When you purchase through links on our site, we may earn an affiliate commission.Heres how it works.
The Board called for an overhaul of Microsoft’s security culture.
“The Board concludes that this intrusion should never have happened.

Hackers were able to access Outlook accounts of U.S. government employees.
Storm-0558 was able to succeed because of a cascade of security failures at Microsoft,” said the report.
Several steps could have been taken by Microsoft to prevent the incident, including rotating security keys.
Microsoft had paused the manual rotation of keys, which allowed old keys to continue to work.

Another key-related issue was that Microsoft allowed consumer keys to authenticate to access enterprise customer data.
That panel was commissioned by U.S. President Biden.
The hacker group known as Storm-0558 was able to gain access to 22 organizations.

Microsoft still isn’t certain how the key was stolen, according to the U.S. Cyber Safety Review Board.
Microsoft has responded to security threats and the U.S. Cyber Safety Review Board.











