---
title: "Microsoft Email Attacks: An Inside Look at the Outlook Breach | DuoCircle"
description: "Duocircle · Microsoft Email Attacks An Inside Look At The Out This post will take you through the latest Microsoft Outlook Email Security Breach."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/email-security/microsoft-email-attacks-an-inside-look-at-the-outlook-breach/"
---

Quick Answer

The 2023 Microsoft Outlook breach traces to an April 2021 crash that wrote a consumer signing key into a debug crash dump, which then escaped Microsoft's secure environment due to a race condition. China-based threat actor Storm-0558 compromised a Microsoft engineer's corporate account that had access to the debug environment and exfiltrated the key. A separate 2018 design choice unified consumer and enterprise key metadata at a single endpoint, and a key-scope validation gap in the libraries let the consumer key validate enterprise tokens. Storm-0558 used the forged tokens to access email accounts including Commerce Secretary Gina Raimondo, Assistant Secretary of State Daniel Kritenbrink, and US Ambassador to China Nicholas Burns. Microsoft fixed the race condition, hardened crash-dump handling, improved credential scanning, automated key-scope validation, and the federal Cyber Safety Review Board opened an investigation into cloud identity and authentication infrastructure.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Femail-security%2Fmicrosoft-email-attacks-an-inside-look-at-the-outlook-breach%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Microsoft%20Email%20Attacks%3A%20An%20Inside%20Look%20at%20the%20Outlook%20Breach&url=undefined%2Fblog%2Femail-security%2Fmicrosoft-email-attacks-an-inside-look-at-the-outlook-breach%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Femail-security%2Fmicrosoft-email-attacks-an-inside-look-at-the-outlook-breach%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Femail-security%2Fmicrosoft-email-attacks-an-inside-look-at-the-outlook-breach%2F&title=Microsoft%20Email%20Attacks%3A%20An%20Inside%20Look%20at%20the%20Outlook%20Breach "Share on Reddit") [ ](mailto:?subject=Microsoft%20Email%20Attacks%3A%20An%20Inside%20Look%20at%20the%20Outlook%20Breach&body=Check out this article: undefined%2Fblog%2Femail-security%2Fmicrosoft-email-attacks-an-inside-look-at-the-outlook-breach%2F "Share via Email") 

![microsoft email attacks](https://media.mailhop.org/duocircle/images/2023/09/spf-record-5697.jpg) 

_This post will take you through the latest **Microsoft Outlook**_ _Email Security_ _Breach, covering information on how it occurred, the threat actors behind it, and what Microsoft is doing to remedy the situation._

In an unprecedented cybersecurity incident that shook the [cybersecurity](/) and digital worlds, a Chinese threat actor has breached Microsoft Outlook email accounts. Here is a closer examination of the incident details, exploring the **tactics employed** by the threat actors and the **extensive measures** Microsoft took to address the situation.

## How Did the Microsoft Outlook Breach Originate?

In April 2021, an unexpected event occurred, a computer crash. The crash inadvertently exposed a vital component known as the “consumer signing key.” This key, which should have remained [securely isolated](https://www.onmsft.com/news/microsoft-reports-on-outlook-email-hacking-investigation-heres-what-went-wrong/), unexpectedly entered the crash dump. It initiated a series of events that allowed the Chinese malicious actor known as **Storm-0558** to infiltrate Microsoft’s email system.

## The Significance of the Consumer Signing Key

_The consumer signing key plays a critical role in Microsoft’s security framework._ Its appearance in the crash dump resulted from a software error called a “**race condition**,” which can lead to unintended outcomes. The key material in the crash dump in the abovementioned **incident went unnoticed** within Microsoft’s corporate network’s debugging environment.

## Intrusion by Storm-0558

With the consumer signing key now within reach, the [Chinese threat actor](https://www.moneycontrol.com/news/business/china-based-threat-actors-target-uidai-aiims-icmr-shows-cybersecurity-advisory-10769631.html) Storm-0558 seized the opportunity to compromise email accounts and got successful with a **Microsoft engineer’s corporate account**. The engineer had access to the debugging environment containing the crash dump, which unfortunately still held the key. While specific logs couldn’t confirm the key’s extraction, it remains the most plausible explanation for **Storm-0558’s key acquisition**.

## The Oversight in Key Scope Validation

To streamline its systems, Microsoft introduced a common key metadata publishing endpoint in September 2018 to serve consumer and enterprise accounts. However, during updates to libraries and documentation related to key scope validation, a critical oversight occurred, enabling malicious actors to **utilize a regular key** to [access business emails](https://therecord.media/w3ll-phishing-toolkit-bec-microsoft-365-accounts), an unintended consequence of the system’s design.

