Microsoft SharePoint flaw exploited in global spy campaign, 400 victims impacted

The espionage campaign began when Microsoft failed to fully patch a known security vulnerability in its SharePoint software.

By  Storyboard18Jul 24, 2025 8:41 AM
Microsoft SharePoint flaw exploited in global spy campaign, 400 victims impacted
The espionage campaign began when Microsoft failed to fully patch a known security vulnerability in its SharePoint software.

A far-reaching cyber-espionage campaign exploiting unpatched versions of Microsoft SharePoint server software has compromised around 400 organizations globally, researchers at Netherlands-based cybersecurity firm Eye Security revealed, Reuters reported.

The figure marks a dramatic escalation from the 100 victims initially reported just days earlier and is based on forensic evidence - digital artifacts - found during server scans. However, Eye Security warned that the true scale of the breach could be far larger.

"There are many more, because not all attack vectors have left artifacts that we could scan for," Vaisha Bernard, chief hacker at Eye Security told in the report, which was among the first to detect the attacks.

The identities of most victim organizations have not been made public, but a spokesperson for the U.S. National Institutes of Health (NIH) confirmed on Wednesday that one of its servers had been compromised. "Additional servers were isolated for a precaution," the spokesperson said, according to a Washington Post report.

The espionage campaign began when Microsoft failed to fully patch a known security vulnerability in its SharePoint software.

The flaw quickly became a target for threat actors, prompting a race among system administrators to implement fixes before their networks were breached.

According to the report, both Microsoft and Google parent Alphabet have pointed to Chinese state-owned hackers as being among those exploiting the flaw. However, Beijing has denied the allegations.

First Published on Jul 24, 2025 8:40 AM

More from Storyboard18

Digital

Govt's OTT ban likely to fuel VPN use and piracy surge, say experts

Govt's OTT ban likely to fuel VPN use and piracy surge, say experts

Digital

Meta to halt political, social ads in Europe from October, cites EU laws

Meta to halt political, social ads in Europe from October, cites EU laws

Digital

Congress MP Rajeev Shukla slams OTT platforms ban; calls it attack on free expression

Congress MP Rajeev Shukla slams OTT platforms ban; calls it attack on free expression

Digital

Nvidia AI chips worth over $1 Billion smuggled into China Despite US ban: Report

Nvidia AI chips worth over $1 Billion smuggled into China Despite US ban: Report

Brand Marketing

Dutch antitrust watchdog hits pause on Apple dating app fees ruling

Dutch antitrust watchdog hits pause on Apple dating app fees ruling

Digital

Google rolls out web guide that uses AI to rethink search results

Google rolls out web guide that uses AI to rethink search results

Digital

Balaji Telefilms stock falls 5% as govt bans ALTT over obscene content

Balaji Telefilms stock falls 5% as govt bans ALTT over obscene content

Brand Makers

We are open to sharing our AI models with the Global South: S Krishnan, Secretary, MeitY

We are open to sharing our AI models with the Global South: S Krishnan, Secretary, MeitY