London Daily

Focus on the big picture.
Sunday, Aug 02, 2026

The Microsoft Exchange hack shows attackers are working 'smarter, not harder,' experts say

The Microsoft Exchange hack shows attackers are working 'smarter, not harder,' experts say

Experts are still unsure of the hackers' motivations, and whether the incident may have been a "test run" for a larger attack.

News about a hack that impacted hundreds of thousands of global organizations has largely flown under the radar.

On March 3, Microsoft announced Hafnium, a Chinese-sponsored hacker group, exploited vulnerabilities in its Exchange email servers. Microsoft said hackers left behind "web shells," or tools that allow bad actors to access victims' systems remotely after initial access.

The attack impacted hundreds of thousands of organizations globally and 30,000 in the US. Experts recently told Insider's Aaron Holmes the hack could be "1,000 times more crippling" than the widely publicized SolarWinds attack.

Cyber security experts say though the Exchange server hack has not shocked Americans the way the SolarWinds attack did last year, but citizens must pay attention because of the likely increase in hacks this year and the different ways bad actors are exploiting victims.

"This attack underscores just how vulnerable even the most secure organizations or individuals are when targeted by skilled cybercriminals," Marcin Klecyznski, the CEO of Malwarebytes, told Insider.

Microsoft announced a hack in its Exchange email servers on March 3.

Why you should care about the attack


One takeaway from the Exchange Server attack is that no one is safe from a hack.

Microsoft is an industry leader that accelerated cloud-based security efforts as offices transitioned to remote work during the pandemic. But getting hacked means companies need to develop software with security in every step, as well as have an incident response plan to patch flaws and notify users, per Jonathan Knudsen, a senior security strategist at Synopsys Software Integrity Group.

The hack also suggests cybercriminals are working "smarter, not harder," said Klecyznski. Bad actors know IT security teams' resources have become more stretched due to the rise in remote work, and hackers are looking to advantage of that gap in oversight, he said.

Knudsen advises anyone responsible for a Microsoft Exchange server to patch the system and check for signs of an attack. Systems administrators also need to update servers and carefully examine systems at all times, because hackers can have access to a device for months or years before someone notices.

Kelvin Coleman, the executive director at the National Cyber Security Alliance, said security experts are still unsure of the hackers' motivations, and whether the incident may have been a "test run" for a larger attack — which makes protecting user accounts with quality passwords and multi-factor authentication imperative.

"It can impact a lot of things if folks don't have confidence that their information is protected and secure," Coleman said.

How the Microsoft Exchange hack differs from other attacks


SolarWinds hackers were able to spy on federal agencies like the Department of Homeland Security and Treasury Department. Coleman said the Microsoft attack has received relatively less media attention due to the victims being small- to mid-size organizations and local governments, but that still leaves systems and personal information vulnerable.

The attack also differs from others because hackers did not need to interact with victims to get access to their information, said Ben Read, the senior manager for Cyber Espionage Analysis in FireEye's Intelligence unit. Unlike a phishing scam, which relies on users clicking into a link with malware, the Exchange Server attack gave hackers more control.

Read said that, though this isn't the first time this kind of attack happened, there's been a rise in vulnerabilities in web-facing applications in the past 18 months. Analysts predict cyber attacks will dramatically increase this year as hackers exploit uncertainty around COVID-19 and take advantage of remote workers.

"The sheer number of victims makes it a big deal," Read said in an interview with Insider. "Anyone who hasn't taken mitigation efforts...they're vulnerable as other groups kind of figure out how to exploit these vulnerabilities."

Newsletter

Related Articles

0:00
0:00
Close
Finland Deploys Commercial-Scale Thermal Batteries Using Crushed Rock to Store Renewable Grid Energy
Valued at $109 Million: F-35B Fighter Jet Crashes in Southern California
Sainsbury Agrees to Sell Argos in £120 Million Deal to Private Consortium
High Court Clears Way for Construction of Chinese Embassy at Royal Mint Court
UK Fuel Prices Climb to Multi-Month Highs as Strait of Hormuz Tensions Disrupt Oil Supplies
Severe Summer Drought and Record Heat Put UK Harvests at Risk
Prime Minister Andy Burnham Faces Labour Backbench Opposition Over Potential Support for New North Sea Oil and Gas Drilling
Bank of England Warns Inflation Will Stay Above 3% as Middle East Energy Shock Prolongs Cost-of-Living Pressures
Andy Burnham has Announces Plans to Redistribute Income Tax Revenue to English Mayors
Early-Release Scheme Faces Fresh Scrutiny as Reoffending and Prison Recalls Rise
Police Phone Checks Followed Report on Murder of MI5 Agent Inside Sinn Féin
Archbishop of Canterbury Reaffirms £100 Million Reparative Justice Fund During Ghana Visit
Charities Allege French Police Used Tear Gas Against Channel Migrants
Norwegian Teenager Convicted Over Iran-Linked Murder Plot in Britain
Christian Organisations File Charity Complaints Against Amnesty International UK
Ofgem Tightens Grid Connection Rules for New Data Centres
FTSE 100 Reaches Record High Despite Global Technology Sell-Off
Millions of UK Households Urged to Check Eligibility for Winter Energy Discount
Labour Restores Parliamentary Whips to Diane Abbott and Joani Reid
UK Supreme Court to Hear Challenge Over Palestine Action Ban
UK Commits More Than £8.4 Billion to Dreadnought Nuclear Submarine Programme
England Declares Severe Drought as Wildfire Burns Near Sizewell Nuclear Site
Bank of England Holds Interest Rates at 3.75% as Middle East Tensions Fuel Inflation Risks
Drought Status Extended Across All of Wales as Heat and Dry Weather Deepen Environmental Strain
Record-Low Danube Exposes Probable Mammoth Remains in Bulgaria
UK Business Confidence Climbs to Four-Month High
Greater Manchester Gains Expanded Powers Under Regional Funding Reforms
UK Supreme Court to Hear Appeal Over Palestine Action Terror Ban
Shell's Quarterly Profit Doubles to Nearly $10 Billion on Higher Energy Prices
UK Government Removes VAT From Household Electricity Bills
Exceptional Drought Grips Half of England as Wildfire Threatens Sizewell
Bank of England Holds Interest Rates at 3.75% as Inflation Risks Persist
US Says It Has Carried Out Heavy Strikes on Iran After Attempted Attacks on Its Forces
The chief executive of the popular gaming company laid off many employees and his pay rose to 38 million dollars
UK Employment Holds Steady as Wage Growth Remains Moderate
England to Introduce Artificial Intelligence into Secondary School Curriculum
Wales Launches £1.2 Billion Industrial Regeneration Programme
High Court Upholds UK Digital Surveillance Framework
Northern Ireland Reaches Budget Agreement on Infrastructure and Public Sector Pay
Home Office Expands Digital Border Checks Nationwide
UK Approves Major North Sea Wind and Carbon Capture Project
The World's Most Terrifying Smartphone: Recording, Documenting, and Reporting to the Regime
Scotland Approves Major Renewable Energy Expansion
UK and United States Sign AI and Semiconductor Cooperation Pact
UK Treasury Tightens Fiscal Controls After Gilt Market Volatility
Bank of England Holds Interest Rates at 4.5%
UK Unveils £10 Billion NHS Funding Overhaul and Workforce Reform
The AI User Nightmare: Private Claude Conversations Leaked to the Internet
UK: Former Football Association Leaders Call for World Cup Boycott Over FIFA Privatization Plan
Forbidden Love: China severs millions from their virtual partners
×