{"id":39920,"date":"2021-03-09T15:36:30","date_gmt":"2021-03-09T15:36:30","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/32088\/Microsofts-Crazy-Huge-Hack-Explained.html"},"modified":"2021-03-09T15:36:30","modified_gmt":"2021-03-09T15:36:30","slug":"microsofts-crazy-huge-hack-explained","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/","title":{"rendered":"Microsoft&#8217;s Crazy Huge Hack, Explained"},"content":{"rendered":"<figure class=\"sc-1eow4w5-1 dhDQnh align--bleed js_lazy-image js_marquee-assetfigure\" data-id=\"wrsxfsbugsqbunpugkth\" data-recommend-id=\"image:\/\/wrsxfsbugsqbunpugkth\" data-format=\"jpg\" data-width=\"4494\" data-height=\"2527\" data-lightbox=\"true\" data-recommended=\"true\" contenteditable=\"false\" draggable=\"false\">\n<div class=\"sc-1eow4w5-2 loxZOX img-wrapper\" contenteditable=\"false\" data-syndicationrights=\"true\" data-imagerights=\"getty\" data-hidecredit=\"false\"><span class=\"sc-1eow4w5-0 dnhHtZ js_lightbox-wrapper\"><\/p>\n<div class=\"sc-1eow4w5-3 lktKQM image-hydration-wrapper\">\n<div><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Illustration for article titled Microsoft&amp;#39;s &amp;#39;Crazy Huge Hack,&amp;#39; Explained\" data-expanded-srcset=\"https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_80,pg_1,q_80,w_80\/wrsxfsbugsqbunpugkth.jpg 80w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_140\/wrsxfsbugsqbunpugkth.jpg 140w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_265\/wrsxfsbugsqbunpugkth.jpg 265w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_340\/wrsxfsbugsqbunpugkth.jpg 340w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_490\/wrsxfsbugsqbunpugkth.jpg 490w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_645\/wrsxfsbugsqbunpugkth.jpg 645w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_740\/wrsxfsbugsqbunpugkth.jpg 740w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_965\/wrsxfsbugsqbunpugkth.jpg 965w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_1165\/wrsxfsbugsqbunpugkth.jpg 1165w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_1315\/wrsxfsbugsqbunpugkth.jpg 1315w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_1465\/wrsxfsbugsqbunpugkth.jpg 1465w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_1600\/wrsxfsbugsqbunpugkth.jpg 1600w\" sizes=\" (max-width: 25em) calc(100vw - 32px), (max-width: 37.31em) calc(100vw - 32px), (min-width: 37.37em) and (max-width: 49.94em) calc(100vw - 32px), (min-width: 50em) and (max-width: 63.69em) 800px, (min-width: 63.75em) and (max-width: 85.19em) calc(66.5vw - 32px), 800px \" draggable=\"auto\" data-chomp-id=\"wrsxfsbugsqbunpugkth\" data-format=\"jpg\" data-alt=\"Illustration for article titled Microsoft&amp;#39;s &amp;#39;Crazy Huge Hack,&amp;#39; Explained\" data-anim-src srcset=\"https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_80,pg_1,q_80,w_80\/wrsxfsbugsqbunpugkth.jpg 80w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,fl_progressive,q_80,w_320\/wrsxfsbugsqbunpugkth.jpg 320w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,fl_progressive,pg_1,q_80,w_470\/wrsxfsbugsqbunpugkth.jpg 470w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_scale,f_auto,fl_progressive,pg_1,q_80,w_800\/wrsxfsbugsqbunpugkth.jpg 800w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_scale,f_auto,fl_progressive,pg_1,q_80,w_1600\/wrsxfsbugsqbunpugkth.jpg 1600w\"><\/div>\n<\/div>\n<p><\/span><figcaption class=\"sc-7s1ndr-0 dzxYIl no-caption\">Photo<!-- -->: <!-- -->David Ramos<!-- --> (<!-- -->Getty Images<!