Don’t do SECURITY. Do business SECURELY.

Microsoft Exchange zero-days exploited in mass hacking campaign

Microsoft patches four Exchange Server zero-days exploited by a group it calls Hafnium, leading to tens of thousands of compromised servers.

Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Exchange Server, saying they were being exploited by a group it called Hafnium. Other groups quickly joined in, and tens of thousands of servers worldwide were reported compromised.

What happened

  • The flaws, collectively known as ProxyLogon, let attackers access email accounts and install web shells for long-term access.
  • Microsoft said Hafnium was state-sponsored and operating from China; China denied involvement.
  • Exploitation surged after the patches were released, with criminals and several state-linked groups scanning for unpatched servers.
  • In July 2021 the UK, US, EU, and allies attributed the campaign to actors affiliated with China’s Ministry of State Security.

Why it mattered

The campaign showed how quickly exploitation spreads once a vulnerability becomes known, and it hit many smaller organisations still running their own mail servers.

Lessons for organisations

Patch internet-facing systems within days of critical fixes, hunt for signs of compromise rather than assuming a patch removes an intruder, and consider moving legacy on-premises services to managed platforms. Keep an up-to-date record of internet-facing services so that none are missed when urgent fixes are released.

Source: Microsoft

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights