very good’: The fans trying to get a never-released Chinese Borderlands MMO working are doing something so absurd that I love them for it

ThePawn.com June 21, 2025
Marathon Gets Delayed, Donkey Kong Bananza Gets A Smashing Showing, And More Top Stories
1 min read
  • News

Marathon Gets Delayed, Donkey Kong Bananza Gets A Smashing Showing, And More Top Stories

ThePawn.com June 21, 2025
NetEase’s ‘first AAA singleplayer’ game is Blood Message, and it looks amazing in its first trailer
3 min read
  • News

NetEase’s ‘first AAA singleplayer’ game is Blood Message, and it looks amazing in its first trailer

ThePawn.com June 21, 2025

Latest YouTube Video

Check out these awesome streamers

ThePawn02 on twitch

From Gamewatcher

  • Chrono Odyssey Preview
  • Warhammer 40,000: Space Marine Review
  • Dune: Awakening Review
  • How to get a Worm Tooth in Dune Awakening
  • Phasmophobia Chronicle Update Release Date - Latest News

From IGN

  • The Best Deals Today: Donkey Kong Bananza, LEGO Animal Crossing, Super Mario Party Jamboree, and More
  • Splitgate 2 Dev 1047 Games Hit by Layoffs Amid Turbulent Launch, Co-Founders Say They Won’t Take Salaries ‘As We Lock in to Deliver the Next Phase of the Project’
  • Grow a Garden Summer Update Propels Roblox Game to Astonishing Concurrent Player Record, Dwarfing Even Fortnite — Here Are All the Details
  • Limited Edition IGN Artist Series Hellwalker Prints from Dave Rapoza Now Available
  • Duke Nukem Rights Acquired by Devil May Cry and Castlevania Showrunner

From Kotaku

  • Marathon Gets Delayed, Donkey Kong Bananza Gets A Smashing Showing, And More Top Stories
  • Kotaku’s Weekend Guide: 3 Delightful Games We’re Swinging Into Summer With
  • Mario Kart World's Mirror Mode Is A Little Too Confusing To Activate
  • Six Things I Wish I Knew Before Setting Up My Switch 2
  • Sprite + Tea Review: This Crap Needs To Be Outlawed

.

You may have missed

The Best Deals Today: Donkey Kong Bananza, LEGO Animal Crossing, Super Mario Party Jamboree, and More
3 min read
  • Headlines

The Best Deals Today: Donkey Kong Bananza, LEGO Animal Crossing, Super Mario Party Jamboree, and More

ThePawn.com June 21, 2025
‘I don’t particularly think the game will be very good’: The fans trying to get a never-released Chinese Borderlands MMO working are doing something so absurd that I love them for it
2 min read
  • News

‘I don’t particularly think the game will be very good’: The fans trying to get a never-released Chinese Borderlands MMO working are doing something so absurd that I love them for it

ThePawn.com June 21, 2025
Splitgate 2 Dev 1047 Games Hit by Layoffs Amid Turbulent Launch, Co-Founders Say They Won’t Take Salaries ‘As We Lock in to Deliver the Next Phase of the Project’
2 min read
  • Headlines

Splitgate 2 Dev 1047 Games Hit by Layoffs Amid Turbulent Launch, Co-Founders Say They Won’t Take Salaries ‘As We Lock in to Deliver the Next Phase of the Project’

ThePawn.com June 21, 2025
Marathon Gets Delayed, Donkey Kong Bananza Gets A Smashing Showing, And More Top Stories
1 min read
  • News

Marathon Gets Delayed, Donkey Kong Bananza Gets A Smashing Showing, And More Top Stories

ThePawn.com June 21, 2025
Privacy Policy
  • Home
  • Watch Live
  • News
  • eSports
  • Blog
  • Reviews
  • Guides
  • Guild Login
  • Socials
  • Twitch
  • YouTube
  • Instagram
  • Twitter
  • Facebook
  • Kick.com
Copyright © All rights reserved. | MoreNews by AF themes.