CSRB reports Microsoft Exchange breach by Storm-0558, urges security reforms following espionage incident

Review of the Summer 2023 Microsoft Exchange Online Intrusion (CSRB)

In mid-2023, Storm-0558, linked to China for espionage, breached Microsoft Exchange Online, affecting 22 organizations and over 500 people globally. They exploited 2016-signed tokens to access emails of key US figures like Commerce Secretary Gina Raimondo, Ambassador R. Nicholas Burns, and Congressman Don Bacon, impacting national security.