Microsoft: Chinese Hackers Breached US Govt Email Accounts

FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
TT

Microsoft: Chinese Hackers Breached US Govt Email Accounts

FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo

Chinese-based hackers seeking intelligence information breached the email accounts of a number of US government agencies, computer giant Microsoft said.

"The threat actor Microsoft links to this incident is an adversary based in China that Microsoft calls Storm-0558," the company said in a blog post late Tuesday.

Microsoft said Storm-0558 gained access to email accounts at approximately 25 organizations including government agencies, AFP said.

Microsoft did not identify the targets but a US State Department spokesperson said the department had "detected anomalous activity" and had taken "immediate steps to secure our systems."

"As a matter of cybersecurity policy, we do not discuss details of our response and the incident remains under investigation," the spokesperson said.

According to The Washington Post, the breached email accounts were unclassified and "Pentagon, intelligence community and military email accounts did not appear to be affected."

But the paper reported Wednesday evening, quoting US officials, that State Department email accounts and that of Commerce Secretary Gina Raimondo were hacked. Raimondo's agency has angered China by imposing tough export controls on Chinese technologies.

CNN, citing sources familiar with the investigation, said the Chinese hackers targeted a small number of federal agencies and the email accounts of specific officials at each agency.

In the blog post, Charlie Bell, a Microsoft executive vice president, said "we assess this adversary is focused on espionage, such as gaining access to email systems for intelligence collection.

"This type of espionage-motivated adversary seeks to abuse credentials and gain access to data residing in sensitive systems," Bell said.

US National Security Adviser Jake Sullivan addressed the hack in an appearance on Wednesday on ABC's Good Morning America, and said it had been detected "fairly rapidly."

"We were able to prevent further breaches," Sullivan said.

"The matter is still being investigated, so I have to leave it there because we're gathering further information in consultation with Microsoft and we will continue to apprise the public as we learn more," Sullivan said.

Espionage and data theft
Microsoft said Storm-0558 "primarily targets government agencies in Western Europe and focuses on espionage, data theft, and credential access."

The Redmond, Washington-based company said it had launched an investigation into "anomalous mail activity" on June 16.

"Over the next few weeks, our investigation revealed that beginning on May 15, 2023, Storm-0558 gained access to email accounts affecting approximately 25 organizations including government agencies as well as related consumer accounts.

"They did this by using forged authentication tokens to access user email using an acquired Microsoft account consumer signing key," the company said. "Microsoft has completed mitigation of this attack for all customers."

US Senator Mark Warner, chairman of the Senate Select Committee on Intelligence, said the panel is "closely monitoring what appears to be a significant cybersecurity breach by Chinese intelligence."

"It's clear that the PRC is steadily improving its cyber collection capabilities directed against the US and our allies," Warner said in a statement.

Disclosure of the Chinese hacking comes on the heels of trips to China by US Secretary of State Antony Blinken and Treasury Secretary Janet Yellen and the shooting down by the United States of a Chinese surveillance balloon.

In May, Microsoft said state-sponsored Chinese hackers called "Volt Typhoon" had infiltrated critical US infrastructure networks.

Microsoft highlighted Guam, a US territory in the Pacific Ocean with a vital military outpost, as one of the targets in that attack, but said "malicious" activity had also been detected elsewhere in the United States.

"Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises," the company said at the time.

Microsoft's May statement coincided with an advisory released by US, Australian, Canadian, New Zealand and British authorities warning that the hacking was likely occurring globally.

China denied the allegations, describing the Microsoft report as "extremely unprofessional" and "scissors-and-paste work."

"It is clear that this is a collective disinformation campaign of the Five Eyes coalition countries, initiated by the US for its geopolitical purposes," foreign ministry spokeswoman Mao Ning said, referring to the security alliance of the United States and its Western allies that wrote the report.



US Supreme Court Upholds Law Banning TikTok If It’s Not Sold by Its Chinese Parent Company

A person live streams to their TikTok followers as the high justices rule to uphold a ban on the video-sharing app TikTok in the TikTok vs. Merrick Garland case in Washington, DC, USA, 17 January 2025. (EPA)
A person live streams to their TikTok followers as the high justices rule to uphold a ban on the video-sharing app TikTok in the TikTok vs. Merrick Garland case in Washington, DC, USA, 17 January 2025. (EPA)
TT

US Supreme Court Upholds Law Banning TikTok If It’s Not Sold by Its Chinese Parent Company

A person live streams to their TikTok followers as the high justices rule to uphold a ban on the video-sharing app TikTok in the TikTok vs. Merrick Garland case in Washington, DC, USA, 17 January 2025. (EPA)
A person live streams to their TikTok followers as the high justices rule to uphold a ban on the video-sharing app TikTok in the TikTok vs. Merrick Garland case in Washington, DC, USA, 17 January 2025. (EPA)

The Supreme Court on Friday unanimously upheld the federal law banning TikTok beginning Sunday unless it's sold by its China-based parent company, holding that the risk to national security posed by its ties to China overcomes concerns about limiting speech by the app or its 170 million users in the United States.

