Without publicly attributing the attacks, the U.S. Cybersecurity and Infrastructure Security Agency said the hacks started in mid-May and hit fewer than 10 government accounts.
Microsoft said hackers were able to use the key to forge authentication tokens due to a “validation error in Microsoft code.” Beijing denied involvement.