HomeSecurityChinese hackers stole emails from the US State Department after...

Chinese hackers stole emails from US State Department after Microsoft breach

Chinese hackers who breached Microsoft's (MSFT.O) email platform this year managed to steal tens of thousands of emails from U.S. State Department accounts , a Senate official told Reuters on Wednesday.

See also: Hacker demands $400,000 from Kuwait's Finance Ministry

Chinese hackers

The employee said State Department officials notified lawmakers about the theft of 60,000 emails from 10 of his accounts. Nine of the victims worked in East Asia and the Pacific, while another worked in Europe, according to data provided via email by the employee, who remained anonymous. The employee is employed by Sen. Eric Schmitt.

U.S. officials and Microsoft said in July that since May, Chinese state hackers had accessed about 25 organizations through email accounts, including the U.S. Departments of Commerce and State. The scope of the breach remains unclear.

The US has accused China of being responsible for the breach, which has soured relations between the two countries. China denies the accusations.

The State Department accounts that were compromised were primarily focused on Indo-Pacific diplomacy efforts. The hackers also managed to obtain a list of all the department's emails, according to the information on Wednesday.

See also: Hackers actively exploit an Openfire flaw

Microsoft

The malware attack has once again brought to the fore the important role Microsoft plays in providing IT services to the U.S. government. The State Department has begun moving into “hybrid” environments with multiple vendors and enhanced use of multi-factor authentication as part of measures to protect its systems.

Chinese hackers managed to compromise a Microsoft engineer's device, allowing them to compromise State Department email accounts, according to an update. Microsoft recently announced that an attack on top officials at the U.S. Department of State and Commerce stemmed from a breach of a Microsoft engineer's corporate account.

"We need to harden our defenses against these types of cyberattacks and intrusions," Schmitt said in a statement shared by staff in an email to Reuters after the briefing.

"We need to take a hard look at the federal government's reliance on a single supplier as a potential weak point," he said.

See also: PhilHealth hackers demand $300,000 ransom

A Microsoft spokesman did not immediately respond to a request for comment on the Senate briefing. The company, which has faced criticism for its security practices since the breaches, said a hacking group called Storm-0558 had infiltrated webmail accounts running on the Outlook . The State Department did not immediately respond to a message seeking comment on Wednesday.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS