Giveaway: Win an MSI MAG Z890 TOMAHAWK WIFI II and MPG CORELIQUID P13 360

Microsoft vulnerability causes government emails to be hacked, officials launch investigation

The Cyber Security Review Board has launched an investigation into a Microsoft vulnerability that resulted in US government emails being hacked.

Microsoft vulnerability causes government emails to be hacked, officials launch investigation
Comment IconFacebook IconX IconReddit Icon
Tech and Science Editor
Published
Updated
1 minute & 15 seconds read time

A Microsoft cloud breach that resulted in China state-backed hackers breaking into U.S. government emails has led the Cyber Security Review Board to launch an investigation.

Microsoft vulnerability causes government emails to be hacked, officials launch investigation 48

The Cyber Security Review Board (CSRB) announced on Friday that its investigation will look into cloud-based identity and authentication infrastructure, which will lead to a wider review of all potential and current problems.

This investigation was launched following U.S. government official email accounts being infiltrated by China state-backed hackers that gained access to U.S. Commerce Secretary Gina Raimondo's inbox, several other officials at the U.S. State Department, and officials at a few different government agencies.

Information regarding this story is slowly coming out, but what we do know is that the vulnerability can be traced back to hackers stealing a sensitive signing key that enabled unauthorized access to both enterprise and government email addresses hosted by Microsoft. The key, combined with the security flaw within Microsoft's infrastructure, which has since been fixed, enabled the hackers to forge authentication tokens that gained them access to the email account inboxes.

The security breach happened in mid-May, but officials only detected the vulnerability in June. Why did it take a month? State Department officials used a higher-tier paid account, which enables users to check logs, which Microsoft keeps on file. Other government departments don't use this higher-tier paid account, and if they were given access, the vulnerability would have likely been spotted much sooner.

In response to this vulnerability, Microsoft has said it will make logs available for all customers beginning sometime in September.

Photo of the Diablo IV - PlayStation 5
Best Deals: Diablo IV - PlayStation 5
Today7 days ago30 days ago
$22.99 USD$32.90 USD
$29.99 USD$29.99 USD
$58.40 CAD$57.58 CAD
£41.73-
$22.99 USD$32.90 USD
Check PriceCheck Price
* Prices last scanned 4/16/2026 at 8:13 am CDT - prices may be inaccurate. As an Amazon Associate, we earn from qualifying purchases. We earn affiliate commission from any Newegg or PCCG sales.
News Sources:techcrunch.com and dhs.gov

Tech and Science Editor

Email IconX IconLinkedIn Icon

Jak joined TweakTown in 2017 and has since reviewed 100s of new tech products and kept us informed daily on the latest science, space, and artificial intelligence news. Jak's love for science, space, and technology, and, more specifically, PC gaming, began at 10 years old. It was the day his dad showed him how to play Age of Empires on an old Compaq PC. Ever since that day, Jak fell in love with games and the progression of the technology industry in all its forms.

Follow TweakTown on Google News
Newsletter Subscription