Microsoft Says Chinese Hackers Exploited SharePoint Flaws

SharePoint on laptop

SharePoint on In-House Servers Hacked

On July 22, 2025, Microsoft accused two Chinese nation-state actors, Linen Typhoon and Violet Typhoon, of exploiting flaws in the SharePoint document management software to target businesses and government agencies worldwide. Additionally, according to a company blog, another hacking group based in China, which Microsoft refers to as Storm-2603, also exploited the SharePoint vulnerabilities.

Just days before the announcement, the Microsoft Security Response Center (MSRC) issued a warning on July 19, alerting administrators to an active exploit campaign targeting vulnerabilities in SharePoint Server. Microsoft emphasized that these attacks affect only on-premises deployments of SharePoint and do not impact Microsoft 365’s SharePoint Online.

“This attack specifically targets organizations running SharePoint on their own in-house servers,” explained PrivaPlan CIO Ron Bebus. “Since PrivaPlan and the majority of our clients use SharePoint through Microsoft’s secure, cloud-hosted environment, we are not affected by this vulnerability.”

Why It Matters

Many other businesses and institutions using SharePoint on in-house servers to store and collaborate on documents have reportedly had their sign-in credentials stolen. A cybersecurity firm’s report reviewed by Bloomberg News states that hackers also breached the systems of a US-based healthcare provider and targeted a public university in Southeast Asia, although neither is named in the report.

This incident follows a pattern of Chinese state-sponsored cyber operations targeting critical infrastructure and sensitive sectors worldwide. In recent years, Microsoft has consistently tracked nation-state actors who have leveraged zero-day vulnerabilities to gain persistence within networks — often going undetected for months.

What’s Being Done

“Investigations into other actors also using these exploits is still ongoing,” Microsoft stated in its blog. “With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks.”

Microsoft has already released patches for affected SharePoint Server versions. However, the company is still working to deploy additional fixes to close gaps in older or less common configurations. According to the MSRC, the primary vulnerability allows attackers to execute arbitrary code remotely, gain elevated privileges, and move laterally across systems once they are inside.

Security experts recommend IT teams running SharePoint servers from their on-premise networks take the following immediate steps:

  • Apply Microsoft’s July 2025 security updates to all on-premises SharePoint servers.
  • Conduct a credential audit and reset any exposed or potentially compromised accounts.
  • Stay cyber secure and enable multi-factor authentication (MFA) where possible, especially for admin-level accounts.
  • Consider migrating from on-premises SharePoint to cloud-based Microsoft 365 for enhanced security and faster patch cycles.

Safeguard Your Data

We understand the criticality of safeguarding confidential information. That’s why we offer comprehensive Privacy Risk Assessments explicitly tailored for corporations, health care providers, and government agencies that handle vast amounts of personal and confidential data.

Related Posts

Access PrivaPlan Toolkit

Access CMA-PrivaPlan Toolkit

Stay Ahead of Privacy & Security Compliance

Sign Up for Our Newsletter!

Don’t miss the latest updates, tips, and best practices in privacy and security compliance! Join our email newsletter for:

  • Exclusive Insights: Gain access to vital news and expert insights from PrivaPlan experts.
  • Practical Tips: Learn actionable strategies to protect data privacy & enforce data security.

Sign up now and elevate your compliance game!

A Compliance First Guide focused on AI & the HIPAA Security Rule

Ensuring HIPAA Compliance in Generative AI Systems

Our new practical guide offers actionable strategies for establishing an AI system while focusing on the HIPAA Security Rule framework. It's built to help you:

Learn about Compliance!

Subscribe now for up-to-date information about privacy & security compliance! You’ll receive emails regarding news about compliance & alerts for new blog posts.