Site navigation

Report: Blame for 2023 Government Data Breach Falls on Microsoft

Michael Edgar

,

Microsoft breach
A report from the Department of Homeland Security points the blame for a government data breach at Microsoft.

According to a report from the Department of Homeland Security’s Cyber Safety Review Board (CSRB), a mid-2023 security breach which allowed Chinese hackers to compromise US government email accounts was preventable. 

According to the report, the breach stemmed from a corporate culture at Microsoft that de-emphasised security investments and rigorous risk management.

The CSRB highlighted a series of operational and strategic decisions at Microsoft that it deemed indicative of broader corporate cultural issues. These decisions, the report claims, left vulnerabilities open for exploitation by threat actors. The breach, attributed to the Chinese state-backed group Storm-0558, underscored the importance of robust security measures in the face of escalating cyber threats.

Central to the criticism was Microsoft’s handling of key security protocols. The means by which the hackers obtained a signing key remains unclear, even nearly a year after the incident. 

Microsoft initially stated that the attackers compromised an engineer’s account and accessed the key from a debugging environment. However, the company has since revised its explanation.

Moreover, the report chastised Microsoft for its slow and misleading public statements regarding the breach, noting that the company was unaware of the incident until a customer brought it to their attention. The breach, which impacted at least 22 organisations and 500 individuals, raised concerns about national security given Microsoft’s extensive integration into critical government networks.


Recommended reading


“Cloud computing is some of the most critical infrastructure we have, as it hosts sensitive data and powers business operations across our economy,” said DHS under secretary of policy and CSRB chair Robert Silvers. 

“It is imperative that cloud service providers prioritise security and build it in by design. The Board has become the authoritative organisation for conducting fact-finding and issuing recommendations in the wake of major cyber incidents, receiving extensive industry and expert input in each of its three reviews to date.”

In response to the report, Microsoft has vowed to overhaul its security culture, mobilising its engineering team to address legacy infrastructure issues and enforce stricter security measures. The company has pledged to halt the introduction of new features to its cloud computing environments until necessary security improvements are made and has committed to a transparent timeline for implementing these changes.

Tags:

Michael Edgar

Staff Writer, DIGIT

Latest News

Cybersecurity

Scotland’s Prosecution Service Suffers Third-party Data Breach

AI Featured

Anthropic Eyes Record-Breaking $2tn IPO as It Invites Public to Ask ‘Hard Questions’

Editor's Picks Events Technology

TecTonic Night Summit Returns for Glasgow Tech Week 2026

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far