• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Gen Zers are arriving at college unable to even read a sentence—professors warn it could lead to a generation of anxious and lonely graduates

2

'We didn’t see this coming': Wall Street eats its forecasts as stocks sell off globally on fear of AI bubble ahead of SpaceX IPO

3

'The golden years are not golden': Boomers are hoarding most of America's wealth and power because they're terrified of outliving their money

1

Gen Zers are arriving at college unable to even read a sentence—professors warn it could lead to a generation of anxious and lonely graduates

2

'We didn’t see this coming': Wall Street eats its forecasts as stocks sell off globally on fear of AI bubble ahead of SpaceX IPO

3

'The golden years are not golden': Boomers are hoarding most of America's wealth and power because they're terrified of outliving their money
Tech

Thousands of businesses around the globe hit by Microsoft email hack attack

By
Bloomberg
Bloomberg
,
William Turton
William Turton
, and
Jordan Robertson
Jordan Robertson
Down Arrow Button Icon
By
Bloomberg
Bloomberg
,
William Turton
William Turton
, and
Jordan Robertson
Jordan Robertson
Down Arrow Button Icon
March 8, 2021, 4:47 AM ET

A sophisticated attack on Microsoft Corp.’s widely used business email software is morphing into a global cybersecurity crisis, as hackers race to infect as many victims as possible before companies can secure their computer systems.

The attack, which Microsoft has said started with a Chinese government-backed hacking group, has so far claimed at least 60,000 known victims globally, according to a former senior U.S. official with knowledge of the investigation. Many of them appear to be small or medium-sized businesses caught in a wide net the attackers cast as Microsoft worked to shut down the hack.

The European Banking Authority became one of the latest victims as it said Sunday that access to personal data through emails held on the Microsoft server may have been compromised. Others identified so far include banks and electricity providers, as well as senior citizen homes and an ice cream company, according to Huntress, a Ellicott City, Maryland-based firm that monitors the security of customers, in a blog post Friday.

One U.S. cybersecurity company which asked not to be named said its experts alone were working with at least 50 victims, trying to quickly determine what data the hackers may have taken while also trying to eject them.

The rapidly escalating attack came months after the SolarWinds Corp. breaches by suspected Russian cyberattackers, and drew the concern of U.S. national security officials in part because the latest hackers were able to hit so many victims so quickly. Researchers say in the final phases of the attack, the perpetrators appeared to have automated the process, scooping up tens of thousands of new victims around the world in a matter of days.

Washington responds

Washington is preparing its first major moves in retaliation against foreign intrusions over the next three weeks, the New York Times reported, citing unidentified officials. It plans a series of clandestine actions across Russian networks — intended to send a message to Vladimir Putin and his intelligence services — combined with economic sanctions. President Joe Biden could issue an executive order to shore up federal agencies against Russian hacking, the newspaper reported.

“We are undertaking a whole of government response to assess and address the impact,” a White House official wrote in an email on Saturday. “This is an active threat still developing and we urge network operators to take it very seriously.”

The Chinese hacking group, which Microsoft calls Hafnium, appears to have been breaking into private and government computer networks through the company’s popular Exchange email software for a number of months, initially targeting only a small number of victims, according to Steven Adair, head of the northern Virginia-based Volexity. The cybersecurity company helped Microsoft identify the flaws being used by the hackers for which the software giant issued a fix on Tuesday.

The result is a second cybersecurity crisis coming just months after suspected Russian hackers breached nine federal agencies and at least 100 companies through tampered updates from IT management software maker SolarWinds LLC. Cybersecurity experts that defend the world’s computer systems expressed a growing sense of frustration and exhaustion.

Washington is preparing its first major moves in retaliation against foreign intrusions over the next three weeks, the New York Times reported, citing unidentified officials. It plans a series of clandestine actions across Russian networks — intended to send a message to Vladimir Putin and his intelligence services — combined with economic sanctions. President Joe Biden could issue an executive order to shore up federal agencies against Russian hacking, the newspaper reported.

“We are undertaking a whole of government response to assess and address the impact,” a White House official wrote in an email on Saturday. “This is an active threat still developing and we urge network operators to take it very seriously.”

Hafnium

The Chinese hacking group, which Microsoft calls Hafnium, appears to have been breaking into private and government computer networks through the company’s popular Exchange email software for a number of months, initially targeting only a small number of victims, according to Steven Adair, head of the northern Virginia-based Volexity. The cybersecurity company helped Microsoft identify the flaws being used by the hackers for which the software giant issued a fix on Tuesday.

The result is a second cybersecurity crisis coming just months after suspected Russian hackers breached nine federal agencies and at least 100 companies through tampered updates from IT management software maker SolarWinds LLC. Cybersecurity experts that defend the world’s computer systems expressed a growing sense of frustration and exhaustion.

The good guys are getting tired,” said Charles Carmakal, a senior vice president at FireEye Inc., the Milpitas, California-based cybersecurity company.

Asked about Microsoft’s attribution of the attack to China, a Chinese foreign ministry spokesman said Wednesday that the country “firmly opposes and combats cyber attacks and cyber theft in all forms” and suggested that blaming a particular nation was a “highly sensitive political issue.”

Both the most recent incident and the SolarWinds attack show the fragility of modern networks and sophistication of state-sponsored hackers to identify hard-to-find vulnerabilities or even create them to conduct espionage. They also involve complex cyberattacks, with an initial blast radius of large numbers of computers which is then narrowed as the attackers focus their efforts, which can take affected organizations weeks or months to resolve.

In the case of the Microsoft bugs, simply applying the company-provided updates won’t remove the attackers from a network. A review of affected systems is required, Carmakal said. And the White House emphasized the same thing, including tweets from the National Security Council urging the growing list of victims to carefully comb through their computers for signs of the attackers.

