Connect with us

Hi, what are you looking for?

Tech News

A Rube Goldberg chain of failures led to breach of Microsoft-hosted government emails

Illustration of the Microsoft wordmark on a green background
Illustration: The Verge

In the first half of July, Microsoft disclosed that the Chinese hacking group Storm-0558 had gained access to emails from around 25 organizations, including agencies in the US government. Today, the company is explaining how that happened thanks to a series of internal errors while sharply underscoring just how serious a responsibility it is to maintain massive, growing software infrastructure in an increasingly digitally insecure world.

According to Microsoft’s investigation summary, Storm-0558 was able to gain access to corporate and government emails by obtaining a “Microsoft account consumer key,” which let them create access tokens to their targets’ accounts.

Storm-0558 obtained the key after a Rube Goldberg machine-style series of…

Continue reading…

You May Also Like

Editor's Pick

Gene Healy Last week, the New York Times ran a front-page story admiring President Biden’s political acumen on culture-war issues (“Biden Sidesteps Any Notion...

Editor's Pick

David Boaz I’ve written before about whether athletes take state taxes into account when they weigh competing offers. Here’s another example: Grant Williams left...

Editor's Pick

Jeffrey A. Singer On the same day that the Food and Drug Administration allowed women over‐​the‐​counter access to one progestin‐​only birth control pill, Rep....

Editor's Pick

Marc Joffe Last week the House Appropriations Subcommittee on Transportation, Housing and Urban Development, and Related Agencies approved a Fiscal Year 2024 budget that forbids...