According to a report from the Department of Homeland Security’s Cyber Safety Review Board (CSRB), a mid-2023 security breach which allowed Chinese hackers to compromise US government email accounts was preventable.
According to the report, the breach stemmed from a corporate culture at Microsoft that de-emphasised security investments and rigorous risk management.
The CSRB highlighted a series of operational and strategic decisions at Microsoft that it deemed indicative of broader corporate cultural issues. These decisions, the report claims, left vulnerabilities open for exploitation by threat actors. The breach, attributed to the Chinese state-backed group Storm-0558, underscored the importance of robust security measures in the face of escalating cyber threats.
Central to the criticism was Microsoft’s handling of key security protocols. The means by which the hackers obtained a signing key remains unclear, even nearly a year after the incident.
Microsoft initially stated that the attackers compromised an engineer’s account and accessed the key from a debugging environment. However, the company has since revised its explanation.
Moreover, the report chastised Microsoft for its slow and misleading public statements regarding the breach, noting that the company was unaware of the incident until a customer brought it to their attention. The breach, which impacted at least 22 organisations and 500 individuals, raised concerns about national security given Microsoft’s extensive integration into critical government networks.
Recommended reading
- Strong Cybersecurity Key to AI Superpower Ambitions, Microsoft Says
- OpenAI & Microsoft Disrupt State-backed Hackers
- Data Breach Incidents Surged by Over a Third in 2023
“Cloud computing is some of the most critical infrastructure we have, as it hosts sensitive data and powers business operations across our economy,” said DHS under secretary of policy and CSRB chair Robert Silvers.
“It is imperative that cloud service providers prioritise security and build it in by design. The Board has become the authoritative organisation for conducting fact-finding and issuing recommendations in the wake of major cyber incidents, receiving extensive industry and expert input in each of its three reviews to date.”
In response to the report, Microsoft has vowed to overhaul its security culture, mobilising its engineering team to address legacy infrastructure issues and enforce stricter security measures. The company has pledged to halt the introduction of new features to its cloud computing environments until necessary security improvements are made and has committed to a transparent timeline for implementing these changes.





