{"id":3728,"date":"2025-07-23T03:22:34","date_gmt":"2025-07-23T03:22:34","guid":{"rendered":"https:\/\/260web.com\/news\/microsoft-servers-hacked-by-chinese-groups-firm-says\/"},"modified":"2025-07-23T03:22:34","modified_gmt":"2025-07-23T03:22:34","slug":"microsoft-servers-hacked-by-chinese-groups-firm-says","status":"publish","type":"post","link":"https:\/\/260web.com\/news\/microsoft-servers-hacked-by-chinese-groups-firm-says\/","title":{"rendered":"Microsoft servers hacked by Chinese groups, firm says"},"content":{"rendered":"<p>Microsoft servers hacked by Chinese groups, firm says<\/p>\n<p><div><img decoding=\"async\" src=\"https:\/\/260web.com\/news\/wp-content\/uploads\/2025\/07\/dN6VpU.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div data-component=\"text-block\" readability=\"22\">\n<p class=\"sc-9a00e533-0 hxuGS\">Chinese &#8220;threat actors&#8221; have hacked Microsoft&#8217;s SharePoint document software servers and targeted the data of the businesses using it, the firm has said.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">China state-backed Linen Typhoon and Violet Typhoon as well as China-based Storm-2603 were said to have &#8220;exploited vulnerabilities&#8221; in on-premises SharePoint servers, the kind used by firms, but not in its cloud-based service.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The US tech giant has released security updates in response and has advised all on-premises SharePoint server customers to install them.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">&#8220;Investigations into other actors also using these exploits are still ongoing,&#8221; Microsoft said in a statement.<\/p>\n<\/div>\n<div data-component=\"text-block\" readability=\"57.587433313574\">\n<p class=\"sc-9a00e533-0 hxuGS\">The firm said it had &#8220;high confidence&#8221; the hackers would continue to target systems which have not installed its security updates.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">It added that it would update its website blog with more information as its investigation continues.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Microsoft said it had observed attacks in which hackers had sent a request to a SharePoint server &#8220;enabling the theft of the key material by threat actors&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Charles Carmakal, chief technology officer at Mandiant Consulting firm, a division of Google Cloud, told the BBC it was &#8220;aware of several victims in several different sectors across a number of global geographies&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Carmakal said it appeared that governments and businesses that use SharePoint on their sites were the primary target.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">A number of adversaries who stole material encoded by cryptography were then able to regain ongoing access to the victims&#8217; SharePoint data, he said.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">&#8220;This was exploited in a very broad way, very opportunistically before a patch was made available. That&#8217;s why this is significant,&#8221; Carmakal said.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Carmakal said the &#8220;China-nexus actor&#8221; was deploying techniques similar to previous campaigns associated with Beijing.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Microsoft said Linen Typhoon had &#8220;focused on stealing intellectual property, primarily targeting organizations related to government, defence, strategic planning, and human rights&#8221; for 13 years.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">It added that Violet Typhoon had been &#8220;dedicated to espionage&#8221;, primarily targeting former government and military staff, non-governmental organizations, think tanks, higher education, the media, the financial sector and the health sector in the US, Europe, and East Asia.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Meanwhile, Storm-2603 was &#8220;assessed with medium confidence to be a China-based threat actor&#8221;.<\/p>\n<\/div>\n<p>Published at Wed, 23 Jul 2025 02:53:31 +0000<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft servers hacked by Chinese groups, firm says Chinese &#8220;threat actors&#8221; have hacked Microsoft&#8217;s SharePoint document software servers and targeted the data of the businesses using it, the firm has said. China state-backed Linen Typhoon and Violet Typhoon as well as China-based Storm-2603 were said to have &#8220;exploited vulnerabilities&#8221; in on-premises SharePoint servers, the kind&hellip; <a class=\"more-link\" href=\"https:\/\/260web.com\/news\/microsoft-servers-hacked-by-chinese-groups-firm-says\/\">Continue reading <span class=\"screen-reader-text\">Microsoft servers hacked by Chinese groups, firm says<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":3727,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[5],"tags":[],"class_list":["post-3728","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","entry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/posts\/3728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/comments?post=3728"}],"version-history":[{"count":0,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/posts\/3728\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/media\/3727"}],"wp:attachment":[{"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/media?parent=3728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/categories?post=3728"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/tags?post=3728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}