-- -->)<\/figcaption><\/div>\n<p><span data-id=\"wrsxfsbugsqbunpugkth\" data-recommend-id=\"image:\/\/wrsxfsbugsqbunpugkth\" data-format=\"jpg\" data-width=\"4494\" data-height=\"2527\" data-lightbox=\"true\" data-recommended=\"true\" class=\"js_recommend\"><\/span><\/figure>\n<p><span><\/span><\/p>\n<p class=\"sc-77igqf-0 bOfvBY\">Last week, <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;Internal link&quot;,&quot;https:\/\/gizmodo.com\/microsoft-chinese-hackers-have-been-exploiting-our-ema-1846392190&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/gizmodo.com\/microsoft-chinese-hackers-have-been-exploiting-our-ema-1846392190\">Microsoft announced<\/a><\/span> that the on-premises version of its widely used email and calendaring product Exchange had several previously undisclosed security flaws. These flaws, the company said, were being used by foreign threat actors to hack into the networks of U.S. businesses and governments, primarily to steal large troves of email data. Since then, the big question on everybody\u2019s mind has been: Just how bad is this? <\/p>\n<aside class=\"sc-1rh3ayr-6 jfFNjl inset--story branded-item branded-item--gizmodo\" data-commerce-source=\"inset\" readability=\"16.5\"><a class=\"sc-1out364-0 hMndXN sc-1rh3ayr-2 ihdhCm inset--story__thumb js_link\" data-ga=\"[[&quot;Permalink page click&quot;,&quot;Permalink page click - inset photo&quot;]]\" href=\"https:\/\/gizmodo.com\/the-solarwinds-hack-just-keeps-getting-wilder-1846193313\" rel=\"noopener noreferrer\" target=\"_blank\"><\/p>\n<div class=\"sc-1rh3ayr-1 gpIBWM js_lazy-image\">\n<div><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Illustration for article titled Microsoft&amp;#39;s &amp;#39;Crazy Huge Hack,&amp;#39; Explained\" data-expanded-srcset=\"https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_80,pg_1,q_80,w_80\/tuyqwswo9qu9wd1ius0w.jpg 80w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_78,pg_1,q_60,w_140\/tuyqwswo9qu9wd1ius0w.jpg 140w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_149,pg_1,q_60,w_265\/tuyqwswo9qu9wd1ius0w.jpg 265w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_191,pg_1,q_60,w_340\/tuyqwswo9qu9wd1ius0w.jpg 340w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_275,pg_1,q_60,w_490\/tuyqwswo9qu9wd1ius0w.jpg 490w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_362,pg_1,q_60,w_645\/tuyqwswo9qu9wd1ius0w.jpg 645w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_416,pg_1,q_60,w_740\/tuyqwswo9qu9wd1ius0w.jpg 740w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_542,pg_1,q_60,w_965\/tuyqwswo9qu9wd1ius0w.jpg 965w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_655,pg_1,q_60,w_1165\/tuyqwswo9qu9wd1ius0w.jpg 1165w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_739,pg_1,q_60,w_1315\/tuyqwswo9qu9wd1ius0w.jpg 1315w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_824,pg_1,q_60,w_1465\/tuyqwswo9qu9wd1ius0w.jpg 1465w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_900,pg_1,q_60,w_1600\/tuyqwswo9qu9wd1ius0w.jpg 1600w\" sizes=\"(max-width: 480px) 200px, 260px\" draggable=\"auto\" data-chomp-id=\"tuyqwswo9qu9wd1ius0w\" data-format=\"jpg\" data-alt=\"Illustration for article titled Microsoft&amp;#39;s &amp;#39;Crazy Huge Hack,&amp;#39; Explained\" data-anim-src srcset=\"https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_180,pg_1,q_80,w_320\/tuyqwswo9qu9wd1ius0w.jpg 320w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_264,pg_1,q_80,w_470\/tuyqwswo9qu9wd1ius0w.jpg 470w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_450,pg_1,q_80,w_800\/tuyqwswo9qu9wd1ius0w.jpg 800w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_675,pg_1,q_80,w_1200\/tuyqwswo9qu9wd1ius0w.jpg 1200w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_900,pg_1,q_80,w_1600\/tuyqwswo9qu9wd1ius0w.jpg 1600w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_80,pg_1,q_80,w_80\/tuyqwswo9qu9wd1ius0w.jpg 80w\"><\/div>\n<\/div>\n<p><span class=\"ynl58c-0 kuYOrG\"><svg width=\"64\" height=\"64\" aria-label=\"Gizmodo avatar\" viewBox=\"0 0 64 64\"><g fill=\"none\" fill-rule=\"evenodd\"><path fill=\"#18AFED\" d=\"M0 0h64v64H0z\" \/><path fill=\"#FFF\" d=\"M16.67 46.94A22.04 22.04 0 0 1 11 32.43C11 16.09 24.58 10 33.15 10c8.41 0 14.6 4.13 14.85 4.3a4.22 4.22 0 0 1-1.48 7.58 4.1 4.1 0 0 1-3.1-.61c-.11-.07-4.5-2.9-10.27-2.9-5.37 0-12.77 3.54-12.77 14.06 0 5.98 4.45 13.04 12.6 13.04 4.6 0 7.83-1.23 9.7-2.42v-6.22h-6.36a4.16 4.16 0 0 1-4.13-4.18 4.16 4.16 0 0 1 4.13-4.19h10.5A4.2 4.2 0 0 1 51 32.64V45.1c0 1.13-.5 2.21-1.3 3-2.79 2.73-8.87 5.9-16.88 5.9a21.4 21.4 0 