Security

CSO

Chinese snoops stole 60K State Department emails in that Microsoft email heist

No classified systems involved apparently, but internal diplomatic notes, travel details, staff SSNs, etc


Chinese snoops stole about 60,000 State Department emails when they broke into Microsoft-hosted Outlook and Exchange Online accounts belonging to US government officials over the summer.

"No classified systems were hacked," said State Department spokesperson Matthew Miller during a press briefing Thursday. "These only related to the unclassified systems."

The emails exfiltrated from Microsoft's cloud belonged to 10 State Department officials, nine of whom were working on Indo-Pacific diplomatic efforts, according to Politico. Data stolen from the inboxes reportedly included travel itineraries, diplomatic deliberations, and the 10 officials' Social Security numbers.

Microsoft admits unauthorized access to Exchange Online, blames Chinese gang

READ MORE

The thieves also accessed a list of every State Department email address, according to CNN. These email addresses could be used in future phishing campaigns and other social-engineering schemes.

And while the State Department has not yet formally blamed China or one of its cyber-espionage crews for the break-in, "we have no reason to doubt the attribution that Microsoft has made publicly," Miller said during the briefing.

The State Department uncovered the breach in July and notified Microsoft, which then attributed the intrusion to a China-based threat actor it tracks as Storm-0558

In total, the crooks gained access to email data from around 25 organizations, which also included the US Commerce Department, Microsoft said at the time. 

Earlier this month, Redmond said the cyber-snoops were able to break into the federal government's email accounts because the spies compromised a Microsoft engineer's corporate account and stole a cryptographic key from a software crash dump that should not have contained a copy of the super-secret key in the first place. That key was then used to unlock Uncle Sam's email inboxes hosted by Microsoft in its cloud.

The stolen-emails admission comes as Uncle Sam increasingly sounds the alarm on cyber-espionage threats posed by Chinese government-backed thieves.

Yesterday, US and Japanese law enforcement and cybersecurity agencies warned that Beijing's spies may be hiding in organizations' Cisco routers and using that access to steal sensitive information. The agencies attributed the espionage to a gang called BlackTech that, we're told, targets government, industrial, technology, media, electronics, telecommunication, and defense players in the US and East Asia. 

In July, FBI Director Christopher Wray accused China of stealing "more of our personal and corporate data than every nation big or small, combined." 

The FBI has also attributed attacks against Barracuda Email Security Gateway appliances to China, and said snoops likely exploited a bug in that equipment back in October 2022 even though they weren't noticed until May 2023. 

Nearly one-third of these intrusions hit government agencies, according to Mandiant. ®

Send us news
4 Comments

Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

The Russians are coming! Err, they've already infiltrated UK, US inboxes

Fancy Bear goes phishing in US, European high-value networks

GRU-linked crew going after our code warns Microsoft - Outlook not good

Microsoft issues deadline for end of Windows 10 support – it's pay to play for security

Limited options will be available into 2028, for an undisclosed price

Attacks abuse Microsoft DHCP to spoof DNS records and steal secrets

Akamai says it reported the flaws to Microsoft. Redmond shrugged

Belgian man charged with smuggling sanctioned military tech to Russia and China

Indictments allege plot to shift FPGAs, accelerometers, and spycams

Dump C++ and in Rust you should trust, Five Eyes agencies urge

Memory safety vulnerabilities need to be crushed with better code

Google submits complaints about Microsoft licensing to UK competition regulator

Now Microsoft has regulator breathing down its neck in three regions

Uncle Sam probes cyberattack on Pennsylvania water system by suspected Iranian crew

CISA calls for stronger IT defenses as Texas district also hit by ransomware crew

Microsoft pushes Azure Government Cloud as homefront defender

All your national security are belong to us!

Polish train maker denies claims its software bricked rolling stock maintained by competitor

Says it was probably hacked, which isn't good news either

Hershey phishes! Crooks snarf chocolate lovers' creds

Stealing Kit Kat maker's data?! Give me a break

Scores of US credit unions offline after ransomware infects backend cloud outfit

Supply chain attacks: The gift that keeps on giving