From mid-May 2023, a China-based espionage group Microsoft tracks as Storm-0558 read the email of more than 500 people at 22 organisations, including US State Department and Commerce Department officials. It did not phish them. It forged authentication tokens with a Microsoft account (MSA) consumer signing key created in 2016, one that should have been retired in 2021 but was still valid. A flaw in token validation meant Exchange Online accepted tokens signed with that consumer key for enterprise mailboxes too. The State Department spotted anomalous mail access on 15 June 2023 and alerted Microsoft the next day. Microsoft still does not know how the key was stolen. It first said a 2021 crash dump was the most probable route, then clarified in March 2024 that no such crash dump had been found. The US Cyber Safety Review Board (CSRB) called the intrusion preventable, the result of a "cascade" of Microsoft errors.
Key takeaways
- Storm-0558 forged tokens with a stolen 2016 MSA consumer signing key and used them to read Outlook Web Access and Outlook.com mail from mid-May 2023.
- The key should have been retired in 2021, but manual rotation of consumer keys had stopped that year after an outage, leaving old keys active, according to the CSRB as reported by BleepingComputer.
- Mail systems accepted consumer-signed tokens for enterprise accounts because libraries did not validate key scope automatically and developers assumed they did, Microsoft says.
- Microsoft does not know how the key was stolen; its crash dump theory was later clarified as unproven, and the CSRB found no definitive evidence.
- The identity lesson: signing keys are the most powerful non-human identities of all, and they need inventory, automated rotation, isolation and detection like nothing else.
At a glance
| Organisations | Microsoft; 22 organisations including the US State Department and Commerce Department, with more than 500 individual email accounts compromised |
|---|---|
| When | Intrusion from about 15 May 2023; detected by the State Department on 15 June 2023; disclosed by Microsoft 11 July 2023; CSRB review published April 2024 |
| Attacker | Storm-0558, a China-based espionage actor, according to Microsoft |
| Entry point | A stolen Microsoft account (MSA) consumer signing key; how it was obtained is unknown |
| Identities abused | The 2016 MSA consumer signing key; forged authentication tokens accepted by Exchange Online for enterprise mailboxes |
| Impact | Email accessed at 22 organisations, including senior US government officials; the CSRB said the key and validation flaw allowed full access to "essentially any Exchange Online account" |
| Category | NHI. Incident class: confirmed NHI breach (stolen signing key used to forge tokens) |
What happened
On 15 June 2023, analysts in the US State Department's security operations centre saw anomalous access to mail. They had bought a Microsoft 365 G5 licence with premium audit logging and had built a custom alert, nicknamed "Big Yellow Taxi", on the MailItemsAccessed log. The State Department alerted Microsoft on 16 June. Further logs showed the intrusion had begun by 15 May and possibly earlier, according to Help Net Security's account of the CSRB review. Organisations without premium logging could not detect the same activity, which led Microsoft to expand logging for all customers.
Microsoft published its preliminary findings on 11 July 2023. Storm-0558 had "used an acquired Microsoft account (MSA) consumer key to forge tokens to access OWA and Outlook.com." The key was a consumer key, but Exchange Online accepted it for enterprise mail. Microsoft explained that in 2018 it had introduced a common key metadata endpoint serving both enterprise and consumer keys and documented that applications must check key scope, but "did not update these libraries to perform this scope validation automatically." When the mail system moved to the common endpoint in 2022, "developers in the mail system incorrectly assumed libraries performed complete validation and did not add the required issuer/scope validation."
How the key was taken remains unknown. In September 2023, Microsoft said a consumer signing system crash in April 2021 had produced a crash dump containing the key, which was moved to a debugging environment on the internet-connected corporate network; exfiltration through a compromised engineer's account was "the most probable mechanism by which the actor acquired the key." On 12 March 2024 it added that "we have not found a crash dump containing the impacted key material." Its "leading hypothesis remains that operational errors resulted in key material leaving the secure token signing environment that was subsequently accessed in a debugging environment via a compromised engineering account."
The CSRB's review, published in April 2024, found that the 2016 key should have been retired in March 2021. BleepingComputer reported that consumer key rotation had been manual and was stopped entirely in 2021 after a major outage, "leaving no system in place to alert employees of old, active signing keys." The Board concluded: "The Board finds that this intrusion was preventable and should never have occurred. The Board also concludes that Microsoft's security culture was inadequate and requires an overhaul."
