Case file · STORM-0558 2023

The Storm-0558 Microsoft email hack: one old signing key, 22 organizations

Published 2026-09-29 · 5 min read · Missing control: Rotate and validate login signing keys

In 2023 hackers read the email of the US Commerce Secretary and the US ambassador to China using a single Microsoft signing key that had been created in 2016 and should have expired years earlier.[1][4] This case file covers how one old key opened the inboxes of 22 organizations, why a customer and not Microsoft spotted it, and the control that would have closed the door.

What happened

Starting around May 15, 2023, and possibly earlier, a group Microsoft tracks as Storm-0558 began quietly reading email in Microsoft's cloud-hosted Exchange Online service.[2] The US government's Cyber Safety Review Board, which investigated, described the group as a Chinese nation-state actor.[5]

The intruders reached mailboxes at 22 organizations and more than 500 individuals. Victims included Commerce Secretary Gina Raimondo, Ambassador to China Nicholas Burns, a senior State Department official for East Asia, and a member of Congress. About 60,000 emails were taken from the State Department alone, shortly before senior US officials traveled to China.[1][6]

In mid-June 2023, State Department security analysts noticed unusual mailbox access and alerted Microsoft.[2][4] Microsoft invalidated the stolen key on June 24 and disclosed the attack publicly in July.[1][5] Access had lasted at least 6 weeks.[4]

How they got in

When you log in to a cloud service, it hands your browser a digital pass, called a token, that says who you are. The service trusts that pass because it carries a signature made with a secret key only the provider should hold. Whoever holds that key can make passes for anyone.

The attackers held one of those keys: a Microsoft consumer account signing key from 2016.[1][2] Two things made it far more dangerous than it should have been. First, it was still working in 2023, although the review board found it should have expired in March 2021.[4] Second, a consumer key should only have worked for personal accounts. But Microsoft's mail system did not check which kind of key had signed a pass, so passes signed with the consumer key were accepted for business and government email too.[2][3]

How the key was stolen remains unknown. In September 2023 Microsoft said it had likely leaked through a 2021 crash report copied onto its corporate network and taken from a hacked engineer's account.[3] In March 2024 Microsoft updated that post to say it had never actually found a crash report containing the key, and the review board noted Microsoft had no logs showing the key was taken that way.[1][3]

How it was caught and what it cost

Microsoft did not detect the break-in. The State Department did, because it paid for Microsoft's higher tier of logging and ran its own custom alert rules over those logs. Many other victims lacked that logging and had no way to see the intrusion themselves.[4]

The review board's report, dated March 20, 2024, and released on April 3, called the intrusion preventable and blamed a cascade of Microsoft security failures and a security culture that needed an overhaul.[1][5] It urged Microsoft's leadership to put security ahead of new features until major improvements were made.[1][5] No arrests or charges have been announced. The cost was measured in secrets: diplomatic email read by a foreign intelligence service ahead of high-level talks.

The missing control

The missing control: rotating and validating login signing keys. Keys that sign logins should be retired on schedule, and every system that accepts a login should check that it was signed by the right key for that kind of account.

Either half would have blunted this attack. A key retired in 2021 would have been worthless in 2023 no matter who stole it.[4] And a mail system that rejected consumer-signed passes for business accounts would have kept government inboxes out of reach even with the key in hand.[3] Together they turn a stolen secret from a master key into scrap.

What to do in your business

Watch the case
One stolen Microsoft key, a cabinet secretary's inboxDrops 2026-11-23
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. The Record: DHS review board cites 'cascade of security failures' at Microsoft behind China hack
  2. Help Net Security: A 'cascade' of errors let Chinese hackers into US government inboxes
  3. Microsoft Security Response Center: Results of major technical investigations for Storm-0558 key acquisition
  4. Risky Business News: CSRB lashes Microsoft's 'cascade of security failures'
  5. TechTarget: Cyber Safety Review Board slams Microsoft security failures
  6. iTWire: 2023 Azure breach: US rips Microsoft over 'cascade of security failures'