Microsoft has publicly accused Chinese state-sponsored hacking groups of exploiting vulnerabilities in its SharePoint document management software to launch cyberattacks against large corporations, government agencies, and critical infrastructure worldwide.
On Tuesday, the US tech giant revealed that two China-linked groups—Linen Typhoon and Violet Typhoon—had taken advantage of a “spoofing” zero-day vulnerability to breach servers used by Microsoft customers. A third group, Storm-2603, was also identified as exploiting these weaknesses. These attacks primarily targeted customers operating on-premise SharePoint servers, while users of Microsoft’s cloud-based SharePoint service remained unaffected.
In response, Microsoft has released comprehensive security patches to address the flaw. “Investigations into other actors also using these exploits are still ongoing,” the company said in a statement. “With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks.”
The vulnerability was publicly disclosed on Sunday alongside the release of security updates. Prior reporting by the Washington Post and Bloomberg highlighted that the hack affected US federal and state agencies, universities, energy companies, as well as national governments in Europe and the Middle East.
Microsoft, a major federal contractor, has faced heightened scrutiny in recent years over cyberattacks on its systems. In 2023, Chinese state-backed hackers associated with Storm-0558 breached Microsoft Exchange Online, targeting US lawmakers.
The initial discovery of the SharePoint exploit was made last week by Netherlands-based cybersecurity firm Eye Security, which described the activity as a “co-ordinated mass exploitation campaign” affecting dozens of systems in countries including Saudi Arabia, Vietnam, Oman, and the United Arab Emirates.
CrowdStrike, a US cybersecurity company, noted a sharp increase in attacks following widespread disclosure of the vulnerability.
Despite SharePoint being used by more than 200 million customers as of 2020, the number of organizations using on-premise servers is smaller but remains a significant target for attackers.
Last year, the now-disbanded US Cyber Safety Review Board criticized Microsoft for “deprioritising both enterprise security investments and rigorous risk management,” calling for a cultural overhaul to improve cybersecurity resilience.
Microsoft has also faced criticism after a ProPublica investigation revealed that China-based engineers were involved in support roles for US Department of Defense contracts. Microsoft has since pledged to end such practices. Frank Shaw, Microsoft’s head of communications, stated on X (formerly Twitter) last week: “Microsoft has made changes to our support for US Government customers to assure that no China-based engineering teams are providing technical assistance for DoD Government cloud and related services.”
As Microsoft continues to fortify its defenses, cybersecurity experts warn that state-sponsored threat actors will persistently exploit vulnerabilities to target high-value corporate and government networks.

