Open cardosec

Case 48EB5E · Famous breaches · L5 Expert

Storm-0558 forged token attack

Practise as: Deep dive · Interview

Interview questionExplain how Storm-0558 read US government email in 2023 without phishing a single user.

  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. China-linked Storm-0558 obtained a Microsoft consumer (MSA) token-signing key created in 2016 that was never retired
  2. A validation flaw let Exchange Online accept consumer-key-signed tokens for enterprise mailboxes: forge, then read mail
  3. About 25 organisations hit, incl. US State and Commerce; MFA, passwords and endpoint controls were irrelevant
  4. State detected it via MailItemsAccessed audit events in premium logging; Microsoft later added it to standard (E3/G3) audit
  5. CSRB (2024) called it a preventable cascade of failures; Microsoft could not confirm how the key was stolen

If the interviewer pushes back

  • If you are a cloud tenant, what can you realistically detect or control when the provider's signing key is stolen?
  • Compare this with Golden SAML in SolarWinds: who owned the compromised key, and who could rotate it?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.