
Cyber Security
Microsoft SharePoint Hack Reaches 400+ Victims, Including U.S. Nuclear Agency
Updated on Thu, Jul 24, 2025
Recent events show how one such gap turned into a major global threat.
We’re talking about the recent Microsoft SharePoint hack, which has taken the spotlight over security threats faced by Alaska Airlines, Ring, KNP, and WhatsApp.
Let’s unpack how a common software issue became a serious cybersecurity concern.
Read on!
Ransomware Hits Over 400 Victims Via SharePoint Server Vulnerability
Microsoft has recently sounded the alarm over ongoing cyberattacks exploiting major security flaws in its on-premises SharePoint Server systems. Now, that threat has taken a dangerous turn.
Hackers targeting vulnerabilities in Microsoft's SharePoint server software are now deploying ransomware, escalating the already widespread cyber-espionage campaign. Microsoft has identified the culprits as the group "Storm-2603," confirming the group’s exploitation of a spoofing vulnerability in a recent blog post.
This new development introduces the threat of network paralysis until digital currency payments are made, a significant departure from typical data theft objectives of state-backed operations.
The campaign has impacted over 400 victims, up from 100 affected businesses days earlier, although Eye Security warns the true number may be higher. While most remain unnamed, the National Institute of Health (NIH) confirmed a breach, and reports suggest the Department of Homeland Security and other U.S. agencies were also affected.
"There are many more, because not all attack vectors have left artifacts that we could scan for," said Vaisha Bernard, chief hacker at Eye Security, one of the first firms to detect the breaches.
Microsoft and Google-owner, Alphabet, say Chinese hackers are behind the attacks, though Beijing denies it. The move to ransomware marks a serious escalation in the ongoing cyber campaign.
Yet, this rise in ransomware attacks could have been prevented, as it traces back to a patch that didn’t fully fix the SharePoint flaw.
July Security Patch Failed To Fix Critical SharePoint Flaw, Says Microsoft
A major SharePoint flaw found in May wasn’t fully fixed by Microsoft’s recent patch in July, sparking the ongoing global cyber-espionage campaign.
Microsoft confirmed on Tuesday that its initial fix was ineffective, although subsequent patches have been deployed.
The source of the cyber-espionage campaign, which has hit around 100 organizations, is still unknown. However, Microsoft's blog post points to three China-linked hacking groups—"Linen Typhoon," "Violet Typhoon," and another unnamed group as exploiting the weakness.
Beijing's embassy in Washington denies these allegations, stating China "opposed all forms of cyberattacks, and smearing others without solid evidence."
The flaw, dubbed "ToolShell," was initially discovered by a Vietnamese cybersecurity researcher who earned a $100,000 prize. Despite Microsoft's July 8 patch, cybersecurity firms observed increased malicious activity around ten days later, with British firm Sophos noting, "Threat actors subsequently developed exploits that appear to bypass these patches."
The U.S. National Nuclear Security Administration was reportedly breached, though no sensitive data appears to have been compromised.
The failed fix had bigger consequences, and one of them being a breach at a top U.S. agency.
U.S. Nuclear Agency Reportedly Breached In Microsoft SharePoint Hack
The U.S. National Nuclear Security Administration (NNSA), which oversees the nation’s nuclear weapons, was reportedly breached in a recent hack targeting Microsoft’s SharePoint software, according to Bloomberg News.
Though the breach impacted the NNSA, which manages the U.S. nuclear arsenal, there’s no indication that sensitive or classified data was compromised. The full scope and impact are still being assessed, as the SharePoint server flaw continues to be fixed.
The U.S. Energy Department, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and Microsoft have not commented on the matter yet.
However, the incident highlights the growing challenge of protecting critical infrastructure from cyber threats and criminal groups.
Can delayed security patches be justified when national infrastructure is at risk? Should Microsoft be liable for the losses incurred by the ransomware victims?
Let us know your thoughts in the comments section below!
First published on Thu, Jul 24, 2025
Enjoyed what you've read so far? Great news - there's more to explore!
Stay up to date with the latest news, a vast collection of tech articles including introductory guides, product reviews, trends and more, thought-provoking interviews, hottest AI blogs and entertaining tech memes.
Plus, get access to branded insights such as informative white papers, intriguing case studies, in-depth reports, enlightening videos and exciting events and webinars from industry-leading global brands.
Dive into TechDogs' treasure trove today and Know Your World of technology!
Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.
Loading comments...


