0 1-16.16-7.06z\" \/><\/g><\/svg><\/span><\/a><\/aside>\n<h3 class=\"sc-1bwb26k-1 kpbNNd\" id=\"h1065\">The short answer is: It\u2019s pretty bad<\/h3>\n<p class=\"sc-77igqf-0 bOfvBY\">So far, hack descriptors such as \u201c<span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/twitter.com\/C_C_Krebs\/status\/1368004411545579525&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/twitter.com\/C_C_Krebs\/status\/1368004411545579525\" target=\"_blank\" rel=\"noopener noreferrer\">crazy huge<\/a><\/span>,\u201d \u201c<span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.wired.com\/story\/china-microsoft-exchange-server-hack-victims\/&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.wired.com\/story\/china-microsoft-exchange-server-hack-victims\/\" target=\"_blank\" rel=\"noopener noreferrer\">astronomical<\/a><\/span>,\u201d and \u201c<span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/krebsonsecurity.com\/2021\/03\/at-least-30000-u-s-organizations-newly-hacked-via-holes-in-microsofts-email-software\/&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/krebsonsecurity.com\/2021\/03\/at-least-30000-u-s-organizations-newly-hacked-via-holes-in-microsofts-email-software\/\" target=\"_blank\" rel=\"noopener noreferrer\">unusually aggressive<\/a><\/span>\u201d seem to be right on the money. As a result of Exchange vulnerabilities, it is likely that tens of thousands of U.S.-based entities have had malicious backdoors implanted in their systems. Anonymous sources close to the Microsoft investigation have repeatedly told press outlets that somewhere <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/krebsonsecurity.com\/2021\/03\/at-least-30000-u-s-organizations-newly-hacked-via-holes-in-microsofts-email-software\/&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/krebsonsecurity.com\/2021\/03\/at-least-30000-u-s-organizations-newly-hacked-via-holes-in-microsofts-email-software\/\" target=\"_blank\" rel=\"noopener noreferrer\">around 30,000<\/a><\/span> American organizations have been compromised as a result of the security flaws (if correct, these numbers officially dwarf SolarWinds, which led to the compromise of about 18,000 entities domestically and nine federal agencies, according to the White House). The number of compromised entities worldwide could be much larger. A source <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.bloomberg.com\/news\/articles\/2021-03-07\/hackers-breach-thousands-of-microsoft-customers-around-the-world&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.bloomberg.com\/news\/articles\/2021-03-07\/hackers-breach-thousands-of-microsoft-customers-around-the-world\" target=\"_blank\" rel=\"noopener noreferrer\">recently told Bloomberg<\/a><\/span> that there are \u201cat least 60,000 known victims globally.\u201d<\/p>\n<div id class=\"bxm4mm-11 gamHXh js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic movable-ad\">\n<div class=\"bxm4mm-12 iqioLK ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 bOfvBY\">Even more problematically, some researchers have said that, since the public disclosure of the Exchange vulnerabilities, it would appear that attacks on the product have only accelerated. Anton Ivanov, a threat research specialist at Kaspersky, said in an email that his team has seen an uptick in activity over the past week. <\/p>\n<p class=\"sc-77igqf-0 bOfvBY\">\u201cFrom the beginning, we anticipated that attempts to exploit these vulnerabilities would increase rapidly, and this is exactly what we are seeing now \u2013 so far we have detected such attacks in over a hundred countries essentially in every part of the world,\u201d Ivanov told Gizmodo. \u201cEven though the initial attacks may have been targeted, there is no reason for actors to not try their luck by attacking essentially any organization that runs a vulnerable server. These attacks are associated with a high risk of data theft or even ransomware attacks, and, therefore, organizations need to take protective measures as soon as possible.