Military Space News
CYBER WARS
Chinese hackers breached US govt email accounts: Microsoft
Chinese hackers breached US govt email accounts: Microsoft
By Chris Lefkow
Washington (AFP) July 13, 2023

Chinese-based hackers seeking intelligence information breached the email accounts of a number of US government agencies, computer giant Microsoft said.

"The threat actor Microsoft links to this incident is an adversary based in China that Microsoft calls Storm-0558," the company said in a blog post late Tuesday.

Microsoft said Storm-0558 gained access to email accounts at approximately 25 organizations including government agencies.

Microsoft did not identify the targets but a US State Department spokesperson said the department had "detected anomalous activity" and had taken "immediate steps to secure our systems."

"As a matter of cybersecurity policy, we do not discuss details of our response and the incident remains under investigation," the spokesperson said.

According to The Washington Post, the breached email accounts were unclassified and "Pentagon, intelligence community and military email accounts did not appear to be affected."

But the paper reported Wednesday evening, quoting US officials, that State Department email accounts and that of Commerce Secretary Gina Raimondo were hacked. Raimondo's agency has angered China by imposing tough export controls on Chinese technologies.

CNN, citing sources familiar with the investigation, said the Chinese hackers targeted a small number of federal agencies and the email accounts of specific officials at each agency.

In the blog post, Charlie Bell, a Microsoft executive vice president, said "we assess this adversary is focused on espionage, such as gaining access to email systems for intelligence collection.

"This type of espionage-motivated adversary seeks to abuse credentials and gain access to data residing in sensitive systems," Bell said.

US National Security Adviser Jake Sullivan addressed the hack in an appearance on Wednesday on ABC's Good Morning America, and said it had been detected "fairly rapidly."

"We were able to prevent further breaches," Sullivan said.

"The matter is still being investigated, so I have to leave it there because we're gathering further information in consultation with Microsoft and we will continue to apprise the public as we learn more," Sullivan said.

- Espionage and data theft -

Microsoft said Storm-0558 "primarily targets government agencies in Western Europe and focuses on espionage, data theft, and credential access."

The Redmond, Washington-based company said it had launched an investigation into "anomalous mail activity" on June 16.

"Over the next few weeks, our investigation revealed that beginning on May 15, 2023, Storm-0558 gained access to email accounts affecting approximately 25 organizations including government agencies as well as related consumer accounts.

"They did this by using forged authentication tokens to access user email using an acquired Microsoft account consumer signing key," the company said. "Microsoft has completed mitigation of this attack for all customers."

US Senator Mark Warner, chairman of the Senate Select Committee on Intelligence, said the panel is "closely monitoring what appears to be a significant cybersecurity breach by Chinese intelligence."

"It's clear that the PRC is steadily improving its cyber collection capabilities directed against the US and our allies," Warner said in a statement.

Disclosure of the Chinese hacking comes on the heels of trips to China by US Secretary of State Antony Blinken and Treasury Secretary Janet Yellen and the shooting down by the United States of a Chinese surveillance balloon.

In May, Microsoft said state-sponsored Chinese hackers called "Volt Typhoon" had infiltrated critical US infrastructure networks.

Microsoft highlighted Guam, a US territory in the Pacific Ocean with a vital military outpost, as one of the targets in that attack, but said "malicious" activity had also been detected elsewhere in the United States.

"Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises," the company said at the time.

Microsoft's May statement coincided with an advisory released by US, Australian, Canadian, New Zealand and British authorities warning that the hacking was likely occurring globally.

China denied the allegations, describing the Microsoft report as "extremely unprofessional" and "scissors-and-paste work."

"It is clear that this is a collective disinformation campaign of the Five Eyes coalition countries, initiated by the US for its geopolitical purposes," foreign ministry spokeswoman Mao Ning said, referring to the security alliance of the United States and its Western allies that wrote the report.

Related Links
Cyberwar - Internet Security News - Systems and Policy Issues

Subscribe Free To Our Daily Newsletters
Tweet

RELATED CONTENT
The following news reports may link to other Space Media Network websites.
CYBER WARS
Serbian intelligence chief sanctioned over corruption, ties to Russia
Washington DC (UPI) Jul 11, 2023
A Serbian politician currently serving as the head of the country's Security Intelligence Agency is now under sanctions, the U.S. Treasury Department confirmed Tuesday. The sanctions against Aleksandar Vulin are being conducted through the department's Office of Foreign Assets Control and are in response to corruption allegations and ties to an already-sanctioned Serbian arms dealer. Vulin was appointed last December and has opposed sanctions against Russia over its war in Ukraine. ... read more

CYBER WARS
Lockheed Martin achieves milestone in PAC-3 MSE Integration with Aegis Weapon System

Swiss want in on Germany's Sky Shield plan

Lockheed Martin targets small businesses via Next Generation Interceptor

Poland to buy US Patriot missile defense systems worth $15 bn

CYBER WARS
First French long-range missiles already in Ukraine

France to send Ukraine SCALP long-range missiles: Macron

France's SCALP missiles: long-range weapon for Ukraine's armoury

4 killed, 37 injured in Russian missile strike on Lviv in Ukraine's far west

CYBER WARS
U.S. kills ISIS leader in Syria with drones that had been harassed by Russia

Pentagon calls on Russia to stop 'reckless behavior' in Syria

CENTCOM: Russian jets harassed U.S. drones in Syria

Drones steal the spotlight at Paris Air Show

CYBER WARS
ATLAS Space launches Freedom Space for Government Missions

SYRACUSE 4B Satellite Launched: Boost for French Military Communications

DoD awards Global X-Band Blanket Purchase Agreement to SES

Ensuring reliable communications between US and Partners at the tactical edge

CYBER WARS
RTX secures $117M contract with US Army for Advanced Targeting Sensor Systems

Fury among aid groups as US approves cluster bombs for Ukraine

MARSS Unveils NiDAR X-JOC: A Transportable, AI-Enabled Command and Control Centre

Lithuania says NATO summit will offer Ukraine 'a lot'

CYBER WARS
Germany pledges 700 mn euros in new arms aid to Ukraine

Biden thanks Erdogan for Sweden decision, backs F-16s sale

Cuba, Russia envisage technical-military cooperation

EU adds 3.5 billion euros to Ukraine weapons fund

CYBER WARS
Existential threat or bogeyman?: Russia's view on NATO

Michel, Erdogan agree to 're-energise' EU-Turkey ties

Xi says Russia and China should 'lead global governance reform'

Biden's Joint Chiefs pick warns Tuberville that military 'will lose talent' over promotion blockade

CYBER WARS
Single-molecule valve: a breakthrough in nanoscale control

Subscribe Free To Our Daily Newsletters




The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.