Microsoft Corp (NASDAQ:MSFT) has been slammed by the US government over security errors which allowed Chinese-backed hackers access to senior officials’ email accounts last year.
“Microsoft's security culture was inadequate and requires an overhaul,” a Biden administration-appointed review board found on Tuesday.
The hack “was preventable and should never have occurred,” it added.
Chinese operatives had gained access to hundreds of Microsoft email accounts from 22 different organisations, including those of US Chinese Ambassador Nicholas Burns and Commerce Secretary Gina Raimondo.
They had downloaded some 60,000 emails from America’s State Department alone throughout the attack, which lasted at least six weeks from around May time.
A “rapid cultural change” is needed at Microsoft, said the report while calling on the software giant to spell out measures to bolster cybersecurity.
In particular, a sensitive cryptographic key was found to have not been properly protected, meaning hackers could remotely sign into accounts with forged credentials.
China has since denied involvement in the incident, which the Institute for Critical Infrastructure Technology argued should prompt the government to rethink its relationship with Microsoft.
“The US government has reached a decision point with its IT service providers: more of the same or better cybersecurity,” the think tank’s chief executive, Cory Simpson, said.
“We appreciate the work [...] to investigate the impact of well-resourced nation-state threat actors who operate continuously and without meaningful deterrence,” a Microsoft spokesperson responded.
“Our security engineers continue to harden all our systems against attack and implement even more robust sensors and logs to help us detect and repel [...] cyber-armies.”