Get 40% Off
⚠ Earnings Alert! Which stocks are poised to surge?
See the stocks on our ProPicks radar. These strategies gained 19.7% year-to-date.
Unlock full list

Microsoft says ransom-seeking hackers taking advantage of server flaws

Published 03/11/2021, 11:45 PM
Updated 03/12/2021, 10:05 AM
© Reuters. A Microsoft logo is pictured on a store in New York

By Raphael Satter

WASHINGTON (Reuters) - Ransom-seeking hackers have begun taking advantage of a recently disclosed flaw in Microsoft's widely used mail server software, the company said early Thursday - a serious escalation that could portend widespread digital disruption.

The disclosure, initially made on Twitter by Microsoft Corp (NASDAQ:MSFT) security program manager Phillip Misner and later confirmed by the Redmond, Washington-based company, is the realization of worries that have been coursing through the security community for days.

Since March 2, when Microsoft announced the discovery of serious vulnerabilities in its Exchange software, experts have warned that it was only a matter of time before ransomware gangs began using them to shake down organizations across the internet.

Misner didn't immediately respond to follow-up messages and Microsoft did not return emails seeking further comment. The U.S. Cybersecurity and Infrastructure Security Agency and the FBI also didn't immediately respond.

Even though the security holes announced by Microsoft have since been fixed, organizations worldwide have failed to patch their software, leaving them open to exploitation. Experts attribute the sluggish pace of many customers' updates in part to the complexity of Exchange's architecture and lack of expertise. In Germany alone, officials have said that up to 60,000 networks remained vulnerable.

All manner of hackers have begun taking advantage of the holes - one security firm recently counted 10 separate hacking groups using the flaws - but ransomware operators are among the most feared.

Those groups work by locking users out of their devices and data unless the victims cough up big chunks of digital currency. They now potentially have access "into a huge number of vulnerable systems," said Brett Callow of cybersecurity company Emsisoft.

He said more modest companies - many of which lack the ability or awareness to update their software - could be particularly affected by the latest variant of ransomware.

© Reuters. A Microsoft logo is pictured on a store in New York

"This is a potentially serious risk to small businesses," he said.

Latest comments

If it is microsoft and ransomware then it has to be those pesky scammers from india.
who on earth is still using Microsoft exchange
alternatives?
You clearly arent in IT.
Apparently 60,000 German networks.
Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.