Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

Microsoft Exchange Successfully Hacked Due to Weak Security Culture, Cyber Safety Review Board Says

by Jerry Petersen
April 3, 2024
in Cybersecurity, DHS, News
Hacker

Hacker

The intrusion by a hacking group affiliated with the People’s Republic of China called Storm-0558 into the Microsoft Exchange Online service during the summer of 2023 could have been prevented, according to a report released by the Cyber Safety Review Board in late March.

Table of Contents

  • You might also like
  • CBP’s Office of Field Operations Unveils 2026–2030 Strategy
  • Space Force Appoints Richard Beckman as PAE for Infrastructure
  • CBO Estimates $275B Cost for Golden Fleet

You might also like

CBP’s Office of Field Operations Unveils 2026–2030 Strategy

Space Force Appoints Richard Beckman as PAE for Infrastructure

CBO Estimates $275B Cost for Golden Fleet

The findings and recommendations within the report are based on a seven-month independent review conducted by the CSRB, which saw participation and cooperation from various stakeholders, including law enforcement organizations, cybersecurity companies, organizations that were impacted by the attack and Microsoft itself, the Department of Homeland Security said Tuesday.

The report attributes the success of Storm-0558’s hacking campaign to the inadequacy of the security culture within Microsoft as illustrated by a number of failures, including the company’s inability to detect the compromised status of an employee’s laptop, through which, it is believed, Storm-0558 managed to obtain Microsoft cryptographic signing keys.

With these keys, the hackers gained access to and exfiltrated information from Microsoft’s email service, compromising the accounts of numerous U.S. government officials, including that of Commerce Secretary Gina Raimondo, Rep. Don Bacon and U.S. Ambassador to the People’s Republic of China R. Nicholas Baum.

Illegal access to the email accounts is believed to have begun in May 15 but Microsoft would not initiate response efforts until June 16, after the Department of State notified the company of anomalous service activity.

To bring about change in Microsoft’s security culture, the report recommends that the company formulate and publicly disclose a plan on how it would reform its security practices, an effort to which senior officers would be held accountable. The report also recommends that, in the meantime, the company divert personnel to focus on product security improvements rather than feature development.

As for the broader industry, the report recommends, among other things, that cloud service providers implement modern control mechanisms as well as emerging digital identity standards. The report also calls for the adoption of a minimum standard for cloud service audit logging to facilitate the detection and investigation of intrusions.

Microsoft Exchange Successfully Hacked Due to Weak Security Culture, Cyber Safety Review Board Says

Cyber experts, government leaders and industry visionaries will speak about the dynamic and evolving role of cyber in the public sector at the Potomac Officers Club’s 2024 Cyber Summit, which will take place in June. Register now to attend this important event!

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Zakiya Carr Johnson Named State Department’s Chief Diversity & Inclusion Officer; Antony Blinken Quoted

Next Post

Digital Engineering, AI, Cloud, Open Integration Keys to Army Modernization, SAIC’s Josh Jackson Says

Recommended For You

Schuyler Moore to Lead Central Command’s Innovation Functions as CTO

by Naomi Cooper
June 6, 2024
Schuyler Moore to Lead Central Command's Innovation Functions as CTO

Schuyler Moore, former director of science and technology for the Defense Innovation Board, has joined U.S. Central Command to serve as its first chief technology officer. In her...

Read moreDetails

Military Seeks Expeditionary, Hybrid Satcom Services for the Future; Brig. Gen. Robert Collins Quoted

by Nichols Martin
September 9, 2021
Brig. Gen. Robert Collins

Brig. Gen. Robert Collins, the U.S. Army's program executive officer for tactical networks, said the military wants to purchase end-to-end services and resilient hardware that can receive satellite...

Read moreDetails

NASA, Boeing Complete Checkpoint Review of Starliner Flight Test Preparations

by Naomi Cooper
May 30, 2023
Crew Flight Test vehicle

NASA and Boeing have completed a joint checkpoint review of the first crewed flight mission of the latter's Starliner spacecraft to the International Space Station. Ninety-five percent of...

Read moreDetails

GSA Reveals 6 New Political Appointees, Promotions

by Miles Jamison
September 11, 2024
GSA Reveals 6 New Political Appointees, Promotions

The U.S. General Services Administration revealed several new political appointees and promotions.The agency said Monday the following will be serving GSA in various capacities:Tadeh Issakhanian has been designated as...

Read moreDetails

Report: Congress, White House to Address Govt Spending, Immigration Issues

by Jane Edwards
March 23, 2018
Report: Congress, White House to Address Govt Spending, Immigration Issues

President Donald Trump’s administration and lawmakers are scheduled to return to Washington this week to address a series of issues that Congress kicked into 2018 in order to...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!