NewsBytes
    Hindi Tamil Telugu
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi Tamil Telugu
    NewsBytes
    User Placeholder

    Hi,

    Logout

    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Inspirational
    Career
    Bengaluru
    Delhi
    Mumbai

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / Microsoft could have stopped 2023 Chinese email breach: US government
    Summarize
    Next Article
    Microsoft could have stopped 2023 Chinese email breach: US government
    The email accounts of 22 organizations were hacked

    Microsoft could have stopped 2023 Chinese email breach: US government

    By Dwaipayan Roy
    Apr 03, 2024
    05:09 pm

    What's the story

    An investigation by the US Cyber Safety Review Board has revealed that a significant breach of government emails in 2023, could have been prevented by Microsoft.

    The breach was executed through Microsoft Exchange Online software and was described as a "cascade of security failures" at the tech giant.

    This lapse in security permitted Chinese state-sponsored hackers to infiltrate the email accounts of 22 organizations, affecting over 500 individuals, including those involved in national security.

    Findings

    DHS report labels breach as 'preventable'

    The Department of Homeland Security (DHS) issued a critical report, labeling the breach as "preventable."

    The report pointed out several actions within Microsoft that led to "a corporate culture that deprioritized enterprise security investments and rigorous risk management."

    Hackers exploited a Microsoft account consumer key to generate tokens, for accessing Outlook on the web and Outlook.com.

    While it is unclear how the key was stolen, it is suspected to have been part of a crash dump.

    Admission

    Microsoft admits to misinformation in initial report

    Microsoft admitted to the Cyber Safety Review Board in November, that its September blog post about the incident contained inaccuracies.

    However, it only corrected this misinformation on March 12, months later, after persistent questioning by the board.

    CSRB concluded that Microsoft's security culture requires significant improvement.

    It stated, "The Board finds that this intrusion was preventable and should never have occurred."

    New launch

    AI-powered chatbot launched amid security concerns

    The disclosure of the breach coincides with Microsoft's launch of Copilot for Security. It is an AI-powered chatbot designed for cybersecurity professionals.

    The company is charging businesses $4 per hour of usage to access this newest AI tool.

    Meanwhile, Microsoft continues to grapple with ongoing attacks from Russian state-sponsored hackers, known as Nobelium, who infiltrated some Microsoft executive email accounts and stole some of the company's source code.

    Overhaul

    Microsoft initiates major overhaul of software security

    In response to these security breaches, Microsoft is undertaking a significant overhaul of its software security with the new Secure Future Initiative (SFI).

    The SFI aims to transform how Microsoft designs, builds, tests, and uses its software and services.

    This initiative represents the most substantial change to Microsoft's security efforts since the rollout of its Security Development Lifecycle (SDL) in 2004.

    It was introduced following the Blaster worm that hit Windows XP machines offline in 2003.

    Recommendations

    CSRB recommends immediate security improvements

    The CSRB has recommended that Microsoft halt feature addition to its cloud computing environment until "substantial security improvements have been made."

    The panel also requested Microsoft CEO Satya Nadella to initiate "rapid cultural change" and publicly share "a plan with specific timelines to make fundamental, security-focused reforms across the company and its full suite of products."

    Response

    Microsoft pledges to strengthen systems against future attacks

    In response to the report, Microsoft expressed appreciation for the CSRB's investigation.

    It also pledged to "continue to harden all our systems against attack and implement even more robust sensors and logs to help us detect and repel the cyber-armies of our adversaries."

    The company accepted that the involved hackers are "well-resourced nation state threat actors who operate continuously and without meaningful deterrence."

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Microsoft
    Satya Nadella
    US Government
    Cybercrimes

    Latest

    Is Matt Reeves not returning for 'The Batman 2'?  James Gunn
    This AI uses selfies to predict cancer survival chances Artificial Intelligence and Machine Learning
    'Nothing greater than nation': BCCI secretary amid IPL 2025 suspension  Indian Premier League (IPL)
    Meet SkyStriker, made-in-Bengaluru suicide drones deployed in Operation Sindoor Bengaluru

    Microsoft

    Microsoft's new API will aid game developers in AI upscaling Artificial Intelligence and Machine Learning
    Microsoft adds new Copilot skills, AI features to Windows 11 Windows 11
    Microsoft introduces Copilot AI chatbot for Excel and Outlook Artificial Intelligence and Machine Learning
    NVIDIA surpasses Saudi Aramco, becomes 3rd largest company by m-cap NVIDIA

    Satya Nadella

    Satya Nadella turns author with 'Hit Refresh' Microsoft
    Engineers' Day: The Indian legends making us proud India
    Taking three-dimensional (3D) selfies? Yup, AI can do that Bill Gates
    Knowing Satya Nadella beyond Microsoft India

    US Government

    US: Trump temporarily ends longest government shutdown in history Donald Trump
    Trump to sign funding deal; will declare national emergency anyway Donald Trump
    #ComicBytes: Five worst things which Captain America has done White House
    #ComicBytes: Five lesser-known facts about Superman Superman

    Cybercrimes

    Investment scam: Chinese masterminds swindle Rs. 700cr from 15,000 Indians China
    Haryana violence: Govinda clears air on now-deleted controversial tweet Govinda
    Ransomware attacks surged by 133% in India amid global decline India
    Police verification mandatory for SIM card dealers, bulk connections discontinued Ashwini Vaishnaw
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025