Microsoft: Chinese Hackers Breached US Govt Email Accounts

FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
TT

Microsoft: Chinese Hackers Breached US Govt Email Accounts

FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: Microsoft logo is seen on a smartphone placed on displayed Activision Blizzard logo in this illustration taken January 18, 2022. REUTERS/Dado Ruvic/Illustration/File Photo

Chinese-based hackers seeking intelligence information breached the email accounts of a number of US government agencies, computer giant Microsoft said.

"The threat actor Microsoft links to this incident is an adversary based in China that Microsoft calls Storm-0558," the company said in a blog post late Tuesday.

Microsoft said Storm-0558 gained access to email accounts at approximately 25 organizations including government agencies, AFP said.

Microsoft did not identify the targets but a US State Department spokesperson said the department had "detected anomalous activity" and had taken "immediate steps to secure our systems."

"As a matter of cybersecurity policy, we do not discuss details of our response and the incident remains under investigation," the spokesperson said.

According to The Washington Post, the breached email accounts were unclassified and "Pentagon, intelligence community and military email accounts did not appear to be affected."

But the paper reported Wednesday evening, quoting US officials, that State Department email accounts and that of Commerce Secretary Gina Raimondo were hacked. Raimondo's agency has angered China by imposing tough export controls on Chinese technologies.

CNN, citing sources familiar with the investigation, said the Chinese hackers targeted a small number of federal agencies and the email accounts of specific officials at each agency.

In the blog post, Charlie Bell, a Microsoft executive vice president, said "we assess this adversary is focused on espionage, such as gaining access to email systems for intelligence collection.

"This type of espionage-motivated adversary seeks to abuse credentials and gain access to data residing in sensitive systems," Bell said.

US National Security Adviser Jake Sullivan addressed the hack in an appearance on Wednesday on ABC's Good Morning America, and said it had been detected "fairly rapidly."

"We were able to prevent further breaches," Sullivan said.

"The matter is still being investigated, so I have to leave it there because we're gathering further information in consultation with Microsoft and we will continue to apprise the public as we learn more," Sullivan said.

Espionage and data theft
Microsoft said Storm-0558 "primarily targets government agencies in Western Europe and focuses on espionage, data theft, and credential access."

The Redmond, Washington-based company said it had launched an investigation into "anomalous mail activity" on June 16.

"Over the next few weeks, our investigation revealed that beginning on May 15, 2023, Storm-0558 gained access to email accounts affecting approximately 25 organizations including government agencies as well as related consumer accounts.

"They did this by using forged authentication tokens to access user email using an acquired Microsoft account consumer signing key," the company said. "Microsoft has completed mitigation of this attack for all customers."

US Senator Mark Warner, chairman of the Senate Select Committee on Intelligence, said the panel is "closely monitoring what appears to be a significant cybersecurity breach by Chinese intelligence."

"It's clear that the PRC is steadily improving its cyber collection capabilities directed against the US and our allies," Warner said in a statement.

Disclosure of the Chinese hacking comes on the heels of trips to China by US Secretary of State Antony Blinken and Treasury Secretary Janet Yellen and the shooting down by the United States of a Chinese surveillance balloon.

In May, Microsoft said state-sponsored Chinese hackers called "Volt Typhoon" had infiltrated critical US infrastructure networks.

Microsoft highlighted Guam, a US territory in the Pacific Ocean with a vital military outpost, as one of the targets in that attack, but said "malicious" activity had also been detected elsewhere in the United States.

"Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises," the company said at the time.

Microsoft's May statement coincided with an advisory released by US, Australian, Canadian, New Zealand and British authorities warning that the hacking was likely occurring globally.

China denied the allegations, describing the Microsoft report as "extremely unprofessional" and "scissors-and-paste work."

"It is clear that this is a collective disinformation campaign of the Five Eyes coalition countries, initiated by the US for its geopolitical purposes," foreign ministry spokeswoman Mao Ning said, referring to the security alliance of the United States and its Western allies that wrote the report.



