Chinese Hackers Target UK Nuclear Via Sharepoint Flaw
Chinese Hackers Target UK Nuclear Via Sharepoint Flaw

Chinese state-backed hackers have exploited security vulnerabilities in Microsoft's SharePoint servers, breaching hundreds of organisations worldwide, including a US nuclear weapons agency. The attacks, which began as early as 7 July, target on-premises SharePoint systems used by governments and businesses for document collaboration.

Microsoft identified three hacking groups—Linen Typhoon, Violet Typhoon, and Storm-2603—exploiting flaws to spoof authentication credentials and execute malicious code remotely. The company warned that unpatched systems remain at high risk of further attacks.

Dutch cybersecurity firm Eye Security reported that over 400 agencies, businesses, and organisations have been breached, with the majority in the US. Bloomberg reported that the National Nuclear Security Administration, which oversees US nuclear weapons, was among the victims. The UK's nuclear sector is also believed to be at risk, though no specific breaches have been confirmed.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Microsoft has released security updates and urged all users of on-premises SharePoint servers to install them immediately. The company assessed with high confidence that the hacking groups will continue targeting unpatched systems.

The attacks come amid heightened geopolitical tensions between the US and China, with US tech firms like Amazon and McKinsey scaling back AI operations in China. Microsoft and IBM have also reduced China-based research projects.

Pickt after-article banner — collaborative shopping lists app with family illustration