financetom
Business
financetom
/
Business
/
Microsoft server hack has hit about 100 victims, researcher says
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Microsoft server hack has hit about 100 victims, researcher says
Jul 21, 2025 9:41 AM

*

Hack exploits previously unknown flaw in SharePoint

software

*

Thousands of entities potentially now vulnerable to attack

*

Around 100 different organizations compromised by hackers

(Adds comment from Netherlands-based researcher in paragraphs

3, 4, and 5. Adds comment from NCSC in paragraph 9.)

By James Pearson and Raphael Satter

WASHINGTON/LONDON, July 21 (Reuters) -

A sweeping cyberespionage operation targeting Microsoft ( MSFT )

server software compromised about 100 different

organizations as of the weekend, one of the researchers who

helped uncover the campaign said Monday.

Microsoft ( MSFT ) on Saturday issued an alert about "active

attacks" on self-managed SharePoint servers, which are widely

used by government agencies and businesses to share documents

within organisations. Dubbed a "zero day" because it leverages a

previously undisclosed digital weaknesses, the hacks allow spies

to penetrate vulnerable servers and potentially drop a back door

to secure continuous access to victim organizations.

Vaisha Bernard, the chief hacker at Eye Security, a

Netherlands-based cybersecurity firm which

discovered the hacking campaign

targeting one of its clients on Friday, said that an

internet scan carried out with the ShadowServer Foundation had

uncovered nearly 100 victims altogether - and that was before

the technique behind the hack was widely known.

"It's unambiguous," Bernard said. "Who knows what other

adversaries have done since to place other back doors."

He declined to identify the affected organizations, saying

that the relevant national authorities had been notified. The

ShadowServer Foundation didn't immediately return a message

seeking comment.

Another researcher said that, so far, the spying appeared to

be the work of a single hacker or set of hackers.

"It's possible that this will quickly change," said Rafe

Pilling, Director of Threat Intelligence at Sophos, a British

cybersecurity firm.

Microsoft ( MSFT ) said it had "provided security updates and

encourages customers to install them," a company spokesperson

said in an emailed statement.

It was not clear who was behind the ongoing hack. The FBI said

on Sunday it was aware of the attacks and was working closely

with its federal and private-sector partners, but offered no

other details. Britain's National Cyber Security Center said in

a statement that it was aware of "a limited number" of targets

in the United Kingdom.

According to data from Shodan, a search engine that helps to

identify internet-linked equipment, over 8,000 servers online

could theoretically have already been compromised by hackers.

Those servers include major industrial firms, banks,

auditors, healthcare companies, and several U.S. state-level and

international government entities.

"The SharePoint incident appears to have created a broad

level of compromise across a range of servers globally," said

Daniel Card of British cybersecurity consultancy, PwnDefend.

"Taking an assumed breach approach is wise, and it's also

important to understand that just applying the patch isn't all

that is required here."

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Goldman Sachs' Petershill plans to delist from London
Goldman Sachs' Petershill plans to delist from London
Sep 25, 2025
Sept 25 (Reuters) - British investment group Petershill Partners ( PHLLF ) said on Thursday it plans to delist its shares from London and return money to shareholders as the board has become dissatisfied with the firm's share price performance and valuation, dealing another blow to the UK equity market. A subsidiary of Goldman Sachs Group Inc's ( GS )...
Arecor announces Co-development Agreement with US Insulin Pump Device Company for AT278 & Sale of Royalty Rights and Technology Access Fees for AT220 and AT292
Arecor announces Co-development Agreement with US Insulin Pump Device Company for AT278 & Sale of Royalty Rights and Technology Access Fees for AT220 and AT292
Sep 25, 2025
This announcement contains inside information for the purposes of the retained UK version of the EU Market Abuse Regulation (EU) 596/2014 (UK MAR).   Arecor Therapeutics plc (“Arecor” or the “Company”) Co-development Agreement with US Insulin Pump Device Company for AT278 and Sale of Royalty and Technology Access Fees for up to $11 million AT278 (500U/mL) is the only ultra-concentrated and ultra-rapid acting...
Birkenstock raises fiscal 2025 revenue forecast
Birkenstock raises fiscal 2025 revenue forecast
Sep 25, 2025
Sept 25 (Reuters) - German sandal maker Birkenstock ( BIRK ) on Thursday forecast fiscal 2025 revenue of at least 2.09 billion euros ($2.45 billion) on strong demand for its clogs and shoes, ahead of its prior guidance. The company had previously said it expects full-year revenue growth at the higher end of its forecast range of 15% to 17%....
Pepper Advantage to Acquire Computershare’s UK Mortgage Servicing Business
Pepper Advantage to Acquire Computershare’s UK Mortgage Servicing Business
Sep 25, 2025
Transaction will increase Pepper Advantage’s UK AUM to ~£50 billion and accelerate PRISM, its proprietary credit management technology platform LONDON--(BUSINESS WIRE)-- Pepper Advantage, a leading international credit management and technology firm, today announced it will acquire Computershare’s UK mortgage servicing business, Computershare Loan Services, pending regulatory approval. This strategic acquisition will increase Pepper Advantage’s assets under management (AUM) in...
Copyright 2023-2026 - www.financetom.com All Rights Reserved