Microsoft Engineer's Account Breach Leads to Chinese Hack of US Officials

1 min read
Source: The Verge
Microsoft Engineer's Account Breach Leads to Chinese Hack of US Officials
Photo: The Verge
TL;DR Summary

Microsoft has revealed that a Chinese hacking group gained access to government emails by obtaining a "Microsoft account consumer key" through a series of internal errors. The key was left in a crash dump that should have been stripped of sensitive information, and it was then transferred to the company's debugging environment. A credential scan and a compromised Microsoft engineer's account further facilitated the breach. Additionally, Microsoft failed to update its systems to authenticate keys properly, allowing threat actors to access enterprise Microsoft accounts. Microsoft has since corrected the issues and is working on strengthening its systems, but it has faced criticism for its security practices.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

79%

496106 words

Want the full story? Read the original article

Read on The Verge