- Hackers exploited a serious breach in SharePoint to infiltrate global systems, targeting governments, corporations, and universities.
- Microsoft identified China-linked groups as the primary culprits, although other criminal actors have also exploited the flaw.
- The patch released by Microsoft did not completely block the attacks, allowing persistent access even after updating.
- Dozens of high-profile organizations have been compromised, especially in the United States and Europe, as investigations continue.
In recent weeks, a wave of cyberattacks has targeted Microsoft software . Concern is growing among institutions and companies worldwide after a vulnerability was identified in SharePoint, the document management system widely used by government and private organizations. This flaw, classified as highly severe, has allowed unauthorized access to sensitive information in numerous countries.
Initial reports indicate that hundreds of servers have been compromised , affecting government agencies, educational institutions, and the private sector. The incident has prompted an immediate response from both authorities and Microsoft itself, which is attempting to contain the impact of this sophisticated attack.
A breach in SharePoint triggers the attack

During the month of July, several international cybersecurity teams detected a vulnerability in the SharePoint platform, used to store and share internal documents. The flaw allowed attackers to steal login credentials —including usernames, passwords, and encrypted data—and infiltrate the internal networks of high-profile organizations.
The vulnerability was classified as a "zero-day" vulnerability , meaning it was unknown and unfixable at the time it was exploited by the attackers. Initial investigations link the unauthorized access to hundreds of servers located in the US, Germany, the UK, Spain, Switzerland, Brazil, Canada, South Africa, and other regions.
Microsoft itself released a security patch attempting to close the vulnerability, but experts have warned that attackers have found ways to circumvent the corrective measures. In particular, techniques have been detected that allow backdoors to remain operational even after updates , guaranteeing hackers persistent access.
Actors and geopolitical implications
According to reports, the main groups identified after the attacks have been linked to the Chinese government . Microsoft has specifically identified these groups as Linen Typhoon, Violet Typhoon, and Storm-2603. These organizations are believed to have acted as part of an orchestrated cyberespionage campaign aimed at infiltrating government agencies, universities, hospitals, and strategic energy companies across several continents.
The matter has generated diplomatic tensions, as the Chinese Embassy denies any involvement and rejects accusations of a cyberattack, demanding conclusive evidence before making any judgments. Investigations are still underway, but cybersecurity sources and Western governments insist that the patterns used match tactics previously attributed to Chinese actors.
For their part, US entities such as the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) have confirmed that they are actively collaborating to contain the threat and limit the number of compromised organizations.
Microsoft's Scope and Reaction
The full extent of the impact remains uncertain , but direct effects have already been acknowledged on entities such as the U.S. Department of Education, the Florida Department of Finance, the Rhode Island General Assembly, and the agency responsible for the U.S. nuclear arsenal. Incidents have also been detected in Spain, the Middle East, and Asia, affecting everything from universities to energy companies.
Hundreds of organizations have been notified of the risk , and it is estimated that more than 10.000 servers could be exposed , according to experts consulted. The incident highlights the importance of strengthening cybersecurity culture and rapid response to vulnerabilities in critical software, especially when there are integrations with other Microsoft platforms such as Office, Teams, and OneDrive, which expands the attack surface.
Microsoft has reiterated its commitment to security and continues to develop new updates, although it acknowledges that the challenge is especially complex due to the depth of integration of its products.
Tactics and consequences of the attacks

The intrusion campaign has been characterized by its rapid spread and the use of sophisticated methods . The hackers have installed modified components and backdoors in the affected systems, allowing them to regain access even after server reboots or the application of patches.
Mass theft of credentials and the installation of malware capable of impersonating users and maintaining long-term access have also been detected . Among the techniques employed, the exploitation of zero-day vulnerabilities and the distribution of digital payloads to multiple victims across various sectors stand out.
Companies like CrowdStrike, Mandiant, and Eye Security have been key in detecting and analyzing the attack, warning about the possibility that more criminal groups may try to exploit the same vulnerability in the near future.
A constantly evolving global challenge

The global scale of this incident and the constant influx of new victims demonstrate the rapid escalation of cyberattacks targeting critical infrastructure . Investigations are ongoing, and observers suggest that groups other than those initially identified may exploit the same vulnerability while organizations complete their security measures.
Given the magnitude of the threat, authorities are urging all companies and departments that rely on self-hosted SharePoint servers to review access credentials and look for signs of suspicious activity. The persistence and creativity of attackers make it clear that cybersecurity is a marathon, not a sprint, where prevention remains the safest bet.

