Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2026 GBAF Publications Ltd - All Rights Reserved. | Sitemap | Tags | Developed By eCorpIT

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Headlines > Microsoft says some SharePoint server hackers now using ransomware
    Headlines

    Microsoft says some SharePoint server hackers now using ransomware

    Published by Global Banking & Finance Review®

    Posted on July 23, 2025

    2 min read

    Last updated: January 22, 2026

    Microsoft says some SharePoint server hackers now using ransomware - Headlines news and analysis from Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Tags:cybersecurityfinancial institutionstechnology

    Quick Summary

    Microsoft warns of ransomware linked to SharePoint server hacks, with over 400 victims including U.S. agencies, escalating cyber threats.

    Microsoft Warns of Ransomware Tied to SharePoint Server Hacks

    By Raphael Satter

    WASHINGTON (Reuters) -A cyber-espionage campaign centered on vulnerable versions of Microsoft's server software now involves the deployment of ransomware, Microsoft said in a late Wednesday blog post.

    In the post, citing "expanded analysis and threat intelligence," Microsoft said a group it dubs "Storm-2603" is using the vulnerability to seed the ransomware, which typically works by paralyzing victims' networks until a digital currency payment is made.

    The disclosure marks a potential escalation in the campaign, which has already hit at least 400 victims, according to Netherlands-based cybersecurity firm Eye Security. Unlike typical state-backed hacker campaigns, which are aimed at stealing data, ransomware can cause widespread disruption depending on where it lands.

    The figure of 400 victims represents a sharp rise from the 100 organizations cataloged over the weekend. Eye Security says the figure is likely an undercount.

    "There are many more, because not all attack vectors have left artifacts that we could scan for," said Vaisha Bernard, the chief hacker for Eye Security, which was among the first organizations to flag the breaches.

    The details of most of the victim organizations have not yet been fully disclosed, but on Wednesday a representative for the National Institutes of Health confirmed that one of the organization's servers had been compromised.

    "Additional servers were isolated as a precaution," he said. The news of the compromise was first reported by the Washington Post. 

    Other outlets said the hacking campaign had breached an even broader range of U.S. agencies. NextGov, citing multiple people familiar with the matter, reported the Department of Homeland Security had been hit, along with more than five to 12 other agencies.

    Politico, which cited two U.S. officials, said multiple agencies were believed to have been breached.

    DHS' cyberdefense arm, CISA, did not immediately return a message seeking comment on the reports. Microsoft did not immediately return a message seeking further details on the ransomware angle of the hacking or the reported government victims.

    The spy campaign began after Microsoft failed to fully patch a security hole in its SharePoint server software, kicking off a scramble to fix the vulnerability when it was discovered.

    Microsoft and its tech rival, Google-owner Alphabet, have both said Chinese hackers are among those taking advantage of the flaw. Beijing has denied the claim.

    (Reporting by Raphael Satter; Editing by Mark Porter and Christopher Cushing)

    Key Takeaways

    • •Microsoft identifies ransomware linked to SharePoint server vulnerabilities.
    • •Storm-2603 group exploits the flaw to deploy ransomware.
    • •Over 400 victims reported, including government agencies.
    • •Eye Security highlights potential undercount of affected organizations.
    • •Chinese hackers among those exploiting the vulnerability.

    Frequently Asked Questions about Microsoft says some SharePoint server hackers now using ransomware

    1What is the nature of the cyber-espionage campaign?

    The campaign centers on vulnerable versions of Microsoft's server software and now involves the deployment of ransomware by a group called 'Storm-2603'.

    2How many victims have been reported in the hacking campaign?

    At least 400 victims have been reported, a significant increase from the 100 organizations cataloged earlier.

    3What has been the response from the National Institutes of Health?

    A representative confirmed that one of their servers was compromised and additional servers were isolated as a precaution.

    4Which U.S. agency has been mentioned in connection with the breaches?

    The Department of Homeland Security has been reported to have been breached, along with multiple other agencies.

    5What did Microsoft say about the hackers exploiting the vulnerability?

    Microsoft and Alphabet have indicated that Chinese hackers are among those taking advantage of the security flaw in their SharePoint server software.

    More from Headlines

    Explore more articles in the Headlines category

    Image for WANTED: Volunteers to host nuclear waste, forever
    WANTED: Volunteers to host nuclear waste, forever
    Image for German exports rise more than expected, industrial production falls
    German exports rise more than expected, industrial production falls
    Image for LG Energy Solution to end Canada battery JV with Stellantis
    LG Energy Solution to end Canada battery JV with Stellantis
    Image for German exports rise 4% in December
    German exports rise 4% in December
    Image for Offshore developer Orsted Q4 core profit slightly lags forecast
    Offshore developer Orsted Q4 core profit slightly lags forecast
    Image for Hungary's deficit to be around 5% of GDP this year and next, Orban says
    Hungary's deficit to be around 5% of GDP this year and next, Orban says
    Image for Germany's Merz to visit Washington in March, Die Welt reports
    Germany's Merz to visit Washington in March, Die Welt reports
    Image for In Hasina’s hometown in Bangladesh, voters face an unfamiliar ballot
    In Hasina’s hometown in Bangladesh, voters face an unfamiliar ballot
    Image for SocGen lifts profit target as retail bank offsets trading drop
    SocGen lifts profit target as retail bank offsets trading drop
    Image for Germany's PNE loses bid for Vietnam wind project, in new blow to foreign investors
    Germany's PNE loses bid for Vietnam wind project, in new blow to foreign investors
    Image for Iran, US to negotiate in Oman amid deep rifts and mounting war fears
    Iran, US to negotiate in Oman amid deep rifts and mounting war fears
    Image for Oil set for first weekly decline in seven weeks ahead of US-Iran talks
    Oil set for first weekly decline in seven weeks ahead of US-Iran talks
    View All Headlines Posts
    Previous Headlines PostTakeaways of US-Japan deal include potential gains for Trump, Ishiba and EU
    Next Headlines PostExclusive-Chinese engines, shipped as 'cooling units', power Russian drones used in Ukraine