Microsoft Exchange Online · 2023
A stolen signing key opened government mailboxes
A China-linked actor, tracked as Storm-0558, used a stolen Microsoft consumer signing key to forge authentication tokens and read Exchange Online mailboxes belonging to 22 organisations and more than 500 individuals, including officials at the US State and Commerce Departments. Roughly 60,000 State Department emails were taken. The Cyber Safety Review Board concluded in 2024 that the intrusion was preventable and traced it to a cascade of avoidable failures at Microsoft.
What Steno changes
No tenant setting would have stopped this. The affected departments did nothing wrong — the compromise was inside the provider holding their mail. Steno removes that dependency for meeting content: there is no provider account, no key and no server holding your transcripts to be compromised.