Chinese state-linked hackers since May have secretly accessed email accounts at around 25 organizations, including at least two U.S. government agencies, Microsoft and U.S. officials said on Wednesday.
The United States detected a breach of federal government accounts "fairly rapidly" and managed to prevent further breaches, White House national security adviser Jake Sullivan said in an interview with ABC's Good Morning America program.
The U.S. State and Commerce Departments were among the affected agencies, and hackers gained access to the email accounts of Secretary of Commerce Gina Raimondo and State Department officials, the Washington Post reported, citing U.S. officials familiar with the matter. The hackers reportedly had access to the government emails for about a month before officials caught on to the breach.
Raimondo is the only known Cabinet-level official to have their account breached in the incident.
Microsoft said in a statement that the hacking group—which it dubbed Storm-0558—forged digital authentication tokens to access webmail accounts running on the firm's Outlook service. The activity began in May, Microsoft said.
"As with any observed nation-state actor activity, Microsoft has contacted all targeted or compromised organizations directly via their tenant admins and provided them with important information to help them investigate and respond," the company added.
Microsoft did not say which organizations or governments had been affected, but added that the hacking group involved primarily targets entities in Western Europe.
China's embassy in London called the accusation "disinformation" and called the U.S. government "the world's biggest hacking empire and global cyber thief." China routinely denies involvement in hacking operations regardless of the available evidence or context.
White House National Security Council spokesman Adam Hodge said an intrusion in Microsoft's cloud security "affected unclassified systems," without elaborating.
"Officials immediately contacted Microsoft to find the source and vulnerability in their cloud service," Hodge added.
The State Department "detected anomalous activity" and "took immediate steps to secure our systems," a department spokesperson said in a statement. The Commerce Department said it took "immediate action" after Microsoft notified it of a compromise.
Private sector cybersecurity experts have said newly discovered hacking activity shows how Chinese groups are improving their cyber capabilities.
"Chinese cyber espionage has come a long way from the smash-and-grab tactics many of us are familiar with," said John Hultquist, chief analyst for U.S. cybersecurity firm Mandiant.
(Editing by Alistair Bell and Diane Craft)
Published under: China