Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • DHS Board Blames Microsoft’s ‘Cascade’ of Errors for 2023 E-mail Breach
    • Bill to Revise Browser Requirements Under CCPA Advances
    • Children’s Data Privacy Act Advances in California
    • D.C. Circuit Gives Hikvision, Dahua Some Hope in ‘Covered List’ Case
    • Greek Immigration Authority Fined Over GDPR Violations
    • HEALTH CARE COMPLIANCE NEWS—New Jersey SNF hit with $100K CMP for HIPAA violation over timely access to medical records
    • Hong Kong DPA Issues Enforcement Notice After Cyberport Data Breach
    • Italy Suspends Worldcoin’s Orb Collection of Iris Scans
    • NIST Publishes Draft Handbook on IoT Cybersecurity
    • Summit Seeks Clarity Amid ‘Rip-and-Replace' Funding Shortfall
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, DHS Board Blames Microsoft’s ‘Cascade’ of Errors for 2023 E-mail Breach, (Apr 3, 2024)

    Organizations Mentioned:Microsoft

    By Tom Leithauser

    A “cascade of Microsoft’s avoidable errors” led to a widespread breach of the company’s cloud-based e-mail service last year, enabling a Chinese cyber espionage group to monitor the communications of Commerce Secretary Gin ...

    By Tom Leithauser

    A “cascade of Microsoft’s avoidable errors” led to a widespread breach of the company’s cloud-based e-mail service last year, enabling a Chinese cyber espionage group to monitor the communications of Commerce Secretary Gina Raimondo and other key leaders in the U.S. and abroad, according to a report from the Department of Homeland Security’s Cyber Safety Review Board (CSRB).

    The report, published late yesterday, recommends steps that Microsoft, other cloud service providers (CSPs), and the federal government should take to avoid a repeat of the breach that was discovered in July 2023.

    “It is not an exaggeration to say that cloud computing has become an indispensable resource to this nation, and indeed, much of the world,” the report notes. “As a result, cloud service providers (CSPs) have become custodians of nearly unimaginable amounts of data.”

    “In effect, the CSPs have become one of our most important critical infrastructure industries. As a result, these companies must invest in and prioritize security consistent with this ‘new normal,’ for the protection of their customers and our most critical economic and security interests,” it says.

    The Microsoft breach occurred after a Chinese state-sponsored hacking group known as Storm-0558 acquired a master key that enabled it to generate forged tokens to access the cloud-based e-mail accounts of 22 organizations and more than 500 individuals around the world, according to the report. Those accounts included Ms. Raimondo’s and those of other U.S. officials involved with U.S.-China relations. Rep. Don Bacon (R., Neb.) was also a victim.

    “The Board finds that this intrusion was preventable and should never have occurred. The Board also concludes that Microsoft’s security culture was inadequate and requires an overhaul, particularly in light of the company’s centrality in the technology ecosystem and the level of trust customers place in the company to protect their data and operations,” the report says.

    The report faults Microsoft’s “failure to detect the compromise of its cryptographic crown jewels,” which Microsoft learned about from the State Department.

    In addition, Microsoft failed to implement more robust security controls used by other CSPs and provided “inaccurate public statements,” the report says.

    “Throughout this review, the Board identified a series of Microsoft operational and strategic decisions that collectively point to a corporate culture that deprioritized both enterprise security investments and rigorous risk management,” it says.

    “To drive the rapid cultural change that is needed within Microsoft, the Board believes that Microsoft’s customers would benefit from its CEO and Board of Directors directly focusing on the company’s security culture and developing and sharing publicly a plan with specific timelines to make fundamental, security-focused reforms across the company and its full suite of products,” it advises.

    “In the meantime, Microsoft leadership should consider directing internal Microsoft teams to deprioritize feature developments across the company’s cloud infrastructure and product suite until substantial security improvements have been made in order to preclude competition for resources. In all instances, security risks should be fully and appropriately assessed and addressed before new features are deployed,” it recommends.

    It also offers a series of recommendations for cloud service providers more generally and suggests that the U.S. government should do more to hold CSPs accountable through changes to the Federal Risk and Authorization Management Program (FedRAMP), which provides executive branch agencies with a catalog of vetted cloud services.

    In coordination with the Office of Management and Budget and Cybersecurity and Infrastructure Security Agency, FedRAMP’s overseers “should establish a minimum threshold for periodically re-evaluating legacy FedRAMP authorization packages,” the report says.

    “For example, some FedRAMP authorized packages are for services that have become especially widely used across the government while others may be considered High Value Assets (HVA) that may merit more regular review,” it says.

    FedRAMP should also “establish a process for conducting discretionary special reviews of FedRAMP authorized Cloud Service Offerings (CSOs) that convene security experts within the federal government to make recommendations for security improvements for the CSO,” it adds.

    The CSRB was established pursuant to President Biden’s 2021 cybersecurity executive order and modeled on the National Transportation Safety Board, which conducts after-action reviews of major transportation accidents. The board’s review and report on the Microsoft breach was its third.

    The CSRB’s membership includes representatives from technology companies, although Microsoft is not a participant, and some cybersecurity experts have expressed doubt that the board has the structure and powers needed to conduct robust reviews of private-sector cybersecurity lapses (CPR, Jan. 17).

    But its hard-hitting conclusions about Microsoft’s corporate culture suggest that the board is willing to undertake difficult reviews. The board noted that Microsoft was cooperative throughout the review.

    Microsoft said it appreciated the CSRB’s work “to investigate the impact of well-resourced nation state threat actors who operate continuously and without meaningful deterrence.”

    “As we announced in our Secure Future Initiative, recent events have demonstrated a need to adopt a new culture of engineering security in our own networks,” a company spokesperson told CPR.

    “While no organization is immune to cyberattack from well-resourced adversaries, we have mobilized our engineering teams to identify and mitigate legacy infrastructure, improve processes, and enforce security benchmarks. Our security engineers continue to harden all our systems against attack and implement even more robust sensors and logs to help us detect and repel the cyber-armies of our adversaries,” the spokesperson said.

    The CSRB report notes that, although Microsoft was able to take steps to block the intrusions by Storm-0558, the company still is unsure how the group obtained the master key that enabled its espionage campaign.

    “Microsoft developed 46 hypotheses to investigate, including some scenarios as wide-ranging as the adversary possessing a theoretical quantum computing capability to break public-key cryptography or an insider who stole the key during its creation,” it says.

    “Microsoft then assigned teams for each hypothesis to try to: prove how the theft occurred; prove it could no longer occur in the same way now; and to prove Microsoft would detect it if it happened today,” it adds. “Nine months after the discovery of the intrusion, Microsoft says that its investigation into these hypotheses remains ongoing.”

    MainStory: TopStory FederalLegislation DataSecurity DataBreach

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use