\u201d<\/p>\n<div class=\"bxm4mm-19 fIUNXF\" readability=\"1.6071428571429\">\n<div class=\"sc-1atgi65-0 sc-1atgi65-1 bdNdA-D js_commerce-inset-permalink\" data-inset-url=\"https:\/\/kinjadeals.theinventory.com\/stock-up-on-rechargeable-batteries-or-48-packs-of-aaa-a-1845950334\" data-inset-category=\"CommerceInsetMobile\" readability=\"1.875\">\n<p>G\/O Media may get a commission<\/p>\n<\/div>\n<\/div>\n<h3 class=\"sc-1bwb26k-1 kpbNNd\" id=\"h1066\">How Are the Attacks Happening? <\/h3>\n<p class=\"sc-77igqf-0 bOfvBY\">Microsoft Exchange Server comes in two formats, which has led to some confusion about what systems are at risk: there is an on-premises product and a software-as-a-service cloud product. The cloud product, Exchange Online, is said to be unaffected by the security flaws. As previously stated, it is the on-premises products that are being exploited. Other Microsoft email products are not thought to be vulnerable. As <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.cisa.gov\/ed2102&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.cisa.gov\/ed2102\" target=\"_blank\" rel=\"noopener noreferrer\">CISA has said<\/a><\/span>, \u201cneither the vulnerabilities nor the identified exploit activity is currently known to affect Microsoft 365 or Azure Cloud deployments.\u201d<\/p>\n<div id class=\"bxm4mm-11 gamHXh js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic movable-ad\">\n<div class=\"bxm4mm-12 iqioLK ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 bOfvBY\">There are four vulnerabilities in on-premises Exchange Servers that are actively being exploited (see: <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-26855&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-26855\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a><\/span>, <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-26857&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-26857\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a><\/span>, <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-26858&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-26858\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a><\/span>, and <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2021-27065&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2021-27065\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a><\/span>). Three other security-associated vulnerabilities exist, but <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.cisa.gov\/ed2102&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.cisa.gov\/ed2102\" target=\"_blank\" rel=\"noopener noreferrer\">authorities say<\/a><\/span> these have not seen active exploitation of these yet (see: <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-26412&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-26412\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a><\/span>, <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-26854&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-26854\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a><\/span>, and <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-27078&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-27078\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a><\/span>.) Patches can be found <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/msrc-blog.microsoft.com\/2021\/03\/05\/microsoft-exchange-server-vulnerabilities-mitigations-march-2021\/&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/05\/microsoft-exchange-server-vulnerabilities-mitigations-march-2021\/\" target=\"_blank\" rel=\"noopener noreferrer\">at Microsoft\u2019s website<\/a><\/span>, though, as we\u2019ll go over in more detail later, there have been some issues with proper deployment.