Years later, Microsoft admits that Chinese authorities hacked Hotmail accounts belonging to Tibetan and Uyghur minorities, but at the time it did not warn users, leaving the victims in the dark.

Former Microsoft employees revealed this information, and Microsoft said its policies would change to notify users in the event of a hack and that the company was never sure of the source of the Hotmail attacks.
The company declined to comment on whether this problem had any impact on its decision to change its policy.
The problem dates back to 2011 when Trend Micro announced that it found emails originating from the Republic of China that contained a tiny computer program but were not linked to Chinese authorities at the time.
To be able to hack Hotmail users, Chinese authorities exploited an undiagnosed flaw on Microsoft's site to secretly forward copies of all of the recipient's incoming mail to an account belonging to the attacker.
When the flaw was made known by Trend Micro it had already been fixed by Microsoft.
At the same time, Microsoft launched its own investigation, concluding that some Hotmail accounts had been hacked since July 2009. These accounts included those of Tibetan and Uyghur leaders from various countries, as well as Japanese and African diplomats, human rights lawyers and others who held sensitive positions within China, according to former Microsoft employees.
Some of the attacks came from AS4808, a Chinese network linked to espionage campaigns.
Microsoft does not deny that the majority of attacks originate from China but added that some also originate from elsewhere without providing details.
As for the Chinese government, the Foreign Ministry spokesman stated that China is a proponent of cybersecurity and strongly opposes any forms of attacks on it, adding that any violator will be punished according to the law.
