Skip to content
South African Live
Menu
  • Home
  • Entertainment
  • Politics
  • Fashion
  • Sports
  • Tech
  • Business
  • About us
Menu

SharePoint zero-day attackers now using ransomware

Posted on July 24, 2025
44

SharePoint zero-day attackers now deploying ransomwareA cyber-espionage campaign centred on vulnerable versions of Microsoft’s server software now involves the deployment of ransomware, Microsoft said in a late Wednesday blog post.

In the post, citing “expanded analysis and threat intelligence”, Microsoft said a group it dubs “Storm-2603” is using the vulnerability to seed the ransomware, which typically works by paralysing victims’ networks until a digital currency payment is made.

The disclosure marks a potential escalation in the campaign, which has already hit at least 400 victims, according to Netherlands-based cybersecurity firm Eye Security. Unlike typical state-backed hacker campaigns, which are aimed at stealing data, ransomware can cause widespread disruption depending on where it lands.

The disclosure marks a potential escalation in the campaign, which has already hit at least 400 victims

The figure of 400 victims represents a sharp rise from the 100 organisations cataloged over the weekend. Eye Security says the figure is likely an undercount.

“There are many more, because not all attack vectors have left artifacts that we could scan for,” said Vaisha Bernard, the chief hacker for Eye Security, which was among the first organisations to flag the breaches.

The details of most of the victim organisations have not yet been fully disclosed, but on Wednesday a representative for the National Institutes of Health confirmed that one of the organisation’s servers had been compromised.

“Additional servers were isolated as a precaution,” he said.

Breached

Other outlets said the hacking campaign had breached an even broader range of US agencies. NextGov, citing multiple people familiar with the matter, reported the department of homeland security had been hit, along with more than five to 12 other agencies.

Politico, which cited two US officials, said multiple agencies were believed to have been breached.

Read: SharePoint zero-day impact ripples around the world

DHS’s cyberdefence arm, CISA, did not immediately return a message seeking comment on the reports. Microsoft did not immediately return a message seeking further details on the ransomware angle of the hacking or the reported government victims.

RansomwareThe spy campaign began after Microsoft failed to fully patch a security hole in its SharePoint server software, kicking off a scramble to fix the vulnerability when it was discovered.

Microsoft and its tech rival, Google, have both said Chinese hackers are among those taking advantage of the flaw. Beijing has denied the claim.  — Raphael Satter, (c) 2025 Reuters

Get breaking news from TechCentral on WhatsApp. Sign up here.

Don’t miss:

South Africa among countries targeted in Microsoft SharePoint attacks

Recent Posts

  • Portsmouth snap up Bafana midfielder
  • Top 10 youngest billionaires of 2025, according to Forbes
  • Simphiwe Dana on people stealing from her
  • Gospel star Rebecca Malope scores R1m after suing detergent brand
  • Thembi Kgatlana opens up about her absence from Banyana Banyana squad for WAFCON 2024

First established in 2020 by iReport Media Group, southafricanlive.co.za has evolved to become one of the most-read websites in South Africa. Published by iReport Media Group since 2020, find out all about us right here.

We bring you the latest breaking news updates, from South Africa and the African continent. South African Live is an independent, no agenda and no bias online news disruptor that goes beyond the news and behind the headlines. We believe what sets us apart is that we deliver news differently. While we hold ourselves to the utmost journalistic integrity of being truthful, we encourage a writing style that is acerbic and conversational, when appropriate.

LATEST NEWS

  • Portsmouth snap up Bafana midfielder
  • Top 10 youngest billionaires of 2025, according to Forbes
  • Simphiwe Dana on people stealing from her
  • Gospel star Rebecca Malope scores R1m after suing detergent brand
  • Thembi Kgatlana opens up about her absence from Banyana Banyana squad for WAFCON 2024

Menu

  • Entertainment
  • Business
  • Politics
  • Tech
  • Fashion
  • Sports
  • About us
©2025 South African Live | Design: Newspaperly WordPress Theme