<\/p>\n<p class=\"sc-77igqf-0 bOfvBY\">So far, Microsoft has primarily blamed a threat actor dubbed \u201cHAFNIUM\u201d for the intrusions into Exchange. HAFNIUM is said to be a state-sponsored group whose modus operandi involves exploiting the security flaws to deploy web shells\u2014malicious scripts that can act as backdoors into systems. These web shells allow the hackers to gain remote access to servers, then exfiltrate large tranches of email data\u2014including entire inboxes. The goal of HAFNIUM would appear to be intelligence gathering. Though the group is believed to be based in China, the Chinese government has denied any responsibility.<\/p>\n<div id class=\"bxm4mm-11 gamHXh js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic movable-ad\">\n<div class=\"bxm4mm-12 iqioLK ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 bOfvBY\">However, security researchers say it is almost certain that other threat actors are also involved in the exploitation of the vulnerabilities. Security firm Red Canary reported over the weekend that they had observed multiple activity clusters targeting Exchange servers and that organizations shouldn\u2019t assume that they are necessarily being targeted by HAFNIUM\u2014it could be someone else. \u201cBased on our visibility and that of researchers from Microsoft, FireEye, &amp; others, there are at least 5 different clusters of activity that appear to be exploiting the vulnerabilities,\u201d said Red Canary researcher <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/twitter.com\/redcanary\/status\/1368289939448766465&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/twitter.com\/redcanary\/status\/1368289939448766465\" target=\"_blank\" rel=\"noopener noreferrer\">Katie Nickels<\/a><\/span> on Saturday.<\/p>\n<h3 class=\"sc-1bwb26k-1 kpbNNd\" id=\"h1067\">Who Is Getting Hit <\/h3>\n<p class=\"sc-77igqf-0 bOfvBY\">Due to the widespread use of Exchange, many different types of entities are at-risk. Some large organizations\u2014including <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.bbc.com\/news\/technology-56321567&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.bbc.com\/news\/technology-56321567\" target=\"_blank\" rel=\"noopener noreferrer\">the European Banking Authority<\/a><\/span>\u2014have already announced breaches. There is no word yet on whether the U.S. government has been affected, though numerous agencies\u2014<span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.defense.gov\/Newsroom\/Transcripts\/Transcript\/Article\/2527735\/pentagon-press-secretary-updates-reporters-on-defense-operations\/&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.defense.gov\/Newsroom\/Transcripts\/Transcript\/Article\/2527735\/pentagon-press-secretary-updates-reporters-on-defense-operations\/\" target=\"_blank\" rel=\"noopener noreferrer\">including the Pentagon<\/a><\/span>\u2014are currently going through their own networks to investigate whether they\u2019ve been compromised.<\/p>\n<div id class=\"bxm4mm-11 gamHXh js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic movable-ad\">\n<div class=\"bxm4mm-12 iqioLK ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 bOfvBY\">Security researchers have expressed particular concern for smaller-sized entities\u2014specifically <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.zdnet.com\/article\/microsoft-exchange-zero-day-vulnerabilities-exploited-in-attacks-against-us-local-govts-university\/&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.zdnet.com\/article\/microsoft-exchange-zero-day-vulnerabilities-exploited-in-attacks-against-us-local-govts-university\/\" target=\"_blank\" rel=\"noopener noreferrer\">city and county governments<\/a><\/span> and small and mid-sized businesses\u2014which they say are more at risk. In North Dakota, the state government <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.grandforksherald.com\/business\/technology\/6920998-North-Dakota-suspects-Chinese-hackers-had-control-of-public-email-servers-during-cyberattack&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.grandforksherald.com\/business\/technology\/6920998-North-Dakota-suspects-Chinese-hackers-had-control-of-public-email-servers-during-cyberattack\" target=\"_blank\" rel=\"noopener noreferrer\">recently admitted<\/a><\/span> that it had been targeted by HAFNIUM and that it was investigating whether Chinese hackers had stolen data.