US and its NATO allies officially accuse China of Microsoft Exchange Server hack

China
(Image credit: Future)

The United States and its NATO allies have formally accused the Chinese government of sponsoring Microsoft Exchange Server hacks that took place earlier this year. A state-run Chinese media outlet calls the accusation "absurd."

In March, Microsoft released a statement saying it had detected "multiple 0-day exploits being used to attack on-premises versions of Microsoft Exchange Server in limited and targeted attacks." The attacker was able to use vulnerabilities to access email accounts and install malware that enabled them to undertake further, more long-term attacks. Patches were released in short order, but Microsoft said in an update posted a week later that it "continues to see multiple actors taking advantage of unpatched systems to attack organizations with on-premises Exchange Server."

Microsoft pointed the finger at Hafnium, a "highly skilled and sophisticated" Chinese hacker group that it claims targets US-based interests and industries including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.

"Recently, Hafnium has engaged in a number of attacks using previously unknown exploits targeting on-premises Exchange Server software," Microsoft's Tom Burt explained. "To date, Hafnium is the primary actor we've seen use these exploits.

Today, the US government backed Microsoft's assertion that Hafnium is a "state-sponsored threat actor," issuing a statement attributing "malicious cyber activity and irresponsible state behavior" to the People's Republic of China.

The statement accuses the Chinese government of using "criminal contract hackers to conduct unsanctioned cyber operations globally." It also claims that alongside an alleged contract with China's Ministry of State Security, the hackers involved have "engaged in ransomware attacks, cyber enabled extortion, crypto-jacking, and rank theft from victims around the world, all for [personal] financial gain."

It also reiterates Microsoft's allegations from March, saying "with a high degree of confidence" that China-based hackers were in fact behind hacks that took advantage of Microsoft Exchange Server vulnerabilities. The statement says "tens of thousands of computers and networks worldwide" were compromised "in a massive operation that resulted in significant remediation costs for its mostly private sector victims."

While the US government hasn't taken any direct action against China at this point, it has filed criminal charges against four individuals allegedly connected with online espionage efforts by China. The charges aren't related to the Microsoft Exchange Server hacks, but rather "a multiyear campaign targeting foreign governments and entities in key sectors, including maritime, aviation, defense, education, and healthcare in a least a dozen countries" that took place from 2011 to 2018.

The UK, European Union, and Canada issued parallel statements condemning the Microsoft Server Exchange hack and other cyber-espionage efforts. NATO, the North Atlantic Treaty Organization, also issued a statement condemning "malicious cyber activities," although it took a somewhat more circumspect approach and did not point the finger at China directly. 

"We acknowledge national statements by Allies, such as Canada, the United Kingdom, and the United States, attributing responsibility for the Microsoft Exchange Server compromise to the People's Republic of China," it said. "In line with our recent Brussels Summit Communiqué, we call on all States, including China, to uphold their international commitments and obligations and to act responsibly in the international system, including in cyberspace."

China's Ministry of Foreign Affairs has not yet responded to the accusation, but the state-run Xinhua News Agency described the claims as "absurd" on Twitter:

Xinhua's remark references CIA analyst whistleblower Edward Snowden, who said in 2013 that he believed the US National Security Agency had conducted more than 61,000 hacking operations globally, including many in China. In 2014, The New York Times reported that Snowden's documents showed that the NSA did hack into the servers of Chinese telecom giant Huawei

Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Read more
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Tencent
Tencent has been designated a Chinese military company by the US Department of Defense, which the conglomerate calls a 'misunderstanding'
TP-Link AXE75 Wi-Fi 6E router
US congressman calls again for the government to ban Chinese-made TP-Link routers: 'I would not have that in my home'
TSMC's Fab 14
China taunts Taiwan with claim that chip foundry TSMC could soon become 'USSMC' or the 'United States Semiconductor Manufacturing Co.'
Three Magikarp Pokémon
The FBI used self-destruct on malware infecting over 4,000 US computers, it's super effective
A phone displaying the TikTok logo in front of the US flag.
TikTok users wave goodbye to their 'Chinese spies' as they they ditch the app for another, er, Chinese one
Latest in Gaming Industry
Lara Croft Unified Art
Tomb Raider developer Crystal Dynamics lays off 17 employees 'to better align our current business needs and the studio's future success'
Monster Hunter Wilds' stockpile master studying a manifest
As layoffs and studio closures continue to deathroll the western AAA industry, analyst points out 5 of 8 major Japanese companies hit all-time share prices this year
A still from a video announcement of Game Informer's return, featuring the magazine's Halo 2 issue.
Game Informer is back from the dead: 'The whole team has returned'
Typing on internet search toolbar: What am I doing?
How a Microsoft exec managed to pitch Microsoft Word through the genius tactic of being able to actually use it in a 'type-off' demanded by clients: 'I was the only one who'd actually been a secretary'
Half-Life wallpaper - Gordon Freeman
Former Valve exec says the company struggled to sell Half-Life until coming up with the ultimate 'one simple trick' of marketing manoeuvres: slapping a 'Game of the Year' sticker on the box
Gabe Newell looks into the camera, behind him is a prop of a turret from Team Fortress 2.
Gabe Newell's cult of personality is intense, but a Valve exec who worked with him says his superpower is how he 'delighted in people on the team just being really good at what they did'
Latest in News
A mech awakens.
Mecha Break developer is considering unlocking all mechs following open beta feedback
Lara Croft Unified Art
Tomb Raider developer Crystal Dynamics lays off 17 employees 'to better align our current business needs and the studio's future success'
A long bendy arm stealing money from people in a subway car
'You're a very long arm. You steal things. It's a comedy game,' explains developer of comedy game where you steal things with a very long arm
The heroes are attacked by monsters
Pillars of Eternity is getting turn-based combat to mark its 10th anniversary, and that means PC Gamer editors will soon be arguing about combat mechanics again
Image of Ronaldo from Fatal Fury: City of the Wolves trailer
It doesn't really make sense that soccer star Ronaldo is now a Fatal Fury character, but if you follow the money you can see how it happened
Junah beginning a battle in Metaphor: ReFantazio.
Today's RPG fans are 'very sensitive to feeling like they wasted time' when they die, says Metaphor: ReFantazio battle planner—but Atlus still made combat hard anyway