Desk live·
ForensicPost
Nation-state/Espionage/File 23-0711

Storm-0558 Forged Tokens With a Stolen Microsoft Key to Read Government Email

A signing key that should not have worked, for accounts it should not have reached. Microsoft says a China-based actor forged authentication tokens with an acquired consumer signing key and read mail at around 25 organisations — and the intrusion was found by a customer, not by the platform.

Constructed geometry · not a chart of case data
TargetExchange Online tenants
ActorStorm-0558
D. Kennedy12 min readConfidence: high2 sources reviewed

On 11 July 2023 Microsoft published an account of an intrusion it attributes to a China-based actor it tracks as Storm-0558. The actor obtained access to email accounts in Exchange Online and Outlook.com by forging authentication tokens, using an acquired Microsoft account consumer signing key.

Microsoft puts the access as beginning on 15 May 2023 and affecting approximately 25 organisations, including government agencies, together with consumer accounts of individuals likely associated with them.

Nothing Was Exploited

There is no vulnerability in the ordinary sense at the centre of this file. The actor did not defeat a control; it held the material the control checks against. A token signed with a key the platform trusts is not a forgery the platform can detect — it is a valid token.

This is the same structural problem the corpus later files at 25-0530 for Snowflake and at 25-1207 for OAuth grants: authentication systems fail open when the credential is genuine, and no amount of monitoring on the login event distinguishes the attacker from the user.

A Consumer Key Reached Enterprise Mail

The reported detail that carries the most weight is the crossing of a boundary. The key was a consumer signing key; the mail it reached included enterprise accounts. Subsequent research described a token validation issue that allowed the actor to impersonate accounts across a scope the key was never meant to cover.

Later reporting stated that Microsoft had not established how the key was obtained. A root cause that remains unknown is not a small residual: it is the difference between an incident that has been closed and one that has been stopped.

The Customer Found It

Microsoft began its investigation on 16 June 2023 on the basis of customer-reported information. A month of access preceded the report, and the party that noticed was the tenant rather than the platform holding the logs.

The corpus has argued from its earliest files that detection capability and detection responsibility are held by different parties in cloud services, and that the gap between them is where dwell time accumulates.

How we reported this

Built on Microsoft’s own Security Response Center account of the intrusion, retrieved and read by this desk, and on subsequent reporting of the unresolved key acquisition. The attribution to a China-based actor is Microsoft’s and is reported as Microsoft’s assessment, not as a finding of this desk; the file’s analysis does not depend on it. The figure of approximately 25 organisations is Microsoft’s. This desk has not reviewed the US Cyber Safety Review Board report and does not summarise it here. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Microsoft mitigates China-based threat actor Storm-0558 targeting of customer emailMicrosoft Security Response Center
  2. Microsoft still unsure how hackers stole MSA key in 2023 Exchange attackBleepingComputer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary