Security News > 2021 > July > US and allies officially accuse China of Microsoft Exchange attacks
US and allies, including the European Union, the United Kingdom, and NATO, are officially blaming China for this year's widespread Microsoft Exchange hacking campaign.
The Biden administration attributes "With a high degree of confidence that malicious cyber actors affiliated with PRC's MSS conducted cyber espionage operations utilizing the zero-day vulnerabilities in Microsoft Exchange Server disclosed in early March 2021.".
"The attack on Microsoft Exchange software was highly likely to enable large-scale espionage, including acquiring personally identifiable information and intellectual property," the UK National Cyber Security Centre also said today.
"The attack on Microsoft Exchange servers is another serious example of a malicious act by Chinese state-backed actors in cyberspace," the EU and its Member States added in a separate statement issued today.
In early March 2021, Microsoft disclosed four zero-days actively being exploited in attacks targeting on-premises Microsoft Exchange servers.
After Microsoft disclosed the attacks, Slovak internet security firm ESET discovered at least ten APT groups targeting vulnerable Exchange servers.
News URL
Related news
- Microsoft: Exchange 2016 reaches extended end of support in October (source)
- Microsoft fixes 6 zero-days under active attack (source)
- China-Backed Earth Baku Expands Cyber Attacks to Europe, Middle East, and Africa (source)
- Is Lenovo a blind spot in US anti-China security measures? (source)
- Microsoft: Exchange Online mistakenly tags emails as malware (source)
- Novel attack on Windows spotted in phishing campaign run from and targeting China (source)
- Iran Cyber Attack: Fox Kitten Facilitates Ransomware in US (source)
- Microsoft says it broke some Windows 10 patching – as it fixes flaws under attack (source)
- US proposes ban on connected vehicle tech from China, Russia (source)
- China's Salt Typhoon cyber spies are deep inside US ISPs (source)