Microsoft Cyber Attack Affects Hundreds of Companies and Agencies
Reports indicate that the number of organizations affected by a security flaw in Microsoft SharePoint servers is sharply increasing. A research firm has noted a surge in the count of compromised entities, rising over six times in just a matter of days.
Approximately 400 government agencies, corporations, and various groups have been hacked, according to Eye Security, a Dutch cybersecurity firm that first identified these attacks last week. This is a significant increase from the earlier estimate of about 60.
The majority of the affected organizations are located in the US, followed by countries like Mauritius, Jordan, South Africa, and the Netherlands. Notably, the National Nuclear Security Administration, the agency responsible for the US’s nuclear arsenal, has also been breached.
The National Institutes of Health also faced repercussions due to the SharePoint vulnerabilities. A spokesperson from the Department of Health and Human Services stated, “Our security teams are actively monitoring, identifying, and mitigating risks posed by the Microsoft SharePoint vulnerability.”
He further added that there’s currently no evidence of information being compromised. The department is working alongside Microsoft and the US Cybersecurity and Infrastructure Security Agency regarding these issues.
South Africa’s National Treasury is also seeking assistance from Microsoft due to malware detected on its network. However, it confirmed that its systems and websites remain operational.
These hacks are part of a broader trend of major breaches attributed partially to China, coinciding with escalating tensions between the US and China over security and trade. The US has long criticized China for allegedly pilfering government and corporate secrets for decades.
Eye Security’s co-owner, Vaisha Bernard, expressed that the actual number of affected victims could be significantly higher, considering the potential for hidden ways to compromise servers. “This situation is still evolving, and other opportunistic adversaries continue to exploit vulnerable servers,” he emphasized.
The compromised organizations span various sectors including government, education, and technology. Smaller numbers of victims are reported across Europe, Asia, the Middle East, and South America.
According to threat analyst Sveva Scenarelli of Recorded Future Inc., state-sponsored hackers typically exploit significant cybersecurity weaknesses like those found in SharePoint. They often begin with targeted hacks and, once vulnerabilities are discovered, they start to broaden their methods.
Once access is gained, these groups can evaluate compromised organizations and prioritize targets for additional activities. This could include deepening their access to networks and attempting to extract sensitive information.
US Treasury Secretary Scott Bessent, who will be attending trade talks in Stockholm with Chinese officials next week, suggested that the SharePoint hacks would be included in their discussions.
The vulnerabilities allow hackers to infiltrate SharePoint servers and extract keys, enabling them to impersonate users or services. This can lead to extensive access for stealing confidential data. Microsoft has released patches to rectify these issues, but researchers warn that many servers may already be at risk.
Microsoft has accused Chinese state-sponsored hackers, identified as Linen Typhoon and Violet Typhoon, of orchestrating the attacks. Another group known as Storm-2603 has also been linked to exploiting these vulnerabilities.
Microsoft has consistently pointed fingers at China for significant cyberattacks. For instance, a Chinese operation in 2021 compromised numerous Microsoft Exchange servers, and a 2023 attack targeted senior US officials’ email accounts, leading to scrutiny over Microsoft’s security measures.
Eugenio Benincasa, a researcher at ETH Zurich’s Center for Security Studies, pointed out that members of the identified groups have been indicted in the US for their involvement in hacking campaigns against American organizations. He characterized them as being well-known for engaging in extensive espionage.
Benincasa noted that the SharePoint breaches are likely executed by proxy groups connected to the government rather than being directly conducted by Chinese government agencies. He mentioned that private hacking firms can sometimes engage in “hacker for hire” operations.
With at least three identified groups exploiting the same vulnerability, it is likely that more will follow.
A Chinese Foreign Ministry spokesperson stated, “Cybersecurity is a common challenge faced by all countries and should be addressed through dialogue and collaboration.” He also emphasized China’s opposition to hacking activities.
Microsoft describes the Linen Typhoon group, first identified in 2012, as focused on stealing intellectual property, particularly from government and defense organizations. Violet Typhoon has been active since 2015 and primarily targets former military personnel and NGOs.
The hackers have utilized vulnerabilities in SharePoint to infiltrate systems belonging to various US agencies, including the Education Department and Florida’s Department of Revenue.
Edwin Lyman, who oversees nuclear power safety at the Union of Concerned Scientists, remarked that while the National Nuclear Security Administration safeguards some of the world’s most sensitive information, classified networks are segregated from the internet, making data transmission to adversaries unlikely.
Nevertheless, he noted that less sensitive, unclassified information could have been compromised, including details related to nuclear materials.
— With contributions from Lucille Liu, Ari Natter, and Jessica Nix.
(This version includes updates regarding the South African hack. A previous version also corrected the spelling of Rhode Island.)
What are your thoughts on the recent security vulnerabilities discovered in SharePoint?
