ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

Biden review board blames Microsoft for China hack that targeted US officials: 'Cascade of avoidable errors'

A review board mandated by President Biden blamed Microsoft for a 2023 attack by a group affiliated with the People's Republic of China against US officials.

The Cyber Safety Review Board (CSRB) has released a damning report on Tuesday that claimed serious errors by Microsoft allowed a Chinese hack that targeted the emails of top U.S. government officials.

The report, released by the U.S. Department of Homeland Security, came after an independent review of the Summer 2023 Microsoft Exchange Online intrusion.

This is the third review the CSRB has completed since President Biden mandated the Board through an executive order in February 2022.

The CSRB determined that Microsoft could have prevented Storm-0558's hack, a nefarious group affiliated with the People's Republic of China. They pointed to several operational and strategic decisions that underscored a corporate culture that failed to prioritize security and risk management.

MICROSOFT WARNS RUSSIAN HACKERS ARE USING EXECS' STOLEN EMAILS TO BROADEN CYBERATTACKS

The State Department detected the breach last June. It was discovered because the agency was paying for a higher-tier service that showed audit logs, which revealed that the hackers had obtained around 60,000 emails. According to The Washington Post, Microsoft says it will now provide agencies with that service free of charge.

The Board wrote that the company's "security culture was inadequate and requires an overhaul" and the attack was caused by a "cascade of avoidable errors."

The report also suggested that Microsoft was not fully transparent about what they knew regarding the origin of the attack.

It was determined that Microsoft failed to correct inaccurate statements for months that residual data from a widespread system crash had caused the breach. Microsoft, according to the Board, continues to say they are unsure if this event led to the attack.

"Microsoft's decision not to correct in a timely manner its inaccurate public statements about this incident, including a corporate statement that Microsoft believed it had determined the likely root cause of the intrusion when in fact, it still has not," the report noted.

Microsoft has admitted they "have not found a crash dump containing the impacted key material."

MICROSOFT SAYS RUSSIAN STATE-SPONSORED HACKERS BROKE INTO SOME COMPANY EMAILS

The company updated its public statements on March 12 when it was determined the review was reaching its conclusion.

Microsoft was asked to develop and publicly share a plan, including a timeline, for reforms across its company and products.

"We appreciate Microsoft's full cooperation in the course of the Board's seven-month, independent review. We also appreciate the input received from 19 additional companies, government agencies, and individual experts," DHS Under Secretary of Policy and CSRB Chair Robert Silvers said in a statement announcing the review's completion.

GET FOX BUSINESS ON THE GO BY CLICKING HERE

Microsoft has been the victim of several breaches in recent years.

In 2021, hackers affiliated with China accessed Microsoft Exchange email servers, compromising 30,000 public and private organizations in the U.S. alone.

The SVR, a Russian spy entity, attacked Microsoft's corporate email systems in January.

The infamous 2020 SolarWinds attack by Russian hackers was also orchestrated in part by exploiting a program Microsoft provides to companies. The program allows companies to authenticate the identity of employees on their email systems.

Microsoft did not immediately return Fox News Digital's request for comment. 

Data & News supplied by www.cloudquote.io
Stock quotes supplied by Barchart
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the following
Privacy Policy and Terms and Conditions.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.