Initially, the Chinese hackers appeared to be targeting high value intelligence targets in the U.S., Adair said. About a week ago, everything changed. Other unidentified hacking groups began hitting thousands of victims over a short period, inserting hidden software that could give them access later, he said.

Adair said that other hacking groups may have found the same flaws and began their own attacks — or that China may have wanted to capture as many victims as possible, then sort out which had intelligence value.

Either way, the attacks were so successful — and so rapid — that the hackers appear to have found a way to automate the process. “If you are running an Exchange server, you most likely are a victim,” he said.

Data from other security companies suggest that the scope of the attacks may not end up being quite that bad. Researchers from Huntress examined about 3,000 vulnerable servers on its partners’ networks and found about 350 infections — or just over 10%.

While the SolarWinds hackers infected organizations of all sizes, many of the latest batch of victims are small-to medium-sized business and local government agencies. Organizations that could be most impacted are those that have an email server that’s running the vulnerable software and exposed directly to the internet, a risky setup that larger ones usually avoid.

Smaller organizations are “struggling already due to Covid shutdowns — this exacerbates an already bad situation,” said Jim McMurry, founder of Milton Security Group Inc., a cybersecurity monitoring service in Southern California. “I know from working with a few customers that this is consuming a great deal of time to track down, clean and ensure they were not affected outside of the initial attack vector.”

McMurry said the issue is “very bad” but added that the damage should be mitigated somewhat by the fact that “this was patchable, it was fixable.”

Microsoft said customers that use its cloud-based email system are not affected.

The use of automation to launch very sophisticated attacks may mark a new, frightening era in cybersecurity, one that could overwhelm the limited resources of defenders, several experts said.

Some of the initial infections appear to have been the result of automated scanning and installation of malware, said Alex Stamos, a cybersecurity consultant. Investigators will be looking for infections that led to hackers taking the next step and stealing data — such as e-mail archives -– and searching them for any valuable information later, he said.

“If I was running one of these teams, I would be pulling down email as quickly as possible indiscriminately and then mining them for gold,” Stamos said.

About the Authors
By Bloomberg
See full bioRight Arrow Button Icon
By William Turton
See full bioRight Arrow Button Icon
By Jordan Robertson
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Brian Schimpf gestures with both hands as he speaks on stage.
Startups & VentureBrainstorm Tech
Anduril CEO Brian Schimpf says economic warfare is the ‘new normal’ for military conflicts—and the U.S. needs to get serious
By Lily Mae LazarusJune 8, 2026
3 hours ago
Pentagon accuses Alibaba, Baidu and BYD, three of China’s biggest companies, of supporting the Chinese military
AsiaAlibaba Group
Pentagon accuses Alibaba, Baidu and BYD, three of China’s biggest companies, of supporting the Chinese military
By Kate O'Keeffe and BloombergJune 8, 2026
4 hours ago
Twitch CEO: Social media has become ‘antisocial’ and can’t match the shared, human connection of livestreaming
Big TechBrainstorm Tech
Twitch CEO: Social media has become ‘antisocial’ and can’t match the shared, human connection of livestreaming
By Sebastian HerreraJune 8, 2026
4 hours ago
Two men sitting on chairs on a stage
Future of WorkBrainstorm Tech
Your career needs a ‘gym membership’ to keep up with continuous AI advancements, says Campus founder Tade Oyerinde
By Amanda GerutJune 8, 2026
5 hours ago
ChatGPT maker OpenAI confidentially files for IPO, a week after Anthropic
Startups & VentureOpenAI
ChatGPT maker OpenAI confidentially files for IPO, a week after Anthropic
By Bloomberg, Shirin Ghaffary and Bailey LipschultzJune 8, 2026
5 hours ago
Anthropic’s Boris Cherny, creator of Claude Code, says there are days he manages tens of thousands of AI agents at once
AIBrainstorm Tech
Anthropic’s Boris Cherny, creator of Claude Code, says there are days he manages tens of thousands of AI agents at once
By Sharon GoldmanJune 8, 2026
6 hours ago

Most Popular

Gen Zers are arriving at college unable to even read a sentence—professors warn it could lead to a generation of anxious and lonely graduates
Success
Gen Zers are arriving at college unable to even read a sentence—professors warn it could lead to a generation of anxious and lonely graduates
By Preston ForeJune 7, 2026
2 days ago
'We didn’t see this coming': Wall Street eats its forecasts as stocks sell off globally on fear of AI bubble ahead of SpaceX IPO
Economy
'We didn’t see this coming': Wall Street eats its forecasts as stocks sell off globally on fear of AI bubble ahead of SpaceX IPO
By Jim EdwardsJune 8, 2026
18 hours ago
'The golden years are not golden': Boomers are hoarding most of America's wealth and power because they're terrified of outliving their money
Economy
'The golden years are not golden': Boomers are hoarding most of America's wealth and power because they're terrified of outliving their money
By Nick LichtenbergJune 7, 2026
2 days ago
Current price of oil as of June 8, 2026
Personal Finance
Current price of oil as of June 8, 2026
By Joseph HostetlerJune 8, 2026
14 hours ago
Trump stunned as stocks fall on great jobs report. Barclays explains why ‘we are entering the warning zone'
Big Tech
Trump stunned as stocks fall on great jobs report. Barclays explains why ‘we are entering the warning zone'
By Eva RoytburgJune 7, 2026
1 day ago
SpaceX's IPO will also be a massive selling event triggering big price dislocations across the stock market as investors dump shares to buy SPCX
Investing
SpaceX's IPO will also be a massive selling event triggering big price dislocations across the stock market as investors dump shares to buy SPCX
By Jason MaJune 7, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.