[![Causes of Security Breaches and Data Breaches](https://media.mailhop.org/duocircle/images/2023/09/email-migration-service.jpg)](https://media.mailhop.org/duocircle/images/2023/09/email-migration-service.jpg)

## Microsoft’s Response and Remediation: What did Microsoft do?

In the aftermath of the Microsoft email attacks, the organization undertook a comprehensive effort to rectify the situation. Multiple actions were taken, with a **strong emphasis** on bolstering [email security](/content/email-security-services) measures, as listed below:

1. **Addressing the Root Cause**: The primary cause of the breach, the **race condition issue**, was identified and resolved to prevent future occurrences.
2. **Enhanced Prevention, Detection, and Response**: Microsoft fortified its mechanisms for handling key material in crash dumps to prevent [sensitive data exposure](https://www.infosecurity-magazine.com/news/sensitive-data-uk-army-potentially/) in similar scenarios.
3. **Improvements in Credential Scanning**: Measures were implemented to enhance **credential scanning processes**, reducing the likelihood of unauthorized access.
4. **Automated Key Scope Validation**: Microsoft also introduced improved libraries to automate key scope validation in authentication libraries, **minimizing the risk of key misuse**.

## The Impact of the Outlook Breach

The severity of this breach becomes evident when one considers its targets. Storm-0558 **gained access to the email accounts** of several prominent individuals, including Commerce Secretary Gina Raimondo, the Assistant Secretary of State, East Asia Daniel Kritenbrink, and the U.S. Ambassador to China Nicholas Burns, raising concerns about potential espionage and [compromised communications](https://www.theguardian.com/us-news/2023/jul/29/pentagon-us-air-force-critical-compromise).

## Broader Implications and National Security

The Microsoft Outlook email hacking incident is a stark reminder of the escalating cybersecurity threats governments and organizations face worldwide. The event underscores the **significance of robust email security measures**, especially in [cloud-based services](/email-hosting/enterprise-information-archiving-with-cloud-based-services/), where [spam filtering](/email/spam-filtering) has become increasingly integral to people’s daily lives, ensuring their online communications remain safe and protected.

## A Focus on Cloud Computing Safety

The federal Cyber Safety Review Board has acted in response to the breach. It will concentrate its efforts on examining malicious targeting of cloud computing environments, including the **intrusion** into Microsoft [Exchange Online Protection](/content/exchange-spam-filters/exchange-online-protection) by China-based threat actors. _The broader review will encompass issues related to **cloud-based identity** and authentication infrastructure._

## The Threat Actor Behind the Outlook Breach, Storm-0558

[Storm-0558](https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/) is a China-based threat actor that has garnered attention due to its espionage objectives. Operating during typical Chinese working hours, they have historically targeted U.S. and European diplomatic, economic, and legislative entities, with a **particular focus** on individuals associated with Taiwan and Uyghur geopolitical interests. 

Notably, Storm-0558 has displayed an affinity for **infiltrating media** companies, think tanks, and telecommunications providers, all in pursuit of [unauthorized access to email accounts](https://www.bleepingcomputer.com/news/security/microsoft-chinese-hackers-breached-us-govt-exchange-email-accounts/).

## The Unprecedented Email Access: Storm-0558’s Specialty

Storm-0558 employs a **variety of tactics** to achieve its objectives. Historically, they have obtained initial access through phishing campaigns or exploiting vulnerabilities in public-facing applications, often resulting in [web shell deployment](https://thehackernews.com/2023/09/outlook-breach-microsoft-reveals-how.html?m=1). Among the arsenal of malware used by Storm-0558, one prevalent family is **Cigril**, launched via DLL (Dynamic-Link Library) search order hijacking.

Once inside a compromised system, Storm-0558 meticulously extracts credentials from various sources, including the **LSASS process** memory and [SAM (Security Account Manager)](https://www.windows-active-directory.com/windows-security-account-manager.html) registry hive. These credentials are then used to sign into the targeted user’s cloud email account.

The following are some of the **tools and techniques** used by Storm-0558 to infiltrate restricted user accounts:

### 1\. Authentication Tokens Forgery

One of the most intriguing aspects of the Storm-0558 campaign is its ability to [forge authentication tokens](https://www.bleepingcomputer.com/news/security/nsa-warns-of-hackers-forging-cloud-authentication-information/). _These tokens play a critical role in validating the identity of entities seeking access to resources, such as email accounts._ These tokens are typically issued by identity providers like Azure AD and signed using a private key. By correctly validating the **token’s signature** with the public key, relying parties trust the authenticity of the request.