TikTok's Fight against Going Dark Gains Support from Key US Lawmakers

The TikTok app logo is seen in this illustration taken January 16, 2025. (Reuters)
The TikTok app logo is seen in this illustration taken January 16, 2025. (Reuters)
TT

TikTok's Fight against Going Dark Gains Support from Key US Lawmakers

The TikTok app logo is seen in this illustration taken January 16, 2025. (Reuters)
The TikTok app logo is seen in this illustration taken January 16, 2025. (Reuters)

TikTok's fortunes took a positive turn on Thursday as a growing number of US officials said its Chinese owner should have more time to sell the app and stop it from being banned ahead of President-elect Donald Trump's return to the White House.

Trump's incoming national security adviser said the new Republican administration will keep the social media app used by 170 million Americans alive in the US if there is a viable deal and top Senate Democrat Chuck Schumer urged President Joe Biden to extend by 90 days a deadline to shut it down on Sunday.

A law passed in April mandates TikTok's owner, ByteDance, divest TikTok's US assets by Sunday to a non-Chinese buyer, or be banned on national security concerns.

"We will put measures in place to keep TikTok from going dark," US Representative Mike Waltz told Fox News, pointing to a provision in the law allowing for a 90-day extension if there is "significant progress" toward a divestiture.

"Essentially that buys President Trump time to keep TikTok going," said Waltz, who was picked by Trump to be his national security adviser.

A White House official said on Thursday the Biden administration does not plan to enforce the ban on Sunday leaving it up to the Trump administration, though it is not clear if the app will remain online absent a formal extension.

"Given the timing of when it goes into effect over a holiday weekend a day before inauguration, it will be up to the next administration to implement," the official said.

The US Supreme Court is currently deciding whether to uphold the law and allow TikTok to be banned on Sunday absent a divestiture, overturn the law or pause it to give the justices more time to make a decision.

The court said it may issue rulings on Friday, but as is customary, did not state which case or cases would be decided.

Trump once supported a ban on the app but changed his stance last year. His shift came amid growing signs of support for his presidential campaign among tech executives and overtures from Republican donor Jeff Yass, who owns a big share of ByteDance.

In a sign of warming ties between Trump and TikTok, the video app's CEO, Shou Zi Chew, will attend the presidential inauguration on Jan. 20 and be seated on the dais among other high-profile invitees, two people familiar with the matter told Reuters.

BIPARTISAN SHIFT

"It's clear that more time is needed to find an American buyer and not disrupt the lives and livelihoods of millions of Americans,” Schumer said on the Senate floor, adding that Democrats tried to pass a bill extending the deadline to find a solution to 270 days.

"I will work with the Trump administration and with both parties to keep TikTok alive while protecting our national security," he added.

The comments by Schumer, who was a strong supporter of the law to force a sale, are a sign of the growing concern among prominent Democrats about the potential impact and political fallout of shutting down TikTok.

The New York Times reported Trump is considering an executive order that would seek to allow TikTok to continue operating despite a pending legal ban until new owners are found. It was not immediately clear if Trump has the authority to do so given the legal divestiture requirements imposed by Congress.

TikTok did not respond to requests for comment.

A spokeswoman for the Trump transition, Karoline Leavitt, said, "President Trump has repeatedly expressed his desire to save TikTok, and there's no better deal maker than Donald Trump."

'TALKS A BIG GAME'

Still, several Republicans and Democrats remain concerned about Chinese ownership of the app, worried the Chinese government could use it as a tool to collect data on US citizens and to spread propaganda to the public.

"Trump talks a big game on China & wanted to ban TikTok - just like many Republicans voted to do," Representative Frank Pallone, the top Democrat on the Energy and Commerce Committee, wrote on the social media platform X.

"But now he's inviting TikTok's CEO to sit beside him at his inauguration even though TikTok is linked to the CCP & is a threat to our national security. What message does this send?"

The prospect of a TikTok ban has already triggered some users to seek alternatives, with Chinese social media app RedNote gaining nearly 3 million US users in one day earlier this week, according to analytics firm Similarweb.

Reuters reported that TikTok plans to shut US operations of its social media app on Sunday barring a last-minute reprieve, according to people familiar with the matter.

Privately held ByteDance is about 60% owned by institutional investors such as BlackRock and General Atlantic, while its founders and employees own 20% each. It has more than 7,000 employees in the United States.