Microsoft Hack Hits Hundreds of Firms, Agencies as Damage Spreads

Key Points

  • Rapid Increase in Victims: The number of organizations compromised by a security vulnerability in Microsoft’s SharePoint servers has surged over six-fold in just a few days, with around 400 entities affected, up from an initial estimate of 60, according to Eye Security.**
  • Geographic Spread: Most victims are in the US, followed by Mauritius, Jordan, South Africa, and the Netherlands, with high-profile breaches including the US National Nuclear Security Administration and the National Institutes of Health.**
  • State-Sponsored Attacks: Microsoft attributes the attacks to Chinese state-sponsored hacking groups like Linen Typhoon and Violet Typhoon, amid ongoing US-China tensions over cybersecurity and trade.**
  • Vulnerability Exploitation: The SharePoint flaws allow hackers to steal keys and impersonate users, potentially accessing sensitive data, though Microsoft has released patches to address the issue.**
  • Broader Implications: Experts warn the true number of victims may be higher, with hackers possibly maintaining deep network access for espionage, targeting government, education, and technology sectors globally.**

Summary

A critical security vulnerability in Microsoft’s SharePoint servers has led to a sharp rise in cyberattacks, with over 400 organizations compromised, a six-fold increase in days, as reported by Eye Security. Predominantly affecting US entities, the breaches also span Mauritius, Jordan, South Africa, and the Netherlands, impacting key institutions like the US National Nuclear Security Administration and the National Institutes of Health. Microsoft has pointed to Chinese state-sponsored groups, including Linen Typhoon and Violet Typhoon, as culprits, escalating US-China cybersecurity tensions. The flaws enable hackers to steal access keys and infiltrate networks, though patches have been issued. Experts caution that the actual victim count may be underreported, with potential for deeper espionage across government, education, and tech sectors worldwide. While no data breaches are confirmed, the US and affected nations are collaborating with Microsoft to mitigate risks. This incident underscores ongoing global cybersecurity challenges and the sophisticated nature of state-backed hacking campaigns.

yahoo
July 24, 2025
Stocks
Read article

Related news