Microsoft Exchange server attacks were carried out by China, claim U.S. and UK

Microsoft logo
Microsoft logo (Image credit: Daniel Rubino / Windows Central)

What you need to know

  • The EU and UK released statements claiming that the recent attacks on Microsoft Exchange servers came from China.
  • The UK government states that Chinese state-backed groups were behind the attacks.
  • The EU does not directly accuse the Chinese government of being involved but hints in that direction.

The United States (U.S.), European Union (EU), and United Kingdom (UK) claim that the recent attacks on Microsoft Exchange servers came from China. The U.S. and UK specifically point towards the Chinese government, stating that Chinese state-backed actors were behind the attacks.

The attacks on Microsoft Exchange servers affected thousands of organizations. Cybercriminals raced to take advantage of discovered vulnerabilities and Microsoft quickly mitigated issues. Microsoft also released a one-click mitigation tool to help organizations protect against attackers.

Both the EU and UK say that the Chinese Ministry of State Security was responsible for other espionage activity, as reported by the BBC.

"The cyber-attack on Microsoft Exchange Servers by Chinese state-backed groups was a reckless but familiar pattern of behaviour," said UK foreign secretary Dominic Raab. "The Chinese government must end this systematic cyber-sabotage and can expect to be held to account if it does not."

The UK government issued a release detailing its accusations. It says that "Widespread, credible evidence demonstrates that sustained, irresponsible cyber activity emanating from China continues."

At the end of its release, the UK government calls on China to "reaffirm the commitment made to the UK in 2015 and as part of the G20 not to conduct or support cyber-enabled theft of intellectual property of trade secrets."

In March 2021, Microsoft explained that a group known as Hafnium operates out of China and was behind the attacks on Exchange servers. This situation, and many more, have led to the White House's July 19, 2021 statement on the matter.

The EU statement shares a similar tone to its U.S. counterpart:

The EU and its member states strongly denounce these malicious cyber activities, which are undertaken in contradiction with the norms of responsible state behaviour as endorsed by all UN member states. We continue to urge the Chinese authorities to adhere to these norms and not allow its territory to be used for malicious cyber activities, and take all appropriate measures and reasonably available and feasible steps to detect, investigate and address the situation.

While the EU does not accuse the Chinese government of backing the groups behind the attacks, the organization does urge Chinese authorities to not allow China to be used for malicious cyber activities.

The EU also detected "malicious cyber activities" targetting government institutions and political organizations in the EU, its member states, and several industries in Europe. The UK reports the same activities, known as "APT40" and APT31" by cybersecurity experts.

CATEGORIES
Sean Endicott
News Writer and apps editor

Sean Endicott is a tech journalist at Windows Central, specializing in Windows, Microsoft software, AI, and PCs. He's covered major launches, from Windows 10 and 11 to the rise of AI tools like ChatGPT. Sean's journey began with the Lumia 740, leading to strong ties with app developers. Outside writing, he coaches American football, utilizing Microsoft services to manage his team. He studied broadcast journalism at Nottingham Trent University and is active on X @SeanEndicott_ and Threads @sean_endicott_. 

Read more
A DeepSeek artificial intelligence logo and icons on various smartphones or laptops.
DeepSeek is reportedly sending intricate user data to Chinese telecom despite US ban — weeks after suffering a "large-scale cyberattack"
TikTok
Microsoft is once again reportedly involved in talks to buy TikTok, with Oracle leading
TikTok logo on a smart phone flanked by a Surface Book
President Trump confirms that Microsoft is in talks to buy up TikTok, as the social network's future hangs in the balance
Xbox Logo
Happy Monday! Microsoft services, including Xbox, appear to be down in some locations to start the week
Satya Nadella contemplating during the annual Microsoft shareholders meeting.
Microsoft CEO Satya Nadella touts DeepSeek's open-source AI as "super impressive": "We should take the developments out of China very, very seriously"
The X account of OpenAI CEO Sam Altman is displayed on a mobile phone with a ChatGPT logo.
OpenAI CEO Sam Altman wants to "work with China" but would the US government allow it?
Latest in Microsoft
Cloud servers
Microsoft has killed "several" data center projects in the U.S. and Europe, according to reports — Microsoft responds (Updated)
Steve Ballmer and Bill Gates, former CEOs of Microsoft.
Bill Gates says Satya Nadella almost missed the cut for CEO of Microsoft — Even with Steve Ballmer's support
HP Reverb G2 VR headset
Was Windows Mixed Reality as bad as I remember? I look back at the failed VR platform that was ahead of its time.
Microsoft Majorana 1 chip designed for quantum computing
Microsoft dismisses quantum computing skepticism: "There is a century-old scientific process established by the American Physical Society for resolving disputes"
The Microsoft logo on a smartphone and laptop arranged in Crockett, California, US, on Friday, Dec. 29, 2023.
"Would you say there is a reasonable balance between what you contribute to Microsoft and what you get in return?" Two-thirds of Microsoft employees say YES — as AI engineers get preferential compensation packages.
Like a Dragon Pirate Yakuza in Hawaii screenshot
Microsoft blocks (some) Windows 11 pirates while Lenovo steals the show at Mobile World Congress
Latest in News
Cloud servers
Microsoft has killed "several" data center projects in the U.S. and Europe, according to reports — Microsoft responds (Updated)
Photo of Microsoft's new sign-in page for Xbox.com using the Microsoft Edge browser.
Over one billion users will get a new Microsoft user experience, and it has a dark mode
The Thing: Remastered key art
The Thing comes to Xbox Cloud Gaming's "Stream Your Own Game" library alongside other new arrivals
Promotional screenshot of heroes fighting a giant in Pillars of Eternity
Obsidian's classic Baldur's Gate successor 'Pillars of Eternity' is getting a surprise turn-based mode later this year, alongside other updates
Atomfall
Atomfall reviews and Metacritic scores are in: Here's a roundup of what everyone's saying about this new Game Pass survival game
Screenshot of one of the new flat world presets in Minecraft.
Minecraft testing new flat world presets and a better way to locate your friends in-game