<\/p>\n<p class=\"sc-77igqf-0 bOfvBY\">Lior Div, CEO of security firm Cybereason, said that smaller businesses were particularly at risk of being compromised by the campaigns. Div stressed the potential impact this hack could have on local economies in the event that the attacks prove more destructive than invasive: <\/p>\n<blockquote data-type=\"BlockQuote\" class=\"sc-8hxd3p-0 gZJbdR\" readability=\"15\">\n<p class=\"sc-77igqf-0 bOfvBY\">\u201cThe newest assault against Microsoft Exchange is 1,000 times more devastating [than SolarWinds] because the Chinese attackers have targeted SMEs [small and medium size enterprises], the lifeblood of the U.S. economy and the driver of the global economy,\u201d said Div, in an email. \u201cSMEs were the most impacted by the COVID-19 pandemic, with millions of businesses closing around the world. And just when we are starting to turn the corner after a devastating year, this attack against SMEs is launched. This attack is potentially even more damaging because SMEs typically don\u2019t typically have as robust a security posture in place, allowing threat actors to prey on the weak and drive strong revenue streams this way.\u201d<\/p>\n<\/blockquote>\n<div id class=\"bxm4mm-11 gamHXh js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic movable-ad\">\n<div class=\"bxm4mm-12 iqioLK ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<aside class=\"sc-1rh3ayr-6 jfFNjl inset--story branded-item branded-item--gizmodo\" data-commerce-source=\"inset\" readability=\"14.095744680851\"><a class=\"sc-1out364-0 hMndXN sc-1rh3ayr-2 ihdhCm inset--story__thumb js_link\" data-ga=\"[[&quot;Permalink page click&quot;,&quot;Permalink page click - inset photo&quot;]]\" href=\"https:\/\/gizmodo.com\/microsoft-chinese-hackers-have-been-exploiting-our-ema-1846392190\" rel=\"noopener noreferrer\" target=\"_blank\"><\/p>\n<div class=\"sc-1rh3ayr-1 gpIBWM js_lazy-image\">\n<div><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Illustration for article titled Microsoft&amp;#39;s &amp;#39;Crazy Huge Hack,&amp;#39; Explained\" data-expanded-srcset=\"https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_80,pg_1,q_80,w_80\/z0cndeiu8gnt2efnq74f.jpg 80w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_78,pg_1,q_60,w_140\/z0cndeiu8gnt2efnq74f.jpg 140w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_149,pg_1,q_60,w_265\/z0cndeiu8gnt2efnq74f.jpg 265w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_191,pg_1,q_60,w_340\/z0cndeiu8gnt2efnq74f.jpg 340w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_275,pg_1,q_60,w_490\/z0cndeiu8gnt2efnq74f.jpg 490w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_362,pg_1,q_60,w_645\/z0cndeiu8gnt2efnq74f.jpg 645w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_416,pg_1,q_60,w_740\/z0cndeiu8gnt2efnq74f.jpg 740w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_542,pg_1,q_60,w_965\/z0cndeiu8gnt2efnq74f.jpg 965w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_655,pg_1,q_60,w_1165\/z0cndeiu8gnt2efnq74f.jpg 1165w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_739,pg_1,q_60,w_1315\/z0cndeiu8gnt2efnq74f.jpg 1315w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_824,pg_1,q_60,w_1465\/z0cndeiu8gnt2efnq74f.jpg 1465w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,g_center,h_900,pg_1,q_60,w_1600\/z0cndeiu8gnt2efnq74f.jpg 1600w\" sizes=\"(max-width: 480px) 200px, 260px\" draggable=\"auto\" data-chomp-id=\"z0cndeiu8gnt2efnq74f\" data-format=\"jpg\" data-alt=\"Illustration for article titled Microsoft&amp;#39;s &amp;#39;Crazy Huge Hack,&amp;#39; Explained\" data-anim-src srcset=\"https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_180,pg_1,q_80,w_320\/z0cndeiu8gnt2efnq74f.jpg 320w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_264,pg_1,q_80,w_470\/z0cndeiu8gnt2efnq74f.jpg 470w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_450,pg_1,q_80,w_800\/z0cndeiu8gnt2efnq74f.jpg 800w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_675,pg_1,q_80,w_1200\/z0cndeiu8gnt2efnq74f.jpg 