Thousands of SharePoint Servers Hit by Active Cyber Attack 

Thousands of SharePoint Servers Hit by Active Cyber Attack 

I
Inspirepreneur Team
Jul 22, 2025 8:00 AM IST
Category Asia
SharePoint

Synopsis

Breaking News - Microsoft is dealing with a serious cyber attack, targeting on-premises SharePoint servers, which may have targeted thousands of systems across the world. The company confirmed on July 19 that the incident…

Breaking News - Microsoft is dealing with a serious cyber attack, targeting on-premises SharePoint servers, which may have targeted thousands of systems across the world. The company confirmed on July 19 that the incident is ongoing and involves active exploitation of critical vulnerability.

The cyber hack is not affecting SharePoint online, which is a cloud-based service, but instead it is limited to servers hosted directly by the companies. These are widely used by private companies, schools, and federal agencies to manage and store important internal documents and smooth communications.

01
Chapter one

Dutch Cyber Firm Was The First To Detect Vulnerability  

The Netherlands-based cybersecurity company Eye Security was the first to see this issue, describing it as a large-scale exploitation of a SharePoint remote-code execution ( RCE ) vulnerability. The attack first noticed on July 18 was classified as a “zero attack”, meaning that it exploited gaps even Microsoft had not discovered yet.

Eye Security reported that multiple of their systems were compromised during two distinct waves on July 18 and 19. Hackers used this flow to extract private Digital keys, even without logging in, which allowed them to install malware and access internal files. Because SharePoint connects with Microsoft Outlook and Teams, it led hackers to data theft, password leaks, and movement throughout a company’s network. 

02
Chapter two

Federal Agencies, Schools, And Energy Firms Among Victims 

The Microsoft and American authorities are still investigating this attack on the full scope. Early reports suggest it is wide-reaching. According to the Washington Post, at least two American Federal agencies had their servers breached. The Center for Internet Security said they’ve warned 100 companies, including universities and public schools, about possible attack exposure. Cyber experts have warned that any company using on-premises servers is at risk. “It’s a significant vulnerability,” said Adam Meyers from CrowdStrike.

03
Chapter three

Emergency Patches Deployed, but Risk Remains 

Microsoft has released emergency security updates on July 20 for the subscription edition and some versions of SharePoint 2019. Updates for other versions such as SharePoint 2016 are still being developed. Security experts are advising all users of on-premises SharePoint to assume compromise. It is recommended that during this time, install the latest patches, ensure antivirus like Microsoft Defender is active, and rotate internal digital keys to limit exposure.


Stay informed. Stay inspired. Subscribe to Inspirepreneur Magazine’s Newsletter for the latest developments on global conflicts, leadership insights, and strategic innovations shaping tomorrow’s world.

I
Written by Inspirepreneur Team

At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.