London Daily

Focus on the big picture.
Wednesday, Mar 25, 2026

GCHQ warns businesses to urgently update their Microsoft email servers after suspected China hack

GCHQ warns businesses to urgently update their Microsoft email servers after suspected China hack

The warning follows what Microsoft said was a state-sponsored espionage campaign from a group based in China.

The UK's National Cyber Security Centre, a part of GCHQ, is warning businesses to urgently update their Microsoft email servers following a state-sponsored espionage campaign.

Microsoft has warned that multiple groups are taking advantage of a global and indiscriminate hack of its clients' on-premise email servers, attributing the attack to state-sponsored group based in China, with tens of thousands of potential victims worldwide.

The NCSC has stressed the immediate need for organisations to patch their vulnerable Microsoft Exchange servers, amid warnings that the careless techniques used by the attackers could also enable criminals to piggyback into victims' networks.

Microsoft said a state-sponsored espionage group hacked it


Sky News understands there were no compromises of public sector organisations in the UK as a result of the state-sponsored attack using vulnerabilities in Microsoft Exchange.

Security officials believe there could be up to 8,000 vulnerable Microsoft servers in the country's private sector, although they estimate roughly half of these may have been patched.

Last week, government security authorities amplified Microsoft's urgent call for customers running on-premise Exchange servers to apply the patch, and the company is now warning that there are multiple groups taking advantage of unpatched systems.

Microsoft initially warned that the state-sponsored group "primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defence contractors, policy think tanks, and NGOs".

After compromising email servers belonging to these organisations, Microsoft said the attackers created web shells - interfaces which allow them to remotely access the compromised network even after the original vulnerabilities were patched - which is provoking additional concern.

Security officials have addressed 2,300 webshells across businesses in the UK, but more could remain undetected.

The NCSC's director for operations, Paul Chichester, said: "We are working closely with industry and international partners to understand the scale and impact of UK exposure, but it is vital that all organisations take immediate steps to protect their networks.

"Whilst this work is ongoing, the most important action is to install the latest Microsoft updates.

"Organisations should also be alive to the threat of ransomware and familiarise themselves with our guidance. Any incidents affecting UK organisations should be reported to the NCSC," he added.

Newsletter

Related Articles

0:00
0:00
Close
UK Government Rejects Cover-Up Claims After Theft of Former PM Aide’s Phone
Cyprus Opens Strategic Talks with UK Over Sovereign Base Areas
UK Faces Risk of Sharp Inflation Surge Despite Stable Pre-Crisis Figures
UK Police Arrest Two Over Suspected Antisemitic Arson as Iran Link Investigated
UK Inflation Holds at Three Percent Ahead of Oil Price Shock from Iran Conflict
UK Fuel Prices Face Upward Pressure as Global Oil Trends Raise Cost Outlook
Girlguiding UK Sets September Deadline for Membership Policy Change Affecting Trans Participants
Germany and UK Accelerate Wind Power Expansion to Strengthen Energy Security
UK Moves to Ban Cryptocurrency Donations to Political Parties Over Foreign Influence Concerns
UK and Turkey Finalise Major Air Defence Agreement Worth Billions
Apple Introduces Mandatory Age Verification for iPhone Users in the UK
Diverging Views Emerge Over Meghan Markle’s Planned Australia Appearance
Trump Signals Frustration with UK Leadership Amid Diverging Approaches to Iran Conflict
UK Government Takes Control of Hunterston B as Landmark Nuclear Decommissioning Begins
UK Public Inflation Expectations Jump Sharply in March, Raising Pressure on Bank of England
UK Ministers Warn Expanded North Sea Drilling Would Deepen Exposure to Global Energy Volatility
Delayed UK Defence Investment Plan Leaves Suppliers Under Severe Financial Strain
Can Iran Strike the UK? Assessing the Real Military Threat as Conflict Escalates
Sanctioned Iranian Banker Linked to Luxury Marbella Villa Through UK Corporate Structure
Casey Bloys Navigates HBO Max UK Launch, Paramount Integration and Industry Buzz Over Netflix Meeting
Iran Conflict Sparks Sharp Turbulence in UK Mortgage Market, Reaching Pandemic-Era Disruption Levels
Major Donor Urges University of Kentucky to Reconsider Mitch Barnhart’s Post-Retirement Role
United Kingdom Moves to Lead International Effort to Reopen Strait of Hormuz
UK Police Investigate Targeted Attack on Jewish Ambulance Vehicles
UK Police Investigate Targeted Attack on Jewish Ambulance Vehicles
Senior UK Advocate Criticises Barnhart Retirement Appointment, Calls for Reconsideration
UK Finds No Evidence of Direct Iranian Threat to Britain, Says Prime Minister Starmer
Assessing Iran’s Strike Capability and the UK’s Readiness Amid Rising Tensions
NATO Unable to Confirm Iran’s Role in Strike on UK-US Base as Tehran Denies Involvement
University of Kentucky’s Youling Xiong Receives SEC Faculty Achievement Award for 2026
Trump Highlights Satirical Portrayal of UK Leadership Amid Talks with Prime Minister Starmer on Iran Conflict
Trump Highlights Satirical Portrayal of UK Leadership Amid Talks with Prime Minister Starmer on Iran Conflict
UK Fuel Prices Surge Toward Crisis Levels as Experts Warn of Further Sharp Increases
UK Fuel Prices Surge Toward Crisis Levels as Experts Warn of Further Sharp Increases
Duchess of Sussex Secures ‘As Ever’ Trademark Rights in Australia Ahead of High-Profile Visit
UK Reaffirms Security as Officials Reject Claims of Immediate Iranian Missile Threat
Rising Middle East Tensions Spark ‘Trumpflation’ Debate Over Impact on UK Households
UK Minister Says No Evidence Iran Can Strike Europe Despite Heightened Warnings
British-Iranians Voice Safety Concerns to Authorities as Regional Conflict Intensifies
Confirmed Meningitis Cases Linked to Kent Outbreak Revised Down to Twenty
UK Government Sees No Evidence Iran Can Strike London Amid Rising Regional Tensions
Debate Grows Over Recognition of Indigenous Cultural Icons in the United Kingdom
Iran Missile Launch Toward Diego Garcia Raises Questions After Failed Strike on US–UK Base
Donald Trump Amplifies Viral Satirical Clip Highlighting UK–US Political Dynamics
UK Satirical Show Draws Attention with Sketch Referencing Trump and Prince Andrew
Meghan Markle’s Possible UK Return Sparks Renewed Attention on Sussex Role
Starmer Convenes Urgent Talks on Cost-of-Living Pressures Linked to Iran Conflict
Starmer Convenes Urgent Talks on Cost-of-Living Pressures Linked to Iran Conflict
UK Investors Eye Bargain Shares Ahead of ISA Deadline Amid Market Volatility
UK Investors Eye Bargain Shares Ahead of ISA Deadline Amid Market Volatility
×