Earlier quoted context omitted.
> many MS engineering accounts had already been hacked This isnt being focused on enough here. MS is set up in such a way that there are individual members of staff, with individual devices, that just need to be compromised for all their infrastructure is compromised. This fact alone means that's its near certainly presently compromised. states have the resources to place an engineer at MS, let alone compromise one o…
Microsoft knows which accounts were targeted by the attacker. They say so in the first link: "Our telemetry and investigations indicate that post-compromise activity was limited to email access and exfiltration for targeted users." Therefore, no, it is hyperbole that this attack means any and all MS data is compromised. The key that was compromised from one MS engineer was used in conjunction with a specific bug - cr…
That's the access patterns of a single application for a single user. They know absolutely nothing about what's happened to their infrastructure.