{
  "type": "bundle",
  "id": "bundle--ecca42cf-f104-50e9-83b4-927ecbf109cf",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--5c8eaef2-3c46-595a-848c-879eec9f4208",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:3ffa6d56-9460-55ed-90f3-b748ee12c50f",
      "name": "Microsoft",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--1acac05a-d1de-5dd4-8446-05e65fa2ed13",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:80c23364-6b10-51e3-b49a-e8043c3a1f7d",
      "name": "Microsoft Storm-0558 email compromise"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--41bbf3f3-06b3-5004-8ae2-e3625dbddf54",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:2b27362f-0d53-532e-8aee-9e102998087e",
      "name": "Microsoft Storm-0558 email compromise"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--32997e89-befa-5581-891d-179dcf0685e5",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:3e0f390f-0bf4-521f-8434-a4d993c21efd",
      "relationship_type": "affected-organization",
      "source_ref": "incident--1acac05a-d1de-5dd4-8446-05e65fa2ed13",
      "target_ref": "identity--5c8eaef2-3c46-595a-848c-879eec9f4208",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Microsoft",
          "url": "https://www.microsoft.com/en-us/msrc/blog/2023/07/microsoft-mitigates-china-based-threat-actor-storm-0558-targeting-of-customer-email",
          "external_id": "cit:6415bb5b-cb37-5d8c-9ab9-7643f388be16",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:1dd926ff6dd7318d541b212bbba7f77134a28f7210c0268fbdc1571be3181ba4"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--93eeb729-0285-537e-8a28-0d9065cceab7",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:422e3974-fb56-5512-9378-21693ce016c8",
      "confidence": 88,
      "external_references": [
        {
          "source_name": "Microsoft",
          "url": "https://www.microsoft.com/en-us/msrc/blog/2023/07/microsoft-mitigates-china-based-threat-actor-storm-0558-targeting-of-customer-email",
          "external_id": "cit:a2938202-6d89-5d78-92d4-c96b5ac5e8a8",
          "description": "They did this by using forged authentication tokens to access user email using an acquired Microsoft account (MSA) consumer signing key.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:63ad40e223ea35839b4027188052a3dc28da97036bd034155b2487900118df02"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Chinese state-linked actor; forged Azure AD tokens using a stolen Microsoft signing key."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--987de953-a77c-5b92-87e3-cda8cf54af57",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:df1c0b46-9124-568d-b9e7-e6afbc7acf18",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Microsoft",
          "url": "https://www.microsoft.com/en-us/msrc/blog/2023/07/microsoft-mitigates-china-based-threat-actor-storm-0558-targeting-of-customer-email",
          "external_id": "cit:921fe4c8-188b-5698-bb01-58f5fcde8d0d",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:1dd926ff6dd7318d541b212bbba7f77134a28f7210c0268fbdc1571be3181ba4"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the microsoft storm-0558 email compromise involving Microsoft."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--9ec138e6-9717-5236-8e7b-1fad5ca2741e",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:66bf185d-108f-5f9b-a50a-65c9e2ad8220",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Microsoft",
          "url": "https://www.microsoft.com/en-us/msrc/blog/2023/07/microsoft-mitigates-china-based-threat-actor-storm-0558-targeting-of-customer-email",
          "external_id": "cit:183220e4-b12e-55b7-8667-7a1b18372a8c",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:63ad40e223ea35839b4027188052a3dc28da97036bd034155b2487900118df02"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "date",
        "value": "2023-07-11"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--dbb50bcf-dbfb-528e-8b8a-de48ee946ce0",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:0fcf6547-54ca-535f-b361-86bdbc630f61",
      "confidence": 84,
      "external_references": [
        {
          "source_name": "Microsoft",
          "url": "https://www.microsoft.com/en-us/msrc/blog/2023/07/microsoft-mitigates-china-based-threat-actor-storm-0558-targeting-of-customer-email",
          "external_id": "cit:5a906017-5177-5271-82ea-87de4883afbe",
          "description": "Microsoft investigations determined that Storm-0558 gained access to customer email accounts using Outlook Web Access in Exchange Online (OWA) and Outlook.com by forging authentication tokens to access user email.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:63ad40e223ea35839b4027188052a3dc28da97036bd034155b2487900118df02"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Accessed Exchange Online mailboxes of the US State Department, Commerce Secretary, and other officials."
      }
    },
    {
      "type": "x-ally-event",
      "spec_version": "2.1",
      "id": "x-ally-event--8d999dc4-7a3f-5230-882c-2f70678b3038",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "evt:565d3874-6935-5482-8749-d8af14ce206b",
      "name": "Documented public update"
    }
  ]
}
