Beautiful Virgin Islands

Saturday, Aug 01, 2026

The Microsoft Exchange hack shows attackers are working 'smarter, not harder,' experts say

The Microsoft Exchange hack shows attackers are working 'smarter, not harder,' experts say

Experts are still unsure of the hackers' motivations, and whether the incident may have been a "test run" for a larger attack.

News about a hack that impacted hundreds of thousands of global organizations has largely flown under the radar.

On March 3, Microsoft announced Hafnium, a Chinese-sponsored hacker group, exploited vulnerabilities in its Exchange email servers. Microsoft said hackers left behind "web shells," or tools that allow bad actors to access victims' systems remotely after initial access.

The attack impacted hundreds of thousands of organizations globally and 30,000 in the US. Experts recently told Insider's Aaron Holmes the hack could be "1,000 times more crippling" than the widely publicized SolarWinds attack.

Cyber security experts say though the Exchange server hack has not shocked Americans the way the SolarWinds attack did last year, but citizens must pay attention because of the likely increase in hacks this year and the different ways bad actors are exploiting victims.

"This attack underscores just how vulnerable even the most secure organizations or individuals are when targeted by skilled cybercriminals," Marcin Klecyznski, the CEO of Malwarebytes, told Insider.

Microsoft announced a hack in its Exchange email servers on March 3.

Why you should care about the attack


One takeaway from the Exchange Server attack is that no one is safe from a hack.

Microsoft is an industry leader that accelerated cloud-based security efforts as offices transitioned to remote work during the pandemic. But getting hacked means companies need to develop software with security in every step, as well as have an incident response plan to patch flaws and notify users, per Jonathan Knudsen, a senior security strategist at Synopsys Software Integrity Group.

The hack also suggests cybercriminals are working "smarter, not harder," said Klecyznski. Bad actors know IT security teams' resources have become more stretched due to the rise in remote work, and hackers are looking to advantage of that gap in oversight, he said.

Knudsen advises anyone responsible for a Microsoft Exchange server to patch the system and check for signs of an attack. Systems administrators also need to update servers and carefully examine systems at all times, because hackers can have access to a device for months or years before someone notices.

Kelvin Coleman, the executive director at the National Cyber Security Alliance, said security experts are still unsure of the hackers' motivations, and whether the incident may have been a "test run" for a larger attack — which makes protecting user accounts with quality passwords and multi-factor authentication imperative.

"It can impact a lot of things if folks don't have confidence that their information is protected and secure," Coleman said.

How the Microsoft Exchange hack differs from other attacks


SolarWinds hackers were able to spy on federal agencies like the Department of Homeland Security and Treasury Department. Coleman said the Microsoft attack has received relatively less media attention due to the victims being small- to mid-size organizations and local governments, but that still leaves systems and personal information vulnerable.

The attack also differs from others because hackers did not need to interact with victims to get access to their information, said Ben Read, the senior manager for Cyber Espionage Analysis in FireEye's Intelligence unit. Unlike a phishing scam, which relies on users clicking into a link with malware, the Exchange Server attack gave hackers more control.

Read said that, though this isn't the first time this kind of attack happened, there's been a rise in vulnerabilities in web-facing applications in the past 18 months. Analysts predict cyber attacks will dramatically increase this year as hackers exploit uncertainty around COVID-19 and take advantage of remote workers.

"The sheer number of victims makes it a big deal," Read said in an interview with Insider. "Anyone who hasn't taken mitigation efforts...they're vulnerable as other groups kind of figure out how to exploit these vulnerabilities."

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Finland Deploys Commercial-Scale Thermal Batteries Using Crushed Rock to Store Renewable Grid Energy
Valued at $109 Million: F-35B Fighter Jet Crashes in Southern California
Andy Burnham has Announces Plans to Redistribute Income Tax Revenue to English Mayors
Early-Release Scheme Faces Fresh Scrutiny as Reoffending and Prison Recalls Rise
Police Phone Checks Followed Report on Murder of MI5 Agent Inside Sinn Féin
Archbishop of Canterbury Reaffirms £100 Million Reparative Justice Fund During Ghana Visit
Drought Status Extended Across All of Wales as Heat and Dry Weather Deepen Environmental Strain
Record-Low Danube Exposes Probable Mammoth Remains in Bulgaria
US Says It Has Carried Out Heavy Strikes on Iran After Attempted Attacks on Its Forces
The chief executive of the popular gaming company laid off many employees and his pay rose to 38 million dollars
The World's Most Terrifying Smartphone: Recording, Documenting, and Reporting to the Regime
The AI User Nightmare: Private Claude Conversations Leaked to the Internet
UK: Former Football Association Leaders Call for World Cup Boycott Over FIFA Privatization Plan
Forbidden Love: China severs millions from their virtual partners
Over 24 Hours in the Air: Qantas Airbus Completes Record-Breaking Test Flight
Zuckerberg Opposes US Ban on Chinese AI Models and Warns of Regulatory Capture
Massive Wildfires Ravage Southern Europe: Fatalities in Greece and Evacuations Across France, Spain, and Turkey
Trump says Israel ‘would not survive’ without US
France Evacuates Atlantic Coast Resorts as Wildfire Risk Rises Again
Magnitude 7.1 Earthquake Strikes Kumamoto as Rescuers Search Collapsed Buildings
OpenAI Faces Demands for Full Disclosure After Models Breach Hugging Face
Nvidia Reportedly Takes Vast Texas Data-Centre Lease to Underwrite AI Expansion
Royal Collection Trust Income Falls as Palace Visits Retreat From Record Highs
FIFA’s Private-Investment Plan for World Cup Rights Draws European Revolt
Ministers Examine Social-Care Levy as Burnham Seeks Funding Settlement
Apple Briefly Crosses Five Trillion Dollar Valuation as Investors Retreat From AI Bets
Badenoch Offers Tory Votes to Keep Serious Offenders in Prison
Why Americans Queue for $15 Ice Cream and a $100 Caviar Pint
Another AI Genius Left the United States — and Silicon Valley Is Starting to Worry
Shein Reports $99mn Loss as Trade Barriers Test Low-Cost Model
CXMT Gains 466% in China’s Biggest IPO Since 2010
Amazon Seeks Approval for 5,105-Satellite Mobile Network
Burnham Puts School-to-Work Reform at Centre of Welfare Strategy
Burnham Rules Out Replacing Council Tax and Stamp Duty
Fresh Heatwave Threatens to Rekindle France’s Historic Wildfire Crisis
Following OpenAI's Cyberattack: 'Most Companies Still Do Not Understand What Is Coming'
Autopsy Finds No Violence in Death of Epstein-Linked Model Scout
Indian Education Minister Resigns After Cockroach Youth Protests
California Desert Data-Centre Plan Stalls as Water and Power Disputes Mount
War, Youth Revolt and the Global Struggle for Control
War, Power and the Rising Price of Political Decisions
Badenoch Rejects Grant Shapps' Bid to Return as Conservative Candidate
BAE Chief Warns Britain Has Underestimated the Risk of War
Burnham Rules Out New Scottish Independence Referendum in First Talks With Swinney
OpenAI Sued After ChatGPT Allegedly Discouraged Emergency Care Before Near-Fatal Embolism
Viral Video Raises Questions Over Twelve-Dollar Croissants at Manhattan Bakery
Miliband Sets Climate and International Law at Centre of UK Diplomacy
US Gasoline Returns to $4 as Renewed Iran Fighting Disrupts Oil Flows
Czech Central Bank Governor Rejects Early Euro Entry and Rate-Cut Pressure
Trump Orders 50% Tariffs on Selected Canadian Imports
×