{"id":832796,"date":"2025-07-24T09:15:24","date_gmt":"2025-07-24T07:15:24","guid":{"rendered":"https:\/\/businesstech.co.za\/news\/?p=832796"},"modified":"2025-07-24T09:15:30","modified_gmt":"2025-07-24T07:15:30","slug":"national-treasury-exposed-to-malware-in-major-microsoft-security-breach","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/it-services\/832796\/national-treasury-exposed-to-malware-in-major-microsoft-security-breach\/","title":{"rendered":"National Treasury exposed to malware in major Microsoft security breach"},"content":{"rendered":"\n<p>The number of companies and organizations compromised by a security vulnerability in Microsoft Corp.\u2019s SharePoint servers is increasing rapidly, with the tally of victims soaring more than six-fold in a few days, according to one research firm.<\/p>\n\n\n\n<p>Hackers have breached about 400 government agencies, corporations and other groups, according to estimates from Eye Security, the Dutch cybersecurity company that identified an early wave of the attacks last week. <\/p>\n\n\n\n<p>That\u2019s up from roughly 60 based on its previous estimate provided to Bloomberg News on Tuesday.<\/p>\n\n\n\n<p>The security firm said that most of the victims are in the US, followed by Mauritius, Jordan, South Africa and the Netherlands. <\/p>\n\n\n\n<p>The National Nuclear Security Administration, the US agency responsible for maintaining and designing the nation\u2019s cache of nuclear weapons, was among those breached, Bloomberg reported earlier.\u00a0<\/p>\n\n\n\n<p>The National Institutes of Health was also impacted through the SharePoint flaws, according to a person familiar with the matter. <\/p>\n\n\n\n<p>Andrew Nixon, a spokesperson for the Department of Health and Human Services, said, \u201cThe Department and its security teams are actively engaged in monitoring, identifying, and mitigating all risks to our IT systems posed by the Microsoft SharePoint vulnerability.\u201d<\/p>\n\n\n\n<p>\u201cAt present, we have no indication that any information was breached as a result of this vulnerability,\u201d he said, adding that the department is collaborating with Microsoft and the US Cybersecurity and Infrastructure Security Agency. <\/p>\n\n\n\n<p>The Washington Post previously reported that NIH was breached.<\/p>\n\n\n\n<p>And South Africa\u2019s National Treasury said it was seeking help from Microsoft after discovering malware on its network, but added that its systems and websites were operating normally.<\/p>\n\n\n\n<p>The hacks are among the latest major breaches that Microsoft has blamed, at least in part, on China and come amid heightened tensions between Washington and Beijing over global security and trade. <\/p>\n\n\n\n<p>The US has repeatedly criticized China for campaigns that have allegedly stolen government and corporate secrets over a period spanning decades.<\/p>\n\n\n\n<p>The real number of victims from the SharePoint exploits \u201cmight be much higher as there can be many more hidden ways to compromise servers that do not leave traces,\u201d Eye Security\u2019s co-owner Vaisha Bernard said in an email to Bloomberg News. <\/p>\n\n\n\n<p>\u201cThis is still developing, and other opportunistic adversaries continue to exploit vulnerable servers.\u201d<\/p>\n\n\n\n<p>The organizations compromised in the SharePoint breaches include many working in government, education and technology services, Bernard said. There were smaller numbers of victims in countries across Europe, Asia, the Middle East and South America.<\/p>\n\n\n\n<p>State-backed hackers tend to exploit major cybersecurity weaknesses, like the SharePoint vulnerability, in waves, according to Sveva Scenarelli, a threat analyst with Recorded Future Inc. <\/p>\n\n\n\n<p>They start with secretive, targeted hacks and then, once the vulnerability is discovered, will begin using it more indiscriminately, she said.<\/p>\n\n\n\n<p>\u201cOnce access has been acquired, individual threat groups can then triage compromised organizations, and prioritize those of particular interest for follow-on activity,\u201d said Scenarelli, of the cyber intelligence firm\u2019s Insikt Group. <\/p>\n\n\n\n<p>She said this can include finding ways to maintain access to a compromised network, burrowing deeper and setting up paths to steal sensitive information.<\/p>\n\n\n\n<p>US Treasury Secretary Scott Bessent, who is set to meet his Chinese counterparts in Stockholm next week for a\u00a0<a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2025-07-22\/bessent-to-attend-us-china-trade-talks-in-stockholm-next-week\" target=\"_blank\" rel=\"noreferrer noopener\">third round<\/a>\u00a0of trade talks, suggested in a Bloomberg Television interview Wednesday that the SharePoint hacks will be discussed.<\/p>\n\n\n\n<p>\u201cObviously things like that will be on the agenda with my Chinese counterparts,\u201d he said.<\/p>\n\n\n\n<p>The security flaws allow hackers to access SharePoint servers and steal keys that can let them impersonate users or services, potentially enabling deep access into compromised networks to steal confidential data.<\/p>\n\n\n\n<p>Microsoft has issued patches to fix the vulnerabilities, but researchers cautioned that hackers may have already got a foothold into many servers.