Timeline
| Date | Event |
|---|---|
| 2016 | Microsoft creates the MSA consumer signing key later used by Storm-0558. |
| 2021 | Manual consumer key rotation stops; the 2016 key, due to be retired, stays active, according to the CSRB. |
| 15 May 2023 | Storm-0558's access to mailboxes has begun by this date. |
| 15 June 2023 | The State Department's security team detects anomalous mail access. |
| 16 June 2023 | The State Department alerts Microsoft. |
| 11 July 2023 | Microsoft discloses the intrusion and the forged tokens. |
| 6 September 2023 | Microsoft publishes its key acquisition findings, citing a 2021 crash dump as most probable. |
| 12 March 2024 | Microsoft updates its findings: no crash dump containing the key has been found. |
| April 2024 | The CSRB publishes its review, calling the intrusion preventable. |
How it happened: the identity attack path
- A signing key that never retired. A 2016 consumer MSA signing key remained valid after manual rotation stopped in 2021.
- Key stolen. Storm-0558 obtained the key by a route Microsoft has not been able to establish.
- Tokens forged. The actor signed its own authentication tokens with the key.
- Scope not validated. Exchange Online accepted consumer-signed tokens for enterprise accounts because issuer and scope checks were missing.
- Silent mailbox access. The actor read mail at 22 organisations; only customers with premium audit logs could see it.
Impact
- Confirmed: more than 500 individuals' email accounts at 22 organisations compromised, including US State Department and Commerce Department officials.
- Potential: the CSRB said the key and flaw allowed full access to "essentially any Exchange Online account".
- Industry response: Microsoft expanded free logging, fixed key scope validation in its libraries and changed key management practices.
What this means for NHI governance
A token signing key is the identity behind every other identity: whoever holds it can mint access for anyone. Here, one such key outlived its intended life by years because rotation was manual and then stopped, and there was no inventory or alerting to show that an old key was still trusted. When it was stolen, no password, MFA or device control stood in the way.
The validation gap made it worse. Accepting a key without checking what it was issued for is the machine equivalent of accepting any ID card without reading it. Signing keys need hardware protection, automated rotation, an authoritative inventory, strict scope validation by every relying service, and detection for tokens that do not match expected issuers. See our Cryptographic Key Management Guide and Identity Provider and SSO Security Guide.
Recommendations
- Automate signing key rotation and retirement. Keep an inventory of every trusted key with its expiry, and alert on keys past retirement. See the Cryptographic Key Management Guide.
- Keep signing keys in hardware. Keys in HSMs cannot end up in crash dumps or debugging environments.
- Validate issuer and scope on every token. Relying services must check which key and issuer a token uses, not only that the signature is valid. See the Token and Session Security Guide.
- Enable and retain detailed audit logs. Mail access logging was what caught this; make sure you have it and keep it long enough. See the ITDR Guide.
- Vet devices from acquisitions before they connect. The CSRB criticised connecting an acquired company's compromised laptop to the corporate network.
Frequently asked questions
What was the Storm-0558 attack?
A China-based espionage group used a stolen Microsoft consumer signing key to forge authentication tokens and read the email of more than 500 people at 22 organisations, including US government officials, from mid-May 2023.
How did Storm-0558 get Microsoft's signing key?
Microsoft does not know. It first said a 2021 crash dump was the most probable route but later clarified that no crash dump containing the key has been found. The CSRB found no definitive evidence either.
Why did a consumer key work for government email?
Microsoft's libraries did not automatically check key scope, and the mail system's developers assumed they did, so Exchange Online accepted consumer-signed tokens for enterprise accounts.
Related NHI Mgmt Group resources
Microsoft Midnight Blizzard Breach · SolarWinds and Golden SAML · Cryptographic Key Management Guide · Token and Session Security Guide · Identity Provider and SSO Security Guide
How NHI Mgmt Group can help
Signing keys, certificates and token issuers sit at the root of every identity system. We help teams inventory them, automate rotation and check that every service validates tokens properly. See our NHI and AI agent security training.
References
- Microsoft MSRC: Results of Major Technical Investigations for Storm-0558 Key Acquisition, updated (12 March 2024)
- BleepingComputer: Microsoft still unsure how hackers stole MSA key in 2023 Exchange attack (3 April 2024)
- Help Net Security: A "cascade" of errors let Chinese hackers into US government inboxes (3 April 2024)