Back
Outfaze Security Team

Outfaze Security Team

Storm-0558: Cloud Email and Token Security Lessons

Storm-0558: Cloud Email and Token Security Lessons

Microsoft disclosed in July 2023 that Storm-0558 used forged authentication tokens to access email data from approximately 25 organizations and a small number of related consumer accounts. The company invalidated the acquired signing key and blocked the affected token path.

The incident demonstrated that cloud identity security depends on provider controls and customer visibility. When a platform-level token issue occurs, customers still need enough audit evidence to understand which identities and data were affected.

Forged tokens challenged normal sign-in assumptions

The attacker did not need each user's password. A forged token could appear to downstream services as valid, shifting detection toward token properties, mailbox behavior, API activity, and provider-supplied indicators.

CISA subsequently published enhanced monitoring guidance for Outlook Online. Provider notification and rapid information sharing were essential because customers could not independently observe every part of the platform.

Prepare for shared-responsibility investigations

Enable the audit and retention available for high-value cloud services, define provider escalation contacts, and know which logs can be exported during an incident. Protect privileged accounts and monitor mailbox access, forwarding, consent, and bulk collection.

If notified of platform compromise, preserve evidence, identify affected accounts and data, revoke sessions, rotate exposed secrets, and review related personal accounts or applications where the facts justify it.

  • Document which evidence is customer-visible and provider-controlled.
  • Retain cloud audit records long enough for delayed discovery.
  • Monitor token use and data access together.
  • Keep provider communications in incident playbooks.

Put the lesson into practice

  1. Review cloud audit licensing, configuration, and retention.
  2. Define a provider-escalation and evidence-request path.
  3. Alert on anomalous mailbox and Graph activity.
  4. Create a forged-token response checklist.
  5. Exercise a cloud incident with incomplete provider information.

Related Outfaze guidance

Authoritative sources