WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Joint Cybersecurity Advisory on Enhanced Monitoring to Detect APT Activity Targeting Outlook Online
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Joint Cybersecurity Advisory on Enhanced Monitoring to Detect APT Activity Targeting Outlook Online

Author: April Zupan

Created: Thursday, July 13, 2023 - 17:33

Categories: Cybersecurity, Federal & State Resources

The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory (CSA), Enhanced Monitoring to Detect APT Activity Targeting Outlook Online, to provide guidance to agencies and critical infrastructure organizations on enhancing monitoring in Microsoft Exchange Online environments. 

In June 2023, a federal civilian agency observed unexpected events in its Microsoft 365 audit logs. After reporting the incident to Microsoft, the activity was deemed malicious. Microsoft is tracking this activity as Storm-0558 with a nexus to China that focuses on espionage, data theft, and credential access. The goal of this CSA is to enhance organizational cybersecurity posture and position organizations to detect similar malicious activity via implementing the listed logging recommendations.

According to Microsoft, beginning on May 15, 2023, Storm-0558 gained access to email accounts affecting approximately 25 organizations including at least one U.S. government agency as well as related consumer accounts of individuals likely associated with these organizations. While Microsoft has completed mitigation of this attack across its customer base, members are encouraged to maintain heightened awareness of their Microsoft Outlook Online environment, implement suggested logging to detect similar methods, and report any suspicious, anomalous activity to Microsoft, CISA, and the FBI. Read more at CISA.

Related Resources

(TLP:CLEAR) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026 – Executive Summary

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar