Ransomware escalates Microsoft SharePoint cyberattack, hundreds of organisations impacted

Ransomware escalates Microsoft SharePoint cyberattack, hundreds of organisations impacted

A concerning development has emerged from a cyber-espionage campaign that exploits vulnerabilities in outdated Microsoft SharePoint server software. Microsoft has reported that the hacking group known as "Storm-2603" has escalated its operations by introducing ransomware into the mix, transforming what was initially a surveillance tactic into a destructive threat. In a recent blog post, Microsoft detailed how this notorious group has shifted its approach, now using the same vulnerability to deploy ransomware that locks down networks and demands cryptocurrency ransoms for restoration. Dutch cybersecurity firm Eye Security revealed that at least 400 organizations have already fallen victim to this attack, a significant rise from the 100 victims identified just days ago. Vaisha Bernard, the chief hacker at Eye Security, noted that the true number is likely much higher, as not all attack vectors have left detectable traces. This shift from traditional espionage methods to a more aggressive ransomware strategy has raised alarms, with the impact now extending beyond private sector companies to include critical U.S. government institutions. A representative from the National Institutes of Health confirmed that one of its servers had been compromised, stating that additional servers were isolated as a precautionary measure. Reports from NextGov and Politico indicate that several federal agencies, including the Department of Homeland Security, may also have been affected by this campaign. However, as of now, the cybersecurity unit of DHS, CISA, has not commented on the situation. The wave of attacks began following Microsoft's failure to fully patch a known security flaw in its SharePoint software, prompting urgent action from IT administrators globally to secure their systems. While Microsoft has not yet provided detailed information regarding the full extent of the ransomware threat or the identities of all affected organizations, both Microsoft and Alphabet, Google's parent company, have linked the attacks to Chinese state-backed hackers, a claim that the Chinese government has denied.

Sources : Business Today

Published On : Jul 24, 2025, 06:30

Mobile
X Launches Ground-Up Redesign of Android App for Enhanced User Experience

In a significant move for its users, X, led by Elon Musk, has unveiled a completely reimagined version of its Android ap...

Business Today | Jul 21, 2026, 05:25
X Launches Ground-Up Redesign of Android App for Enhanced User Experience
AI
Streamlining AI: Major Update to the Model Context Protocol Simplifies Operations

The Model Context Protocol (MCP) serves as a crucial foundation for AI interoperability, enabling AI models to securely ...

TechCrunch | Jul 20, 2026, 21:15
Streamlining AI: Major Update to the Model Context Protocol Simplifies Operations
Science
Colossal Biosciences Eyes Major Funding Boost Amidst De-Extinction Ambitions

Colossal Biosciences, the ambitious startup known for its efforts in de-extinction, is reportedly in discussions to secu...

TechCrunch | Jul 21, 2026, 24:10
Colossal Biosciences Eyes Major Funding Boost Amidst De-Extinction Ambitions
Startups
Agility Robotics Shuns Hiring Wars, Focuses on Culture and Innovation

Agility Robotics has recently established a new base in Silicon Valley, aiming to attract top-tier engineers for its inn...

Business Insider | Jul 20, 2026, 21:45
Agility Robotics Shuns Hiring Wars, Focuses on Culture and Innovation
AI
The Open-Weight AI Debate: Navigating Innovation and Regulation

The emergence of Kimi K3, a leading open-weight large language model developed by the Chinese lab Moonshot, has ignited ...

TechCrunch | Jul 20, 2026, 20:10
The Open-Weight AI Debate: Navigating Innovation and Regulation
View All News