1200w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_900,pg_1,q_80,w_1600\/z0cndeiu8gnt2efnq74f.jpg 1600w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_80,pg_1,q_80,w_80\/z0cndeiu8gnt2efnq74f.jpg 80w\"><\/div>\n<\/div>\n<p><span class=\"ynl58c-0 kuYOrG\"><svg width=\"64\" height=\"64\" aria-label=\"Gizmodo avatar\" viewBox=\"0 0 64 64\"><g fill=\"none\" fill-rule=\"evenodd\"><path fill=\"#18AFED\" d=\"M0 0h64v64H0z\" \/><path fill=\"#FFF\" d=\"M16.67 46.94A22.04 22.04 0 0 1 11 32.43C11 16.09 24.58 10 33.15 10c8.41 0 14.6 4.13 14.85 4.3a4.22 4.22 0 0 1-1.48 7.58 4.1 4.1 0 0 1-3.1-.61c-.11-.07-4.5-2.9-10.27-2.9-5.37 0-12.77 3.54-12.77 14.06 0 5.98 4.45 13.04 12.6 13.04 4.6 0 7.83-1.23 9.7-2.42v-6.22h-6.36a4.16 4.16 0 0 1-4.13-4.18 4.16 4.16 0 0 1 4.13-4.19h10.5A4.2 4.2 0 0 1 51 32.64V45.1c0 1.13-.5 2.21-1.3 3-2.79 2.73-8.87 5.9-16.88 5.9a21.4 21.4 0 0 1-16.16-7.06z\" \/><\/g><\/svg><\/span><\/a><\/aside>\n<h3 class=\"sc-1bwb26k-1 kpbNNd\" id=\"h1068\">What\u2019s Being Done<\/h3>\n<p class=\"sc-77igqf-0 bOfvBY\">The White House <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.businessinsider.com\/biden-wh-launch-task-force-probe-china-microsoft-hack-cnn-2021-3&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.businessinsider.com\/biden-wh-launch-task-force-probe-china-microsoft-hack-cnn-2021-3\" target=\"_blank\" rel=\"noopener noreferrer\">announced late Sunday<\/a><\/span> that it would be putting together a task force to investigate the extent of the hack. This response may be slowed, however, by the fact that the Biden administration is already juggling a response to the SolarWinds hack (the White House is currently mulling covert cyber operations and sanctions on Russia, for its alleged role in the attacks).<\/p>\n<div id class=\"bxm4mm-11 gamHXh js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic movable-ad\">\n<div class=\"bxm4mm-12 iqioLK ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 bOfvBY\">As noted above, Microsoft has issued patches for the vulnerabilities\u2014but these patches have had some problems. On Thursday, a Microsoft spokesperson noted that, in certain cases, the patches would appear to work but wouldn\u2019t actually fix the vulnerability. A <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/support.microsoft.com\/en-us\/topic\/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/support.microsoft.com\/en-us\/topic\/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b\" target=\"_blank\" rel=\"noopener noreferrer\">full break-down<\/a><\/span> of that issue can be found on Microsoft\u2019s website. <\/p>\n<p class=\"sc-77igqf-0 bOfvBY\">Organizations have been warned that they should not only be patching vulnerabilities but should also be investigating whether they have already been compromised. Microsoft has announced resources to help with that. It issued an update to its <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/msrc-blog.microsoft.com\/2021\/03\/05\/microsoft-exchange-server-vulnerabilities-mitigations-march-2021\/&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/05\/microsoft-exchange-server-vulnerabilities-mitigations-march-2021\/\" target=\"_blank\" rel=\"noopener noreferrer\">Safety Scanner (MSERT) tool<\/a><\/span> which can help identify whether web shells have been deployed against Exchange servers. MSERT is an anti-malware tool that searches for, identifies, and removes malware on a system.<\/p>\n<div id class=\"bxm4mm-11 gamHXh js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic movable-ad\">\n<div class=\"bxm4mm-12 iqioLK ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 bOfvBY\">Other than shoring-up defenses and inspecting systems for indications of compromise, there may not be a whole lot that can be done at this point. As with SolarWinds, Americans will probably just have to sit and wait. It will definitely take time to understand how extensive the damage is. <\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/32088\/Microsofts-Crazy-Huge-Hack-Explained.