Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Exchange Server, saying they were being exploited by a group it called Hafnium. Other groups quickly joined in, and tens of thousands of servers worldwide were reported compromised.
What happened
- The flaws, collectively known as ProxyLogon, let attackers access email accounts and install web shells for long-term access.
- Microsoft said Hafnium was state-sponsored and operating from China; China denied involvement.
- Exploitation surged after the patches were released, with criminals and several state-linked groups scanning for unpatched servers.
- In July 2021 the UK, US, EU, and allies attributed the campaign to actors affiliated with China’s Ministry of State Security.
Why it mattered
The campaign showed how quickly exploitation spreads once a vulnerability becomes known, and it hit many smaller organisations still running their own mail servers.
Lessons for organisations
Patch internet-facing systems within days of critical fixes, hunt for signs of compromise rather than assuming a patch removes an intruder, and consider moving legacy on-premises services to managed platforms. Keep an up-to-date record of internet-facing services so that none are missed when urgent fixes are released.
Source: Microsoft
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.