Storm-0558, however, acquired an inactive Microsoft account (MSA) Consumer signing key, which was used to **craft falsified tokens** for Azure AD Enterprise and MSA Consumer to access [OWA (Outlook Web Access)](https://support.intermedia.com/app/articles/detail/a%5Fid/25113/~/what-is-outlook-web-access-%28owa%29%3F-how-does-it-work%3F) and Outlook.com. A **validation error in Microsoft’s code** made it possible for them. While Microsoft has rectified this issue, it’s a compelling example of the threat actor’s technical prowess.

### 2\. PowerShell and Python Scripts

Storm-0558 relies on a set of PowerShell and Python scripts to make **REST API (Application Programming Interface)** calls to the OWA Exchange Store service. These scripts enable actions such as downloading emails and attachments, locating conversations, and retrieving email folder information. The [threat actor](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) can route web requests through **Tor proxies** or hardcoded [SOCKS5 proxy servers](https://netnut.io/socks5-proxy/), making detection more challenging.

The scripts can also contain sensitive information, including **bearer access tokens** and email data, which Storm-0558 leverages for OWA API interactions. Furthermore, they can refresh access tokens for subsequent commands.

### 3\. Dedicated Proxy Infrastructure

Storm-0558’s campaign incorporates dedicated infrastructure, leveraging SoftEther proxy software, presenting a unique challenge by complicating detection and attribution. To combat this scenario, [Microsoft Threat Intelligence](https://www.cpomagazine.com/cyber-security/microsoft-threat-intelligence-chinese-hackers-are-living-off-the-land-inside-us-critical-infrastructure/) had to develop **profiling methods** to track the infrastructure.

As part of the dedicated infrastructure, the threat actor introduced a **web panel for authentication**, further enhancing their capabilities. _Microsoft deployed analytics to track it as a proactive response, leading to its identification._

## What Next for Microsoft Outlook and the Public?

Microsoft’s response to this campaign has been comprehensive. It **stopped the abuse of token renewal**, blocked the [usage of tokens](https://www.securityweek.com/microsoft-cloud-hack-exposed-more-than-exchange-outlook-emails/) signed with the acquired MSA key, and revoked all previously active keys. These actions were coupled with increased system isolation, refined monitoring, and transitioning to a hardened key store to provide better [email protection](/email-services/what-is-post-delivery-email-protection-and-why-it-is-crucial/).

Storm-0558’s activities have been effectively disrupted, and Microsoft continues to monitor the situation, bolstering defenses. As one reflects on the email hacking incident, it becomes clear that the cybersecurity landscape is **continually evolving**. Both public and private sectors must recognize the criticality of cloud infrastructure and collaborate effectively on email security measures.

## How to Stay Safe While Using Microsoft Outlook

Ensuring your **Microsoft** **Outlook security** and protecting sensitive information is paramount, especially after the [Outlook breach](https://www.abc.net.au/news/2021-03-08/microsoft-outlook-hack-white-house-patching-not-enough-backdoor/13226262). Here are some steps and best practices to follow when using Microsoft Outlook:

### 1\. Be Cautious of Phishing Attempts

Phishing emails often [impersonate legitimate entities](https://www.bleepingcomputer.com/news/security/nsa-and-fbi-kimsuky-hackers-pose-as-journalists-to-steal-intel/) and attempt to trick you into revealing sensitive information. Be wary of **unsolicited emails**, especially those requesting personal or financial details. Verify the sender’s authenticity before clicking on links or downloading attachments.

### 2\. Check Email Sender Information

Always double-check the sender’s email address. [Malicious actors](/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/) can create convincing email addresses that **appear genuine** at first glance. Look for subtle misspellings or inconsistencies.

[![Check Email Sender Information](https://media.mailhop.org/duocircle/images/2023/09/spf-record-check-7960.jpg)](https://media.mailhop.org/duocircle/images/2023/09/spf-record-check-7960.jpg)

### 3\. Avoid Downloading Suspicious Attachments

Exercise caution when opening email attachments, mainly if the sender is unknown or the message seems unusual. **Malware can be hidden** in seemingly harmless files.

### 4\. Use Secure Networks

Avoid accessing your email from [public Wi-Fi networks](https://cybersecuritynews.com/mitm-attack-on-wi-fi-networks/), which can be less secure. Instead, use trusted and secure connections, especially when dealing with **sensitive emails** or attachments.

### 5\. Educate Yourself and Your Team

Ensure that the employees of your organization are educated about Outlook security and general [email security practices](/email-security/email-security-best-practices-and-standards-organizations-must-implement/). Offer [phishing awareness training](/phishing-awareness-training) to educate individuals on identifying phishing attempts and emphasize the significance of maintaining **strong and unique passwords**. This specialized training will help enhance their ability to detect phishing attacks and reinforce the importance of password security.

