Microsoft: Chinese Hackers Breached US Govt Email Accounts

FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
TT

Microsoft: Chinese Hackers Breached US Govt Email Accounts

FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo

Chinese-based hackers seeking intelligence information breached the email accounts of a number of US government agencies, computer giant Microsoft said.

"The threat actor Microsoft links to this incident is an adversary based in China that Microsoft calls Storm-0558," the company said in a blog post late Tuesday.

Microsoft said Storm-0558 gained access to email accounts at approximately 25 organizations including government agencies, AFP said.

Microsoft did not identify the targets but a US State Department spokesperson said the department had "detected anomalous activity" and had taken "immediate steps to secure our systems."

"As a matter of cybersecurity policy, we do not discuss details of our response and the incident remains under investigation," the spokesperson said.

According to The Washington Post, the breached email accounts were unclassified and "Pentagon, intelligence community and military email accounts did not appear to be affected."

But the paper reported Wednesday evening, quoting US officials, that State Department email accounts and that of Commerce Secretary Gina Raimondo were hacked. Raimondo's agency has angered China by imposing tough export controls on Chinese technologies.

CNN, citing sources familiar with the investigation, said the Chinese hackers targeted a small number of federal agencies and the email accounts of specific officials at each agency.

In the blog post, Charlie Bell, a Microsoft executive vice president, said "we assess this adversary is focused on espionage, such as gaining access to email systems for intelligence collection.

"This type of espionage-motivated adversary seeks to abuse credentials and gain access to data residing in sensitive systems," Bell said.

US National Security Adviser Jake Sullivan addressed the hack in an appearance on Wednesday on ABC's Good Morning America, and said it had been detected "fairly rapidly."

"We were able to prevent further breaches," Sullivan said.

"The matter is still being investigated, so I have to leave it there because we're gathering further information in consultation with Microsoft and we will continue to apprise the public as we learn more," Sullivan said.

Espionage and data theft
Microsoft said Storm-0558 "primarily targets government agencies in Western Europe and focuses on espionage, data theft, and credential access."

The Redmond, Washington-based company said it had launched an investigation into "anomalous mail activity" on June 16.

"Over the next few weeks, our investigation revealed that beginning on May 15, 2023, Storm-0558 gained access to email accounts affecting approximately 25 organizations including government agencies as well as related consumer accounts.

"They did this by using forged authentication tokens to access user email using an acquired Microsoft account consumer signing key," the company said. "Microsoft has completed mitigation of this attack for all customers."

US Senator Mark Warner, chairman of the Senate Select Committee on Intelligence, said the panel is "closely monitoring what appears to be a significant cybersecurity breach by Chinese intelligence."

"It's clear that the PRC is steadily improving its cyber collection capabilities directed against the US and our allies," Warner said in a statement.

Disclosure of the Chinese hacking comes on the heels of trips to China by US Secretary of State Antony Blinken and Treasury Secretary Janet Yellen and the shooting down by the United States of a Chinese surveillance balloon.

In May, Microsoft said state-sponsored Chinese hackers called "Volt Typhoon" had infiltrated critical US infrastructure networks.

Microsoft highlighted Guam, a US territory in the Pacific Ocean with a vital military outpost, as one of the targets in that attack, but said "malicious" activity had also been detected elsewhere in the United States.

"Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises," the company said at the time.

Microsoft's May statement coincided with an advisory released by US, Australian, Canadian, New Zealand and British authorities warning that the hacking was likely occurring globally.

China denied the allegations, describing the Microsoft report as "extremely unprofessional" and "scissors-and-paste work."

"It is clear that this is a collective disinformation campaign of the Five Eyes coalition countries, initiated by the US for its geopolitical purposes," foreign ministry spokeswoman Mao Ning said, referring to the security alliance of the United States and its Western allies that wrote the report.



TikTok Faces US Ban Deadline as Users Brace for Fallout

A social media influencer films a video for his new Xiaohongshu, also known as RedNote, after leaving TikTok, in Times Square in New York City, US, January 16, 2025. REUTERS/Brendan McDermid/File Photo
A social media influencer films a video for his new Xiaohongshu, also known as RedNote, after leaving TikTok, in Times Square in New York City, US, January 16, 2025. REUTERS/Brendan McDermid/File Photo
TT

TikTok Faces US Ban Deadline as Users Brace for Fallout

A social media influencer films a video for his new Xiaohongshu, also known as RedNote, after leaving TikTok, in Times Square in New York City, US, January 16, 2025. REUTERS/Brendan McDermid/File Photo
A social media influencer films a video for his new Xiaohongshu, also known as RedNote, after leaving TikTok, in Times Square in New York City, US, January 16, 2025. REUTERS/Brendan McDermid/File Photo

TikTok buzzed with nervous anticipation across the US on Saturday as a looming federal ban threatened to sever access to the Chinese-owned app that has captivated nearly half of all Americans, powered small businesses and shaped online culture.

The company said late Friday that it will go dark in the United States on Sunday unless President Joe Biden's administration provides assurances to companies like Apple and Google that they will not face enforcement actions when a ban takes effect.

The ban would be enacted under a law signed by President Joe Biden in April and mark the first US shutdown of a major social media app -- with TikTok boasting about 170 million domestic users and an estimated $20 billion in 2025 revenue.

The platform has until Sunday to cut ties with its China-based parent ByteDance or shut down its US operation to resolve concerns it posed a threat to national security.

Supreme Court justices upheld the ban on Friday in a unanimous decision and a White House statement suggested Biden would not take any action to save TikTok before the deadline.

Without a decision by Biden to formally invoke a 90-day delay in the deadline, companies providing services to TikTok or hosting the app could face legal liability. It is not clear if TikTok's business partners, including Apple, Alphabet's Google and Oracle, will continue doing business with it before Trump is inaugurated on Monday, according to Reuters.

Uncertainty over the app's future had sent users - mostly made up of younger people - scrambling to alternatives including China-based RedNote. Rivals Meta and Snap had also seen their shares rise this month ahead of the ban, as investors bet on an influx of users and ad dollars.

Marketing firms reliant on TikTok have rushed to prepare contingency plans this week in what one executive described as a "hair on fire" moment after months of conventional wisdom saying that a solution would materialize to keep the app running.

There have been signs that TikTok could make a comeback under incoming US President Donald Trump, who wants to pursue a "political resolution" of the issue and had last month urged the Supreme Court to pause implementation of the ban.

Trump said on Friday the decision on the future of the TikTok app will be up to him, but he did not provide any detail about what steps he would take. Media reports have said that he was considering an executive order that would suspend the enforcement of the TikTok sale-or-ban law for 60 to 90 days.

TikTok CEO Shou Zi Chew plans to attend the US presidential inauguration on Jan. 20 and sit among high-profile guests invited by Trump, a source told Reuters.

Suitors including former Los Angeles Dodgers owner Frank McCourt have expressed interest in the fast-growing business that analysts estimate could be worth as much as $50 billion. Media reports say Beijing has also held talks about selling TikTok's US operations to billionaire and Trump ally Elon Musk, though the company has denied that.

Privately held ByteDance is about 60% owned by institutional investors such as BlackRock and General Atlantic, while its founders and employees own 20% each. It has more than 7,000 employees in the US.