Share

FIRSTonline Banner

Global Microsoft SharePoint Hacker Attack: Governments, Businesses, and Schools Affected

A zero-day cyberattack compromised thousands of SharePoint servers worldwide, opening the door to hackers. Public agencies, universities, and energy companies were affected. Microsoft still lacks a definitive patch, and the FBI and governments are investigating.

Global Microsoft SharePoint Hacker Attack: Governments, Businesses, and Schools Affected

A wave of Hacker attacks have overwhelmed governments, universities and companies around the world, taking advantage of a fto criticism in Microsoft's SharePoint servers, the system used for share and manage documents sensitive within organizations. The alarm was raised by the Washington Post, citing cybersecurity experts and U.S. government sources.

It is a zero-day attack, that is, based on a vulnerability that was unknown until the time of its discovery, and has already Servers of at least two US federal agencies compromised, energy companies, auniversities in Brazil, agovernment agency in Spain and even an Asian telecommunications company. An invisible flaw, hit with surgical precision.

An unprecedented wave: local authorities and schools also affected

According to the Dutch company Eye Security, they were Over 50 confirmed violations trackedAmong the targets targeted by the hackers were a U.S. state legislature, several European public bodies, and a local government agency in Albuquerque.

In the United StatesIn particular, the effects have been felt across the board. In one case, a public agency lost access to a digital database intended for citizens, with direct consequences for administrative transparency. The urgency is such that in Arizona, state, local, and tribal authorities convened urgently to coordinate countermeasures.

A race against time with no patch available

Il real problem, for now, is that Microsoft has not yet released a final patch for SharePoint Server 2016 and 2019 versions. The company recommended that users temporarily disconnect servers from the internet or adopt technical changes to address the vulnerabilities. SharePoint Online, the cloud version integrated into Microsoft 365, was not affected by the attack.

“Anyone who has an internally hosted SharePoint server has a problem,” he said. Adam Meyers, vice president of CrowdStrike. The alert was also extended to educational institutions with the Center for Internet Security contacting about 100 organizations, including schools and universities, to report possible compromises.

The role of spoofing and access key theft

Experts fear that the attack was not limited to data theft, but included the theft of cryptographic keys which would allow hackers to re-enter systems even after any updates. In some cases, the attackers would have used spoofing techniques, masquerading as trusted individuals to bypass system protections.

"The patch will arrive, but it won't help those who have already been compromised in the last 72 hours," explained a researcher on condition of anonymity. The risk is that, even after the updates, systems remain vulnerable to future unauthorized access.

Microsoft under accusation, once again

This isn't the first time Microsoft has been in the eye of the storm. Already in 2023, the company was criticized for serious security flaws which allowed Chinese hackers to access the emails of US federal officials, including then-Commerce Secretary Gina Raimondo.

In recent days, the Redmond giant has also had to deal with aProPublica investigation which revealed the use of China-based engineers to manage cloud services for the U.S. Department of Defense. Following the revelation, the Pentagon ordered a comprehensive cloud procurement review.

Investigations underway and global alert

The FBI has confirmed that it is knowledge of the attack and to cooperate with federal agencies and private partners. The Canadian and Australian governments are also conducting joint investigations. According to the U.S. Department of Homeland Security, the hackers exploited a vulnerability similar to the one Microsoft patched in early July, a sign of a targeted and well-organized strategy.

At the moment, The identity of the attackers and their objectives remain unknown.. But the breadth of the operation and the variety of objectives suggest a large-scale coordinated attack, with possible geopolitical implications yet to be clarified.

comments