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":39921,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[9259],"class_list":["post-39920","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackermicrosoftemaildata-loss"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Microsoft&#039;s Crazy Huge Hack, Explained 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft&#039;s Crazy Huge Hack, Explained 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-03-09T15:36:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/microsofts-crazy-huge-hack-explained.gif\" \/>\n\t<meta property=\"og:image:width\" content=\"1\" \/>\n\t<meta property=\"og:image:height\" content=\"1\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/gif\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Microsoft&#8217;s Crazy Huge Hack, Explained\",\"datePublished\":\"2021-03-09T15:36:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/\"},\"wordCount\":1242,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/microsofts-crazy-huge-hack-explained.gif\",\"keywords\":[\"headline,hacker,microsoft,email,data loss\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/\",\"name\":\"Microsoft's Crazy Huge Hack, Explained 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/microsofts-crazy-huge-hack-explained.gif\",\"datePublished\":\"2021-03-09T15:36:30+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/microsofts-crazy-huge-hack-explained.gif\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/microsofts-crazy-huge-hack-explained.gif\",\"width\":1,\"height\":1},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-crazy-huge-hack-explained\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,microsoft,email,data loss\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackermicrosoftemaildata-loss\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Microsoft&#8217;s Crazy Huge Hack, Explained\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft's Crazy Huge Hack, Explained 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/","og_locale":"en_US","og_type":"article","og_title":"Microsoft's Crazy Huge Hack, Explained 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-03-09T15:36:30+00:00","og_image":[{"width":1,"height":1,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/microsofts-crazy-huge-hack-explained.gif","type":"image\/gif"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Microsoft&#8217;s Crazy Huge Hack, Explained","datePublished":"2021-03-09T15:36:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/"},"wordCount":1242,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/microsofts-crazy-huge-hack-explained.gif","keywords":["headline,hacker,microsoft,email,data loss"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/","url":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/","name":"Microsoft's Crazy Huge Hack, Explained 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/microsofts-crazy-huge-hack-explained.gif","datePublished":"2021-03-09T15:36:30+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/microsofts-crazy-huge-hack-explained.gif","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/microsofts-crazy-huge-hack-explained.gif","width":1,"height":1},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/microsofts-crazy-huge-hack-explained\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,microsoft,email,data loss","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackermicrosoftemaildata-loss\/"},{"@type":"ListItem","position":3,"name":"Microsoft&#8217;s Crazy Huge Hack, Explained"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/39920","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=39920"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/39920\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/39921"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=39920"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=39920"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=39920"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}