financetom
Technology
financetom
/
Technology
/
Microsoft server hack hit about 100 organizations, researchers say
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Microsoft server hack hit about 100 organizations, researchers say
Jul 21, 2025 11:10 AM

WASHINGTON/LONDON (Reuters) - A sweeping cyber espionage operation targeting Microsoft ( MSFT ) server software compromised about 100 different organizations as of the weekend, two of the organizations that helped uncover the campaign said on Monday.

Microsoft ( MSFT ) on Saturday issued an alert about "active attacks" on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organisations. SharePoint instances run off of Microsoft ( MSFT ) servers were unaffected.

Dubbed a "zero-day" because it leverages a previously undisclosed digital weakness, the hacks allow spies to penetrate vulnerable servers and potentially drop a backdoor to secure continuous access to victim organizations.

Vaisha Bernard, the chief hacker at Eye Security, a Netherlands-based cybersecurity firm, which discovered the hacking campaign targeting one of its clients on Friday, said that an internet scan carried out with the Shadowserver Foundation had uncovered nearly 100 victims altogether - and that was before the technique behind the hack was widely known.

"It's unambiguous," Bernard said. "Who knows what other adversaries have done since to place other backdoors."

He declined to identify the affected organizations, saying that the relevant national authorities had been notified.

The Shadowserver Foundation confirmed the 100 figure and said that most of those affected were in the United States and Germany and that the victims included government organizations.

Another researcher said that, so far, the spying appeared to be the work of a single hacker or set of hackers.    

"It's possible that this will quickly change," said Rafe Pilling, director of Threat Intelligence at Sophos, a British cybersecurity firm.

Microsoft ( MSFT ) said it had "provided security updates and encourages customers to install them," a company spokesperson said in an emailed statement.

It was not clear who was behind the ongoing hack. The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details. Britain's National Cyber Security Center said in a statement that it was aware of "a limited number" of targets in the United Kingdom. A researcher tracking the campaign said that the campaign appeared initially aimed at a narrow set of government-related organizations.

The pool of potential targets remains vast. According to data from Shodan, a search engine that helps to identify internet-linked equipment, over 8,000 servers online could theoretically have already been compromised by hackers.

Those servers include major industrial firms, banks, auditors, healthcare companies, and several U.S. state-level and international government entities. 

"The SharePoint incident appears to have created a broad level of compromise across a range of servers globally," said Daniel Card of British cybersecurity consultancy, PwnDefend. 

"Taking an assumed breach approach is wise, and it's also important to understand that just applying the patch isn't all that is required here."

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Telecoms seek to block US reinstatement of net neutrality rules
Telecoms seek to block US reinstatement of net neutrality rules
Jun 5, 2024
WASHINGTON (Reuters) - Telecom industry groups are seeking to block the Biden administration's reinstatement of landmark net neutrality rules set to take effect on July 22. The Federal Communications Commission (FCC) voted in April along party lines to reassume regulatory oversight of broadband internet and reinstate open internet rules adopted in 2015 that were rescinded under former President Donald Trump....
Sugar price breaches the minor resistance – Forecast today - 06-06-2024
Sugar price breaches the minor resistance – Forecast today - 06-06-2024
Jun 5, 2024
Sugar Price Analysis Expected Scenario Sugar price surpassed 18.90$ level and closed the daily candlestick above it, to head towards achieving intraday gains and test 19.82$ mainly in the upcoming sessions, making the bullish bias suggested for today. Moving above the EMA50 supports the expected rise, noting that breaking 18.90$ will stop the bullish wave and push the price to...
Corn price declines calmly – Forecast today - 06-06-2024
Corn price declines calmly – Forecast today - 06-06-2024
Jun 5, 2024
Corn Price Analysis Expected Scenario Corn price shows calm negative trades to gradually move away from 449.20$, reinforcing the expectations of continuing the bearish trend, which targets 433.50$ as a next station. The negative effect of the double top pattern reinforces the expectations to continue the decline, noting that breaching 449.20$ will stop the negative scenario and lead the price...
The Protocol: Another Episode in the Layer-2 Teams Drama
The Protocol: Another Episode in the Layer-2 Teams Drama
Jun 5, 2024
Ethereum's layer-2 teams are butting heads once again. This time, major figures in the space are condemning Matter Labs, the creator of zkSync, over its decision to trademark the acronym ZK, which is shorthand for zero-knowledge” cryptography, the core technology underlying zkSync and a plethora of other blockchain projects. Matter Labs claimed it made the move to protect users. Leaders...
Copyright 2023-2025 - www.financetom.com All Rights Reserved