Microsoft servers hacked by Chinese groups, firm says
Microsoft has revealed that Chinese state-linked hacking groups have exploited vulnerabilities in its on-premises SharePoint servers, targeting sensitive business and government data.
Microsoft has revealed that Chinese state-linked hacking groups have exploited vulnerabilities in its on-premises SharePoint servers, targeting sensitive business and government data.
The tech giant identified the groups as Linen Typhoon, Violet Typhoon, and Storm-2603, which are believed to be backed or based in China. These actors did not breach Microsoft’s cloud-based services, but instead exploited flaws in locally hosted SharePoint systems widely used by firms.
"We have high confidence that these threat actors will continue targeting systems lacking our latest security updates," Microsoft said in a statement.
The company has released urgent security patches and advised all affected customers to apply them immediately.
According to Charles Carmakal, CTO at Google Cloud's Mandiant Consulting, multiple sectors and geographies have already been affected. The hackers reportedly stole cryptographic key material, allowing them to maintain persistent access to victims' systems.
Microsoft said the groups have long histories of cyber espionage:
-
Linen Typhoon: 13-year campaign targeting government, defence, and human rights organizations.
-
Violet Typhoon: Focused on espionage across NGOs, think tanks, media, and healthcare sectors.
-
Storm-2603: Believed to be a China-based threat group with ongoing activity.
Investigations into additional actors using these exploits are still underway.