Skip to main content

US nuclear weapons agency reportedly breached in Microsoft SharePoint attacks

The SharePoint zero-day attacks have affected more than 50 organizations.

The SharePoint zero-day attacks have affected more than 50 organizations.

Microsoft Says Chinese Hackers Are Exploiting SharePoint Flaws
Microsoft Says Chinese Hackers Are Exploiting SharePoint Flaws
Photo: Adam Gray / Bloomberg via Getty Images
Tom Warren
is a senior editor and author of Notepad, who has been covering all things Microsoft, PC, and tech for over 20 years.

Hours after Microsoft revealed that hacking groups affiliated with the Chinese government have been exploiting a flaw in its SharePoint software, Bloomberg reported that the National Nuclear Security Administration was also breached in the attacks.

A single source told Bloomberg that the agency, which provides the US Navy with nuclear reactors for submarines, was caught up in the zero-day vulnerability that has hit more than 50 organizations in recent days. The exploit affects on-premises versions of SharePoint, but not the SharePoint Online service that Microsoft operates as part of its Microsoft 365 cloud service.

While the nuclear weapons agency has reportedly been affected by the SharePoint exploit, no sensitive or classified information has leaked, according to Bloomberg. That might be because the US Department of Energy uses Microsoft 365 cloud systems for a lot of its SharePoint work. “The department was minimally impacted due to its widespread use of the Microsoft M365 cloud and very capable cybersecurity systems,” a department spokesperson said in a statement to Bloomberg. “A very small number of systems were impacted. All impacted systems are being restored.”

Microsoft has now patched all versions of SharePoint that have been impacted by the zero-day exploit. The flaw allowed hackers to remotely access SharePoint servers and steal data, passwords, and even move across connected services. It appears to have originated from a combination of two bugs that were presented at the Pwn2Own hacking contest in May.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.