Technology

Report Criticizes Microsoft's Handling of Chinese-State Cyber Intrusion

A recent report released by a government cyber review board has shed light on a Chinese-state intrusion of Microsoft Corp. technology in the previous year, which enabled hackers to gather US officials' emails. The report, issued on Tuesday by the Cyber Safety Review Board, a White House-mandated group tasked with examining significant cyberattacks, stated that

Report Criticizes Microsoft's Handling of Chinese-State Cyber Intrusion

Report Criticizes Microsoft's Handling of Chinese-State Cyber Intrusion

Share
Picture: Reuters
Advertisement

A recent report released by a government cyber review board has shed light on a Chinese-state intrusion of Microsoft Corp. technology in the previous year, which enabled hackers to gather US officials’ emails. The report, issued on Tuesday by the Cyber Safety Review Board, a White House-mandated group tasked with examining significant cyberattacks, stated that such an intrusion “should never have occurred.”

The review board’s findings highlighted several critical aspects of the breach, emphasizing deficiencies in Microsoft’s corporate practices related to enterprise security investments and risk management. According to the report, the company’s security culture was deemed “inadequate” and necessitates a comprehensive overhaul.

The investigation cantered on the 2023 hack of Microsoft Exchange Online mailboxes, during which external actors breached 22 organizations and affected hundreds of individuals, including high-profile figures such as US Commerce Secretary Gina Raimondo, US Ambassador to China Nicholas Burns, and Representative Don Bacon, a Nebraska Republican. The hacking group responsible for the attack was identified as Storm-0558, linked to the Chinese government.

Despite efforts to understand the intrusion, Microsoft has yet to determine how attackers infiltrated the company’s systems, the report revealed. Additionally, reviewers criticized the company’s delayed and inaccurate disclosures about the incident. For instance, Microsoft initially suggested in September 2023 that hackers had exploited a digital certificate tool to steal emails, but later admitted to the review board in November that this disclosure was inaccurate.

In response to the report, Microsoft stated that it would review the findings for additional recommendations. A spokesperson for the company emphasized ongoing efforts to enhance cybersecurity measures, acknowledging the persistent threat of cyberattacks from well-resourced adversaries.

While Microsoft is primarily recognized for its software solutions, it has become a leading provider of cybersecurity products, generating approximately $20 billion in annual revenue from this segment. However, the breach and subsequent report have raised concerns among policymakers, with US Senator Ron Wyden criticizing federal agencies for their role in the incident. Wyden called for the establishment of strict cybersecurity standards for technology vendors, accompanied by independent audits to verify compliance and accountability measures for non-compliance.

TechnologyAfrican startups
Greg Stewart

Reporting for Business Tech Africa on the funding, tools and strategy shaping the continent's founders and SMEs.

Was this useful?0 reactions
Africa is getting more Big Tech investment, but the basics are still holding it back
Read nextTechnology

Africa is getting more Big Tech investment, but the basics are still holding it back

Google, Meta, Microsoft, Amazon and Starlink are putting more money into Africa's digital infrastructure. Subsea cables are reaching more parts of the continent, satellite internet is expanding and cloud companies are adding services for African customers. For businesses that have spent years dealing with unreliable connections, that is useful. There is still a problem underneath

Vutomi Manzini · 4 min readContinue reading