WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Joint Cybersecurity Advisory on Enhanced Monitoring to Detect APT Activity Targeting Outlook Online
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Joint Cybersecurity Advisory on Enhanced Monitoring to Detect APT Activity Targeting Outlook Online

Author: April Zupan

Created: Thursday, July 13, 2023 - 17:33

Categories: Cybersecurity, Federal & State Resources

The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory (CSA), Enhanced Monitoring to Detect APT Activity Targeting Outlook Online, to provide guidance to agencies and critical infrastructure organizations on enhancing monitoring in Microsoft Exchange Online environments. 

In June 2023, a federal civilian agency observed unexpected events in its Microsoft 365 audit logs. After reporting the incident to Microsoft, the activity was deemed malicious. Microsoft is tracking this activity as Storm-0558 with a nexus to China that focuses on espionage, data theft, and credential access. The goal of this CSA is to enhance organizational cybersecurity posture and position organizations to detect similar malicious activity via implementing the listed logging recommendations.

According to Microsoft, beginning on May 15, 2023, Storm-0558 gained access to email accounts affecting approximately 25 organizations including at least one U.S. government agency as well as related consumer accounts of individuals likely associated with these organizations. While Microsoft has completed mitigation of this attack across its customer base, members are encouraged to maintain heightened awareness of their Microsoft Outlook Online environment, implement suggested logging to detect similar methods, and report any suspicious, anomalous activity to Microsoft, CISA, and the FBI. Read more at CISA.

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

May 29, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) GAO Report: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector

May 28, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

May 28, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar