

Earlier this summer, Microsoft disclosed that a threat actor — Storm-0558 — had obtained a Microsoft private encryption key that allowed attackers to generate tokens enabling access to a wide variety of applications, including customers’ Exchange Online and Outlook[.]com accounts.Â
The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted a strategic partner’s traffic data as well as public reporting on the incident to offer further insight into these claims.