<\/p>\n\n\n\n<p>Microsoft on Tuesday accused Chinese state-sponsored hackers known as Linen Typhoon and Violet Typhoon of being behind the attacks. Another hacking group based in China, which Microsoft calls Storm-2603, also exploited them, according to the company.<\/p>\n\n\n\n<p>The Redmond, Washington company has repeatedly blamed China for major cyberattacks. In 2021, an alleged Chinese operation compromised tens of thousands of Microsoft Exchange servers. <\/p>\n\n\n\n<p>In 2023, another alleged Chinese attack on Microsoft Exchange compromised senior US officials\u2019 email accounts. A US government review later\u00a0<a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2025-03\/CSRBReviewOfTheSummer2023MEOIntrusion508.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">accused<\/a>\u00a0Microsoft of a \u201ccascade of security failures\u201d over the 2023 incident.<\/p>\n\n\n\n<p>Eugenio Benincasa, a researcher at ETH Zurich\u2019s Center for Security Studies who specializes in analyzing Chinese cyberattacks, said members of the groups identified by Microsoft had previously been indicted in the US for their alleged involvement in hacking campaigns targeting US organizations. <\/p>\n\n\n\n<p>They are well known for their \u201cextensive espionage,\u201d he said.\u00a0<\/p>\n\n\n\n<p>It\u2019s likely that the SharePoint breaches are being carried out by proxy groups that work with the government rather than Chinese government agencies directly carrying out the hacking, according to Benincasa. <\/p>\n\n\n\n<p>Private hacking companies in the country sometimes participate in \u201chacker for hire\u201d operations, he added.\u00a0<\/p>\n\n\n\n<p>\u201cNow that at least three groups have reportedly exploited the same vulnerability, it\u2019s plausible more could follow,\u201d he said.<\/p>\n\n\n\n<p>\u201cCybersecurity is a common challenge faced by all countries and should be addressed jointly through dialogue and cooperation,\u201d said Chinese Foreign Ministry spokesman Guo Jiakun.<\/p>\n\n\n\n<p> \u201cChina opposes and fights hacking activities in accordance with the law. At the same time, we oppose smears and attacks against China under the excuse of cybersecurity issues.\u201d<\/p>\n\n\n\n<p>According to Microsoft, the hacking group Linen Typhoon was first identified in 2012, and is focused on stealing intellectual property, primarily targeting organizations related to government, defense, strategic planning, and human rights. <\/p>\n\n\n\n<p>Violet Typhoon, first observed in 2015, was \u201cdedicated to espionage\u201d and primarily targeted former government and military personnel, non-governmental organizations, as well as media and education sectors in the US, Europe, and East Asia.\u00a0<\/p>\n\n\n\n<p>The hackers have also used the SharePoint flaws to break into systems belonging to the US Education Department, Florida\u2019s Department of Revenue and the Rhode Island General Assembly, Bloomberg previously&nbsp;<a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2025-07-23\/us-nuclear-weapons-agency-breached-in-microsoft-sharepoint-hack\" target=\"_blank\" rel=\"noreferrer noopener\">reported<\/a>.<\/p>\n\n\n\n<p>Edwin Lyman, director of nuclear power safety for the Union of Concerned Scientists, said that while the National Nuclear Security Administration possesses some of the most restricted and dangerous information in the world, the networks where classified information are stored are isolated from the internet.&nbsp;<\/p>\n\n\n\n<p>\u201cSo even if those networks were compromised, I\u2019m not sure how such information could have been transmitted to the adversaries,\u201d Lyman said in an email. <\/p>\n\n\n\n<p>\u201cBut there are other categories of information that are sensitive but unclassified, that may be treated with less care and might have been exposed. This includes some information related to nuclear materials and even nuclear weapons.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The number of companies and organizations compromised by a security vulnerability in Microsoft&#8217;s SharePoint servers is increasing rapidly, including South Africa&#8217;s National Treasury.<\/p>\n","protected":false},"author":59,"featured_media":805644,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[169,3796],"class_list":["post-832796","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it-services","tag-microsoft","tag-national-treasury"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/832796","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/59"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=832796"}],"version-history":[{"count":1,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/832796\/revisions"}],"predecessor-version":[{"id":832797,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/832796\/revisions\/832797"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/805644"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=832796"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=832796"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=832796"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}