ALL NEWS

Here’s what we know so far about the massive Microsoft Exchange hack

Mar 10, 2021, 5:34 AM

KONSKIE, POLAND - JUNE 17, 2018: Signing in for a Microsoft account on a new modern smartphone...

KONSKIE, POLAND - JUNE 17, 2018: Signing in for a Microsoft account on a new modern smartphone

    (CNN) — Many security experts remain alarmed about the large, Chinese-linked hack of Microsoft’s Exchange email service a week after the attack was first reported.

The breach is believed to have targeted hundreds of thousands of Exchange users around the world. Microsoft said four vulnerabilities in its software allowed hackers to access servers for the popular email and calendar service, and the company urged customers to immediately update their on-premises systems with software fixes.

Even the White House quickly got involved, and now multiple US government agencies also are investigating the attack.

Since the hack was reported last Tuesday, “a large number” of additional threat actors “have been rushing to exploit these vulnerabilities” in Exchange servers that have not yet been updated, cybersecurity software firm Symantec said Monday, adding another layer of urgency to the situation and potentially leading to more victims.

“This is the real deal,” Christopher Krebs, former director of the US Cybersecurity and Infrastructure Security Agency (CISA), tweeted last week, encouraging Exchange server users to quickly respond to the issue.

Here’s what is known about the hack so far:

Who is behind it?

Microsoft attributed the attack to a network of hackers it calls Hafnium, a group the company “assessed to be state sponsored and operating out of China.” The “state-sponsored” actor was identified by the Microsoft Threat Intelligence Center based on observed “tactics and procedures,” according to the company.

Though Hafnium is believed to be based in China, it usually strikes using virtual private servers based in the United States, Microsoft said. The company referred to the group as “a highly skilled and sophisticated actor.”

A spokesperson for China’s Ministry of Foreign Affairs said that the country “firmly opposes and fights all forms of cyber-attacks and thefts in accordance with the law.”

It’s worth noting that the Microsoft Exchange hack is unrelated to the SolarWinds attack that the US government and businesses have been reeling from in recent months, which is suspected to be linked to Russia.

Who was targeted?

As of Saturday, there were an estimated 30,000 affected customers in the United States and 250,000 globally, though those numbers could increase, a US official told CNN.

The hack is mainly a concern for business and government customers that use Microsoft’s Exchange Server product. Microsoft said it has “no evidence that Hafnium’s activities targeted individual consumers or that these exploits impact other Microsoft products.”

It has said the cloud-based Exchange Online and Microsoft 365 products were not affected.

The types of victims so far identified by Microsoft and US government agencies include state and local governments, policy think tanks, academic institutions, infectious disease researchers and businesses such as law firms and defense contractors. Cybersecurity firm FireEye also said last week that it had identified multiple specific victims “including US-based retailers, local governments, a university and an engineering firm.”

What is the goal of the hack?

The attack gave hackers access to the email systems of targeted organizations. Once the Hafnium attackers compromise an organization, Microsoft said, they have been known to steal data such as emails and address books, and to gain access to its user account database.

One victim, a person working at a Washington think tank who was contacted by the FBI, said attackers had used the unauthorized access to email that person’s contacts in a way that looked legitimate. Each message included links asking people to click on them, the person told CNN on Friday.

Hackers could also install additional malware to facilitate ongoing, long-term access to victims’ systems, including files, inboxes and credentials stored there.

What is being done about it?

Microsoft last week released emergency security updates for customers using on-premises Exchange Server systems.

“We strongly encourage all Exchange Server customers to apply these updates immediately,” Microsoft said in a statement.

Microsoft released a tool that can help users detect related malicious activity. CISA, the US cybersecurity agency, advised network security officials to look for evidence of intrusions as far back as September 2020, and released an emergency directive on Tuesday requiring federal agencies to either update their servers or to disconnect them.

White House press secretary Jen Psaki and national security adviser Jake Sullivan also urged IT administrators nationwide to install the software fixes immediately.

The CISA last week warned that if not addressed, the malicious activity could “enable an attacker to gain control of an entire enterprise network.”

Biden administration is expected to form a task force involving multiple agencies — including the National Security Council, FBI, CISA and others — to address the hack.

“This has the potential to simultaneously affect organizations that are critical to everyday life in the US,” a source familiar with the US government investigation into the attack told CNN.