## Final Words

The breach orchestrated by Storm-0558 serves as a wake-up call for anyone concerned with email protection and cybersecurity in general. It highlights the importance of vigilance, **continual improvements** in [cybersecurity practices](/phishing-protection/cybersecurity-basics-that-every-first-time-business-owner-should-know/), and international cooperation to counter cyber threats. The lessons learned from this incident will undoubtedly shape the future of email security, influencing policies and regulations in the digital age.

## Topics

email securityNewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Fmicrosoft-email-attacks-an-inside-look-at-the-outlook-breach%2F) [ ](https://twitter.com/intent/tweet?text=Microsoft%20Email%20Attacks%3A%20An%20Inside%20Look%20at%20the%20Outlook%20Breach&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Fmicrosoft-email-attacks-an-inside-look-at-the-outlook-breach%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Fmicrosoft-email-attacks-an-inside-look-at-the-outlook-breach%2F) Copy 

Related Articles

- [ ![Spam Filters](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-9932.jpg)  10 Crucial Tips that Will Help You Avoid Spam Filters and Send Better Emails Email Security ](/blog/email-security/10-crucial-tips-that-will-help-you-avoid-spam-filters-and-send-better-emails/)
- [ ![Data Privacy And Protection](https://media.mailhop.org/duocircle/images/2022/07/spf-permerror-7082.jpg)  Data Privacy And Protection: 11 Ways To Protect User Data Email Security ](/blog/email-security/data-privacy-and-protection-11-ways-to-protect-user-data/)
- [ ![Emerging Email Security Threats](https://media.mailhop.org/duocircle/images/2023/03/spf-validator-7394.jpg)  Emerging Email Security Threats in 2023 Email Security ](/blog/email-security/emerging-email-security-threats-in-2023/)
- [ ![Google Workspace Email Security](https://media.mailhop.org/duocircle/images/2023/08/spf-record-checker-6371.jpg)  Google Workspace: Advanced Email Security Solutions Email Security ](/blog/email-security/google-workspace-advanced-email-security-solutions/)

## Related Articles

[  Email Security 7m  10 Crucial Tips that Will Help You Avoid Spam Filters and Send Better Emails  Feb 14, 2023 ](/blog/email-security/10-crucial-tips-that-will-help-you-avoid-spam-filters-and-send-better-emails/)[  Email Security 18m  Data Privacy And Protection: 11 Ways To Protect User Data  Jul 28, 2022 ](/blog/email-security/data-privacy-and-protection-11-ways-to-protect-user-data/)[  Email Security 7m  Emerging Email Security Threats in 2023  Mar 9, 2023 ](/blog/email-security/emerging-email-security-threats-in-2023/)[  Email Security 4m  Google Workspace: Advanced Email Security Solutions  Aug 9, 2023 ](/blog/email-security/google-workspace-advanced-email-security-solutions/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Microsoft Email Attacks: An Inside Look at the Outlook Breach","description":"Duocircle · Microsoft Email Attacks An Inside Look At The Out This post will take you through the latest Microsoft Outlook Email Security Breach.","url":"https://www.duocircle.com/blog/email-security/microsoft-email-attacks-an-inside-look-at-the-outlook-breach/","datePublished":"2023-09-14T16:31:38.000Z","dateModified":"2025-05-19T14:03:01.000Z","dateCreated":"2023-09-14T16:31:38.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/microsoft-email-attacks-an-inside-look-at-the-outlook-breach/"},"articleSection":"email-security","keywords":"email security, News, Security, Updates","wordCount":1555,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/09/spf-record-5697.jpg","caption":"microsoft email attacks","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Email Security"},{"@type":"ListItem","position":3,"name":"Microsoft Email Attacks: An Inside Look at the Outlook Breach","item":"https://www.duocircle.com/blog/email-security/microsoft-email-attacks-an-inside-look-at-the-outlook-breach/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Email Security","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Microsoft Email Attacks: An Inside Look at the Outlook Breach","item":"https://www.duocircle.com/blog/email-security/microsoft-email-attacks-an-inside-look-at-the-outlook-breach/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Microsoft Email Attacks: An Inside Look at the Outlook Breach","description":"Duocircle · Microsoft Email Attacks An Inside Look At The Out This post will take you through the latest Microsoft Outlook Email Security Breach.","url":"https://www.duocircle.com/blog/email-security/microsoft-email-attacks-an-inside-look-at-the-outlook-breach/","datePublished":"2023-09-14T16:31:38.000Z","dateModified":"2025-05-19T14:03:01.000Z","dateCreated":"2023-09-14T16:31:38.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/microsoft-email-attacks-an-inside-look-at-the-outlook-breach/"},"articleSection":"email-security","keywords":"email security, News, Security, Updates","wordCount":1555,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/09/spf-record-5697.jpg","caption":"microsoft email attacks","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
