Microsoft says some SharePoint server hackers now using ransomware

Published July 24, 2025
Microsoft signage is seen at the company’s headquarters in Redmond, Washington, US on January 18, 2023. — Reuters/File
Microsoft signage is seen at the company’s headquarters in Redmond, Washington, US on January 18, 2023. — Reuters/File

A cyber-espionage campaign centred on vulnerable versions of Microsoft’s server software now involves the deployment of ransomware, Microsoft said in a late Wednesday blog post.

In the post, citing “expanded analysis and threat intelligence”, Microsoft said a group it dubs “Storm-2603” is using the vulnerability to seed the ransomware, which typically works by paralysing victims’ networks until a digital currency payment is made.

The disclosure marks a potential escalation in the campaign, which has already hit at least 400 victims, according to Netherlands-based cybersecurity firm Eye Security.

Unlike typical state-backed hacker campaigns, which are aimed at stealing data, ransomware can cause widespread disruption depending on where it lands.

The figure of 400 victims represents a sharp rise from the 100 organisations catalogued over the weekend. Eye Security says the figure is likely an undercount.

“There are many more, because not all attack vectors have left artefacts that we could scan for,” said Vaisha Bernard, the chief hacker for Eye Security, which was among the first organisations to flag the breaches.

The details of most of the victim organisations have not yet been fully disclosed, but on Wednesday, a representative for the National Institutes of Health confirmed that one of the organisation’s servers had been compromised.

“Additional servers were isolated as a precaution,” he said. The news of the compromise was first reported by the Washington Post.

Other outlets said the hacking campaign had breached an even broader range of US agencies. NextGov, citing multiple people familiar with the matter, reported the Department of Homeland Security had been hit, along with more than five to 12 other agencies.

Politico, which cited two US officials, said multiple agencies were believed to have been breached.

DHS’ cyberdefense arm, CISA, did not immediately return a message seeking comment on the reports. Microsoft did not immediately return a message seeking further details on the ransomware angle of the hacking or the reported government victims.

The spy campaign began after Microsoft failed to fully patch a security hole in its SharePoint server software, kicking off a scramble to fix the vulnerability when it was discovered.

Microsoft and its tech rival, Google-owner Alphabet, have both said Chinese hackers are among those taking advantage of the flaw. Beijing has denied the claim.

Opinion

Editorial

Unquiet Lebanon
Updated 21 Jun, 2026

Unquiet Lebanon

Either Israel must silence its guns and withdraw from all of Lebanon, or face isolation and boycott from the international community.
Mothers at risk
21 Jun, 2026

Mothers at risk

FOR years, efforts to reduce maternal deaths have focused heavily on postpartum haemorrhage — the severe bleeding...
Political budget
21 Jun, 2026

Political budget

THE KP budget does not read like a document of a province getting its fiscal house in order. Revenue is projected at...
Pakistan’s moment
Updated 20 Jun, 2026

Pakistan’s moment

Pakistan’s diplomats are second to none, and if these states seek to engage this country constructively, a new modus vivendi for the subcontinent can be reached.
Menacing water plans
20 Jun, 2026

Menacing water plans

IN April last year, India suspended the decades-old Indus Waters Treaty, which contains no provision allowing it to...
World Refugee Day
20 Jun, 2026

World Refugee Day

WORLD Refugee Day, observed today around the globe, marks 75 years since the adoption of the 1951 convention ...