Case 48EB5E · Famous breaches · L5 Expert
Storm-0558 forged token attack
Practise as: Deep dive · Interview
Interview questionExplain how Storm-0558 read US government email in 2023 without phishing a single user.
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- China-linked Storm-0558 obtained a Microsoft consumer (MSA) token-signing key created in 2016 that was never retired
- A validation flaw let Exchange Online accept consumer-key-signed tokens for enterprise mailboxes: forge, then read mail
- About 25 organisations hit, incl. US State and Commerce; MFA, passwords and endpoint controls were irrelevant
- State detected it via MailItemsAccessed audit events in premium logging; Microsoft later added it to standard (E3/G3) audit
- CSRB (2024) called it a preventable cascade of failures; Microsoft could not confirm how the key was stolen
If the interviewer pushes back
- If you are a cloud tenant, what can you realistically detect or control when the provider's signing key is stolen?
- Compare this with Golden SAML in SolarWinds: who owned the compromised key, and who could rotate it?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.