The-CNN-Wire
™ & © 2021 Cable News Network, Inc., a WarnerMedia Company. All rights reserved.

We want to hear from you.

Have a story idea or tip? Send it to the KSL NewsRadio team here.

All News

The second episode of The Letter's second season, "Ripple Effect," details the second man killed in...

Amy Donaldson

Sense of dread precedes second 1982 Millcreek Canyon murder

The second episode of The Letter's second season, "Ripple Effect," details the second man killed in a double murder outside a Millcreek Canyon restaurant in 1982. 

19 minutes ago

Columbia University students hold a protest in support of Palestinians, during the ongoing conflict...

Matt Egan, Chris Boyette, Shimon Prokupecz and Nic F. Anderson, CNN

Columbia University main campus classes will be hybrid until semester ends; NYU students, faculty arrested during protests

Columbia University, the epicenter of pro-Palestinian protests at US college campuses in recent days, says all classes at its main campus will be hybrid until the spring semester ends. 

7 hours ago

Actor Rain Wilson arrives at the Cinema for Peace benefit for the J/P Haitian Relief Organization i...

Emma Keddington

Rainn Wilson speaking at Weber State graduation, how much did it cost the school?

OGDEN, Utah — Weber State University is shelling out big bucks to have Rainn Wilson, also known as Dwight Schrute from “The Office,” speak at their graduation commencement on Friday. $125,000 to be exact. Weber State public relations manager Bryan Magaña said while expensive, this serves a higher purpose. The choice to bring in Rainn […]

8 hours ago

FBI agent Douglas Hart, right, testifies Monday about texts between Chad Daybell and Lori Vallow Da...

EMILY ASHCRAFT, KSL.COM

‘Angels are angry’: FBI agent describes ‘manipulating’ texts between Lori and Chad Daybell

BOISE — Jurors in the Chad Daybell murder trial heard testimony Monday from some key people in Lori Vallow Daybell’s life, and from an FBI agent who described “manipulative” texts between the couple. Colby Ryan, Lori Daybell’s oldest child, took deep breaths and some time from the witness stand before identifying photos of his sister, […]

9 hours ago

Volunteers gather at Pedal and Pick at Jordan Park in Salt Lake City on Saturday, April 20, 2024. P...

Mariah Maynes

How did April 22 become Earth Day?

20 million Americans took part in the first Earth Day in 1970. Nowadays, the event is a global affair.

11 hours ago

Richfield City police say the male driver of a utility task vehicle died of injuries he sustained a...

Simone Seikaly

Crash kills utility task vehicle driver in Richfield

Richfield City police said a crash between a utility task vehicle and a car ejected the UTV driver, who died of his injuries.

11 hours ago

Sponsored Articles

Young couple hugging while a realtor in a suit hands them keys in a new home...

Utah Association of Realtors

Buying a home this spring? Avoid these 5 costly pitfalls

By avoiding these pitfalls when buying a home this spring, you can ensure your investment will be long-lasting and secure.

a person dressed up as a nordic viking in a dragon boat resembling the bear lake monster...

Bear Lake Convention and Visitors Bureau

The Legend of the Bear Lake Monster

The Bear Lake monster has captivated people in the region for centuries, with tales that range from the believable to the bizarre.

...

Live Nation Concerts

All the artists coming to Utah First Credit Union Amphitheatre (formerly USANA Amp) this summer

Summer concerts are more than just entertainment; they’re a celebration of life, love, and connection.

Mother and cute toddler child in a little fancy wooden cottage, reading a book, drinking tea and en...

Visit Bear Lake

How to find the best winter lodging in Bear Lake, Utah

Winter lodging in Bear Lake can be more limited than in the summer, but with some careful planning you can easily book your next winter trip.

Happy family in winter clothing at the ski resort, winter time, watching at mountains in front of t...

Visit Bear Lake

Ski more for less: Affordable ski resorts near Bear Lake, Utah

Plan your perfect ski getaway in Bear Lake this winter, with pristine slopes, affordable tickets, and breathtaking scenery.

front of the Butch Cassidy museum with a man in a cowboy hat standing in the doorway...

Bear Lake Convention and Visitors Bureau

Looking Back: The History of Bear Lake

The history of Bear Lake is full of fascinating stories. At over 250,000 years old, the lake has seen generations of people visit its shores.

Here’s what we know so far about the massive Microsoft Exchange hack