Microsoft Halts China Teams Support for DoD
Beyond Classified: Sensitive Government Data Exposed by China-Linked Cloud Support
Table of Contents
Microsoft’s Global Workforce Extended to Justice, Treasury, and Commerce Amidst Security Concerns
Microsoft’s recent decision to cease using China-based engineering teams for its Defense Department cloud systems, a move prompted by ProPublica‘s inquiry into potential hacking and espionage risks, has revealed a broader vulnerability within the U.S. government. ProPublica’s findings indicate that Microsoft has for years leveraged its international workforce, including personnel in China, to maintain cloud systems for other critical federal departments, such as the Justice, Treasury, and Commerce departments.
The Government Community Cloud: A Target for Espionage?
This sensitive work has been conducted within Microsoft’s Government Community Cloud (GCC), a platform designed for information that, while not classified, is nonetheless considered sensitive. The Federal Risk and Authorization Management Program (FedRAMP), the U.S. government’s cloud accreditation authority, has authorized GCC to handle data classified as “moderate” impact. this designation signifies that the loss of confidentiality, integrity, or availability of such data could lead to “serious adverse effect on an agency’s operations, assets, or individuals.”
Justice, Treasury, Commerce, and Beyond: A Widespread Vulnerability
the scope of this practice extends to several key government bodies. A 2022 report highlighted the Justice Department‘s Antitrust Division’s use of GCC to support its criminal and civil investigation and litigation functions. Moreover, propublica’s investigation uncovered that parts of the Environmental Protection Agency and the Department of Education have also utilized GCC.
“Digital Escorts” and lingering Security Doubts
Microsoft has stated that its foreign engineers working on GCC projects are supervised by U.S.-based personnel, referred to as “digital escorts,” a system reportedly mirroring that used for Defense Department support. Though, cybersecurity experts remain concerned.
“There’s a misconception that,if government data isn’t classified,no harm can come of its distribution,” stated Rex Booth,former federal cybersecurity official and current Chief Information Security Officer at SailPoint. He emphasized the growing threat landscape: “With so much data stored in cloud services-and the power of AI to analyze it quickly-even unclassified data can reveal insights that could harm U.S. interests.”
This revelation underscores the critical need for robust oversight and stringent security protocols for all government cloud infrastructure, regardless of classification levels, to safeguard sensitive national interests from potential foreign exploitation.
