Saturday, September 6, 2025
  • Login
Forbes 40under40
  • Home
  • Technology
  • Innovation
  • Real Estate
  • Leadership
  • Money
  • Lifestyle
No Result
View All Result
  • Home
  • Technology
  • Innovation
  • Real Estate
  • Leadership
  • Money
  • Lifestyle
No Result
View All Result
Forbes 40under40
No Result
View All Result
Home Real Estate

Tally of Microsoft victims surges to 400 as hackers capitalise on SharePoint flaw

by Stephanie Irvin
in Real Estate
Tally of Microsoft victims surges to 400 as hackers capitalise on SharePoint flaw
Share on FacebookShare on Twitter


[WASHINGTON] The number of companies and organisations compromised by a security vulnerability in Microsoft’s SharePoint servers is increasing rapidly, with the tally of victims soaring more than six-fold in a few days, according to one research firm.

Hackers have breached about 400 government agencies, corporations and other groups, according to estimates from Eye Security, the Dutch cybersecurity company that identified an early wave of the attacks last week. That’s up from roughly 60 based on its previous estimate provided to Bloomberg News on Tuesday.

The security firm said that most of the victims are in the US, followed by Mauritius, Jordan, South Africa and the Netherlands. The National Nuclear Security Administration, the US agency responsible for maintaining and designing the nation’s cache of nuclear weapons, was among those breached, Bloomberg reported earlier. 

The hacks are among the latest major breaches that Microsoft has blamed, at least in part, on China and come amid heightened tensions between Washington and Beijing over global security and trade. The US has repeatedly criticised China for campaigns that have allegedly stolen government and corporate secrets over a period spanning decades.

“We estimate that the real number might be much higher as there can be many more hidden ways to compromise servers that do not leave traces,” Eye Security’s co-owner Vaisha Bernard said in an email to Bloomberg News. “This is still developing, and other opportunistic adversaries continue to exploit vulnerable servers.”

The organisations compromised in the SharePoint breaches include many working in government, education, and technology services, Bernard said. There were smaller numbers of victims in countries across Europe, Asia, the Middle East and South America.

BT in your inbox

Start and end each day with the latest news stories and analyses delivered straight to your inbox.

US Treasury Secretary Scott Bessent, who is set to meet his Chinese counterparts in Stockholm next week for a third round of trade talks, suggested in a Bloomberg Television interview on Wednesday (Jul 23) that the SharePoint hacks will be discussed. “Obviously things like that will be on the agenda with my Chinese counterparts,” he said.

The security flaws allow hackers to access SharePoint servers and steal keys that can let them impersonate users or services, potentially enabling deep access into compromised networks to steal confidential data. Microsoft has issued patches to fix the vulnerabilities, but researchers cautioned that hackers may have already got a foothold into many servers.

Microsoft on Tuesday accused Chinese state-sponsored hackers known as Linen Typhoon and Violet Typhoon of being behind the attacks. Another hacking group based in China, which Microsoft calls Storm-2603, also exploited them, according to the company.

The Redmond, Washington company has repeatedly blamed China for major cyberattacks. In 2021, an alleged Chinese operation compromised tens of thousands of Microsoft Exchange servers. In 2023, another alleged Chinese attack on Microsoft Exchange compromised senior US officials’ email accounts. A US government review later accused Microsoft of a “cascade of security failures” over the 2023 incident.

Eugenio Benincasa, a researcher at ETH Zurich’s Center for Security Studies who specialises in analysing Chinese cyberattacks, said members of the groups identified by Microsoft had previously been indicted in the US for their alleged involvement in hacking campaigns targeting US organisations. They are well known for their “extensive espionage,” he said. 

It’s likely that the SharePoint breaches are being carried out by proxy groups that work with the government rather than Chinese government agencies directly carrying out the hacking, according to Benincasa. Private hacking companies in the country sometimes participate in “hacker for hire” operations, he added. 

“Now that at least three groups have reportedly exploited the same vulnerability, it’s plausible more could follow,” he said.

“Cybersecurity is a common challenge faced by all countries and should be addressed jointly through dialogue and cooperation,” said Chinese Foreign Ministry spokesman Guo Jiakun. “China opposes and fights hacking activities in accordance with the law. At the same time, we oppose smears and attacks against China under the excuse of cybersecurity issues.”

According to Microsoft, the hacking group Linen Typhoon was first identified in 2012, and is focused on stealing intellectual property, primarily targeting organisations related to government, defence, strategic planning, and human rights. Violet Typhoon, first observed in 2015, was “dedicated to espionage” and primarily targeted former government and military personnel, non-governmental organisations, as well as media and education sectors in the US, Europe, and East Asia. 

The hackers have also used the SharePoint flaws to break into systems belonging to the US Education Department, Florida’s Department of Revenue and the Rhode Island General Assembly, Bloomberg previously reported. BLOOMBERG

Tags: capitaliseflawHackersMicrosoftSharePointSurgestallyVictims
Stephanie Irvin

Stephanie Irvin

Next Post
Judge Judy Reveals the Menendez Brothers Opinion She’ll Get a “Lot of Flak For”

Judge Judy Reveals the Menendez Brothers Opinion She’ll Get a “Lot of Flak For”

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Forbes 40under40 stands as a distinguished platform revered for its commitment to honoring and applauding the remarkable achievements of exceptional individuals who have yet to reach the age of 40. This esteemed initiative serves as a beacon of inspiration, spotlighting trailblazers across various industries and domains, showcasing their innovation, leadership, and impact on a global scale.

 
 
 
 

NEWS

  • Forbes Magazine
  • Technology
  • Innovation
  • Money
  • Leadership
  • Real Estate
  • Lifestyle
Instagram Facebook Youtube

© 2025 Forbes 40under40. All Rights Reserved.

  • About Us
  • Advertise
  • Contact Us
No Result
View All Result
  • Home
  • Technology
  • Innovation
  • Real Estate
  • Leadership
  • Money
  • Lifestyle

© 2024 Forbes 40under40. All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In