Security News > 2021 > July > US and allies officially accuse China of Microsoft Exchange attacks

US and allies, including the European Union, the United Kingdom, and NATO, are officially blaming China for this year's widespread Microsoft Exchange hacking campaign.
The Biden administration attributes "With a high degree of confidence that malicious cyber actors affiliated with PRC's MSS conducted cyber espionage operations utilizing the zero-day vulnerabilities in Microsoft Exchange Server disclosed in early March 2021.".
"The attack on Microsoft Exchange software was highly likely to enable large-scale espionage, including acquiring personally identifiable information and intellectual property," the UK National Cyber Security Centre also said today.
"The attack on Microsoft Exchange servers is another serious example of a malicious act by Chinese state-backed actors in cyberspace," the EU and its Member States added in a separate statement issued today.
In early March 2021, Microsoft disclosed four zero-days actively being exploited in attacks targeting on-premises Microsoft Exchange servers.
After Microsoft disclosed the attacks, Slovak internet security firm ESET discovered at least ten APT groups targeting vulnerable Exchange servers.
News URL
Related news
- US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks (source)
- China names alleged US snoops over Asian Winter Games attacks (source)
- China’s FamousSparrow flies back into action, breaches US org after years off the radar (source)
- Microsoft Warns of Tax-Themed Email Attacks Using PDFs and QR Codes to Deliver Malware (source)
- Microsoft investigates global Exchange Admin Center outage (source)
- Infosec experts fear China could retaliate against tariffs with a Typhoon attack (source)
- Ex-Meta exec tells Senate Zuck dangled US citizen data in bid to enter China (source)
- Microsoft Defender will isolate undiscovered endpoints to block attacks (source)
- China reportedly admitted directing cyberattacks on US infrastructure (source)
- Microsoft: Exchange 2016 and 2019 reach end of support in six months (source)