Microsoft servers hacked by Chinese groups, firm says

Microsoft Reports SharePoint Server Hack by Chinese Groups Targeting Businesses
Photo: BBC

Microsoft Reports SharePoint Server Hack by Chinese Groups Targeting Businesses

Microsoft has reported that Chinese threat actors, specifically Linen Typhoon, Violet Typhoon, and Storm-2603, have successfully hacked its SharePoint document software servers. These groups exploited vulnerabilities in on-premises SharePoint servers, which are used by businesses, but did not target Microsoft’s cloud-based service. The tech giant has already released security updates to address the issue and urged all businesses using on-premises SharePoint servers to implement them promptly. The hackers’ activities were observed to involve sending requests to the SharePoint servers to access and steal sensitive data, potentially allowing them to maintain ongoing access to the affected systems. Charles Carmakal from Mandiant Consulting noted that various global sectors, including government and defense organizations, were targeted. Microsoft also highlighted that Linen Typhoon, known for focusing on intellectual property theft, had been active for over a decade, targeting government and human rights organizations. Violet Typhoon and Storm-2603 were associated with espionage efforts across various industries, including the financial and health sectors. The attack was particularly damaging because it occurred before a patch was available, allowing the hackers to exploit the vulnerability opportunistically.

Leave a Reply

Your email address will not be published. Required fields are marked *