Microsoft faces scrutiny as Sharepoint vulnerabilities exploited in global cyber attacks

Microsoft is facing growing criticism after it confirmed that vulnerabilities in its SharePoint server software have been widely exploited by Chinese state-linked hackers, leading to breaches in hundreds of organisations worldwide, including key US government agencies.

The flaws, which affect only on-premises SharePoint servers and not Microsoft’s cloud-based services, were initially identified at a hacking competition in Berlin in May. Although Microsoft released a patch earlier this month, it was later revealed that the initial fix was incomplete, allowing attackers to continue exploiting the weakness.

According to Microsoft, three groups – Linen Typhoon, Violet Typhoon, and Storm-2603 – have targeted internet-facing SharePoint servers. Linen Typhoon and Violet Typhoon are believed to be Chinese state-backed, while Storm-2603 is assessed to be China-based. Microsoft noted, “With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks against unpatched on-premises SharePoint systems.”

The Dutch cybersecurity firm Eye Security reported that at least 400 organisations have been breached, a figure it expects to rise as investigations continue. “We expect it may continue to rise as investigations progress,” Eye Security stated.

Victims include US federal and state agencies, universities, energy companies, and, according to Bloomberg, the US National Nuclear Security Administration, which oversees the country’s nuclear weapons. The majority of breaches have occurred in the United States, but organisations in Europe and the Middle East have also been affected.

The exploitation campaign escalated when the group Storm-2603 began deploying ransomware, causing further disruption. Microsoft observed that Storm-2603 used the vulnerabilities to gain initial access, steal credentials, and distribute ransomware within compromised environments.

Microsoft has released new comprehensive security updates and urged all users of on-premises SharePoint servers to install them. The company also recommends rotating machine keys, restarting servers, and enabling advanced security features. “Customers should apply these updates immediately to ensure they are protected,” Microsoft advised.

The Chinese embassy in Washington has denied involvement, stating, “We also firmly oppose smearing others without solid evidence.”

The incident has renewed scrutiny of Microsoft’s approach to security. Last year, the US Cyber Safety Review Board criticised the company for “deprioritising both enterprise security investments and rigorous risk management”, calling for an overhaul of its corporate culture.



Share Story:

Recent Stories


The future-ready CFO: Driving strategic growth and innovation
This National Technology News webinar sponsored by Sage will explore how CFOs can leverage their unique blend of financial acumen, technological savvy, and strategic mindset to foster cross-functional collaboration and shape overall company direction. Attendees will gain insights into breaking down operational silos, aligning goals across departments like IT, operations, HR, and marketing, and utilising technology to enable real-time data sharing and visibility.

The corporate roadmap to payment excellence: Keeping pace with emerging trends to maximise growth opportunities
In today's rapidly evolving finance and accounting landscape, one of the biggest challenges organisations face is attracting and retaining top talent. As automation and AI revolutionise the profession, finance teams require new skillsets centred on analysis, collaboration, and strategic thinking to drive sustainable competitive advantage.