A sale does not appear imminent and, although experts have said the app will not disappear from existing users' phones once the law takes effect on Jan. 19, new users won't be able to download it and updates won't be available. That will eventually render the app unworkable, the Justice Department has said in court filings.

The decision came against the backdrop of unusual political agitation by President-elect Donald Trump, who vowed that he could negotiate a solution and the administration of President Joe Biden, which has signaled it won't enforce the law beginning Sunday, his final full day in office.

Trump, mindful of TikTok’s popularity, and his own 14.7 million followers on the app, finds himself on the opposite side of the argument from prominent Senate Republicans who fault TikTok’s Chinese owner for not finding a buyer before now. Trump said in a Truth Social post shortly before the decision was issued that TikTok was among the topics in his conversation Friday with Chinese leader Xi Jinping.

It’s unclear what options are open to Trump once he is sworn in as president on Monday. The law allowed for a 90-day pause in the restrictions on the app if there had been progress toward a sale before it took effect. Solicitor General Elizabeth Prelogar, who defended the law at the Supreme Court for the Democratic Biden administration, told the justices last week that it's uncertain whether the prospect of a sale once the law is in effect could trigger a 90-day respite for TikTok.

“Congress has determined that divestiture is necessary to address its well-supported national security concerns regarding TikTok’s data collection practices and relationship with a foreign adversary,” the court said in an unsigned opinion, adding that the law “does not violate petitioners' First Amendment rights.”

Justices Sonia Sotomayor and Neil Gorsuch filed short separate opinions noting some reservations about the court's decision but going along with the outcome.

“Without doubt, the remedy Congress and the President chose here is dramatic,” Gorsuch wrote. Still, he said he was persuaded by the argument that China could get access to “vast troves of personal information about tens of millions of Americans.”

Some digital rights groups slammed the court’s ruling shortly after it was released.

“Today’s unprecedented decision upholding the TikTok ban harms the free expression of hundreds of millions of TikTok users in this country and around the world,” said Kate Ruane, a director at the Washington-based Center for Democracy & Technology, which has supported TikTok’s challenge to the federal law.

Content creators who opposed the law also worried about the effect on their business if TikTok shuts down. “I’m very, very concerned about what’s going to happen over the next couple weeks,” said Desiree Hill, owner of Crown’s Corner mechanic shop in Conyers, Georgia. “And very scared about the decrease that I’m going to have in reaching customers and worried I’m going to potentially lose my business in the next six months.”

At arguments, the justices were told by a lawyer for TikTok and ByteDance Ltd., the Chinese technology company that is its parent, how difficult it would be to consummate a deal, especially since Chinese law restricts the sale of the proprietary algorithm that has made the social media platform wildly successful.

The app allows users to watch hundreds of videos in about half an hour because some are only a few seconds long, according to a lawsuit filed last year by Kentucky complaining that TikTok is designed to be addictive and harms kids' mental health. Similar suits were filed by more than a dozen states. TikTok has called the claims inaccurate.

The dispute over TikTok's ties to China has come to embody the geopolitical competition between Washington and Beijing.

“ByteDance and its Chinese Communist masters had nine months to sell TikTok before the Sunday deadline,” Sen. Tom Cotton, R-Ark., wrote on X. “The very fact that Communist China refuses to permit its sale reveals exactly what TikTok is: a communist spy app. The Supreme Court correctly rejected TikTok’s lies and propaganda masquerading as legal arguments.”

The US has said it’s concerned about TikTok collecting vast swaths of user data, including sensitive information on viewing habits, that could fall into the hands of the Chinese government through coercion. Officials have also warned the algorithm that fuels what users see on the app is vulnerable to manipulation by Chinese authorities, who can use it to shape content on the platform in a way that’s difficult to detect.

TikTok points out the US has not presented evidence that China has attempted to manipulate content on its US platform or gather American user data through TikTok.

Bipartisan majorities in Congress passed legislation and Biden signed it into law in April. The law was the culmination of a yearslong saga in Washington over TikTok, which the government sees as a national security threat.

TikTok, which sued the government last year over the law, has long denied it could be used as a tool of Beijing. A three-judge panel made up of two Republican appointees and a Democratic appointee unanimously upheld the law in December, prompting TikTok’s quick appeal to the Supreme Court.

Without a sale to an approved buyer, the law bars app stores operated by Apple, Google and others from offering TikTok beginning on Sunday. Internet hosting services also will be prohibited from hosting TikTok.

ByteDance has said it won’t sell. But some investors have been eyeing it, including Trump’s former Treasury Secretary Steven Mnuchin and billionaire businessman Frank McCourt. McCourt’s Project Liberty initiative has said it and its unnamed partners have presented a proposal to ByteDance to acquire TikTok’s US assets. The consortium, which includes “Shark Tank” host Kevin O’Leary, did not disclose the financial terms of the offer.

McCourt, in a statement following the ruling, said his group was “ready to work with the company and President Trump to complete a deal.”

Prelogar told the justices last week that having the law take effect “might be just the jolt” ByteDance needs to reconsider its position.