Chinese hack of US officials due to compromise of Microsoft engineer's account, Microsoft says

Hackers were able to extract a cryptographic key from the engineer’s account and use it to access email accounts that the key should not have given them access to. PHOTO: REUTERS

WASHINGTON - The recently disclosed Chinese hack of senior officials at the US State and Commerce Departments stemmed from the compromise of a Microsoft engineer’s corporate account, Microsoft Corp said in a blog post on Wednesday.

Microsoft said the engineer’s account had been penetrated by a hacking group it dubs Storm-0558, which is alleged to have stolen hundreds of thousands of email messages from top American officials including Commerce Secretary Gina Raimondo, US Ambassador to China Nicholas Burns and Assistant Secretary of State for East Asia Daniel Kritenbrink.

The blog post issued on Wednesday addressed some of the unanswered questions around the incident, which drew fresh scrutiny to Microsoft’s security and led to calls to investigate the company’s practices.

Notably, the post explained how hackers were able to extract a cryptographic key from the engineer’s account and use it to access email accounts that the key should not have given them access to.

Microsoft said it had fixed the flaws that led to the key being accessible from the unidentified engineer’s account and giving the hackers such wide latitude to steal email messages.

Microsoft did not immediately respond to a request for further information about the incident.

The Chinese Embassy in Washington did not immediately return an email.

Beijing has previously described the allegation that it stole email messages from top US officials as “groundless narratives.” REUTERS

Join ST's Telegram channel and get the latest breaking news delivered to you.