The Frank
Home
Today's Fastrack
About
Subscribe
Nuclear Weapons Agency Breached in Microsoft Hack

Nuclear Weapons Agency Breached in Microsoft Hack

author
author

The Frank Staff

The Frank Staff.
[email protected]
@TheFrank_com
The Frank Staff
author

The Frank Staff

The Frank Staff.
[email protected]
@TheFrank_com

Jul 23, 2025

·

0 min read

Share options

Email
Facebook
X
Telegram
WhatsApp
Reddit

Microsoft has warned that Chinese state-sponsored hackers have breached its SharePoint software used by the US agency responsible for maintaining and modernizing the nation’s stockpile of nuclear weapons, according to a report.

The National Nuclear Security Administration, a semi-autonomous agency that operates under the auspices of the Department of Energy, was among the targets of a hack allegedly carried out by Chinese-backed cybercriminals, according to Bloomberg News.

A Dutch cybersecurity company estimates that around 400 government agencies in the US, Mauritius, Jordan, South Africa and the Netherlands were impacted by the hack, according to Bloomberg News.

The Dutch firm, Eye Security, previously estimated that just 60 entities were impacted.

A source familiar with the situation told the financial news site on Tuesday that no sensitive or classified information was known to have been stolen in the hack, which was made possible by exploiting a flaw in Microsoft’s SharePoint document management software.

“On Friday, July 18th, the exploitation of a Microsoft SharePoint zero-day vulnerability began affecting the Department of Energy,” an agency spokesman told Bloomberg News.

“The department was minimally impacted due to its widespread use of the Microsoft M365 cloud and very capable cybersecurity systems. A very small number of systems were impacted. All impacted systems are being restored.”

The breaches have been ongoing since at least July 7, according to Adam Meyers, senior vice president at CrowdStrike, the cybersecurity firm that has partnered with Microsoft to ward off potential cyber threats.

“The early exploitation resembled government-sponsored activity, and then spread more widely to include hacking that ‘looks like China’,” Meyers told Bloomberg News. CrowdStrike’s investigation into the campaign remains ongoing.

Eye Security’s Vaisha Bernard confirmed in an email to The Post that the firm has identified 400 confirmed compromised SharePoint servers worldwide — most of them being in the US, Netherlands, Germany, France, Vietnam, Australia, Canada and the UAE.

According to Bernard, Eye Security cannot confirm an NNSA breach but has seen compromised US government servers.

“We estimate that the real number might be much higher as there can be many more hidden ways to compromise servers that do not leave traces,” Bernard told The Post via email.

In a blog post, the tech giant identified two reputed cybercriminal organizations, Linen Typhoon and Violet Typhoon, in the alleged scheme to exploit flaws in Microsoft’s software that is used by customers on their own networks rather than in the more secure cloud.

These customers are at risk of having their data compromised by the hackers, according to Microsoft, which also fingered a third Chinese-based organization, Storm-2603, as doing the same.

Microsoft SharePoint is a platform used to store, organize, share and manage internal web content across an organization — similar to intranets.

The NNSA wasn’t the only agency that was targeted in the alleged cyberattack.

Among the victims are the US Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly, which is the Ocean State’s legislative body.

Internationally, governments in Europe and the Middle East have also been targeted. Cybersecurity researchers have detected breaches on more than 100 servers, representing at least 60 victims across various sectors, including energy, consulting and academia.

Microsoft has patched the vulnerabilities in recent days, but the company expressed concern that hackers will continue to exploit these flaws in future attacks.

“We have high confidence that threat actors will continue to integrate them into their attacks,” Microsoft stated in its blog post.

“China opposes and fights hacking activities in accordance with the law. At the same time, we oppose smears and attacks against China under the excuse of cybersecurity issues,” a spokesperson for the Chinese embassy said in a statement.

Cybersecurity experts have expressed grave concerns about the severity of the threat.

Michael Sikorski, chief technology officer and head of threat intelligence for Unit 42 at Palo Alto Networks Inc., described the situation as a “high-severity, high-urgency threat.”

He emphasized the risks posed by SharePoint’s deep integration with Microsoft’s ecosystem, which includes services like Office, Teams, OneDrive and Outlook — all of which contain valuable data for attackers.

Eye Security reported that the flaws allow hackers to access SharePoint servers and steal authentication keys, enabling them to impersonate users or services even after patches are applied.

“We estimate that the real number might be much higher as there can be many more hidden ways to compromise servers that do not leave traces,” Eye Security’s co-owner Vaisha Bernard said in an email to Bloomberg News.

“This is still developing, and other opportunistic adversaries continue to exploit vulnerable servers.”

Despite Microsoft’s efforts to bolster its security measures, including hiring executives from government agencies and holding weekly security meetings, the recent breaches have drawn renewed scrutiny.

The US government issued a report last year that was critical of Microsoft’s lax security culture.

Share options

Email
Facebook
X
Telegram
WhatsApp
Reddit

Greta Thunberg Arrested After Israel Intercepts Gaza Flotilla

Oct 2, 2025

4 min

Trump Pledges to Defend Qatar Against ‘Any Attack’

Oct 2, 2025

2 min

Secret Service Agent Fell Asleep at UN General Assembly

Oct 2, 2025

3 min

Supreme Court Allows Lisa Cook to Stay on Fed

Oct 2, 2025

2 min

Musk Calls for Netflix Boycott Over Pro-Trans Cartoon

Oct 2, 2025

2 min

Trump Freezes $18B in NYC Funding

Oct 2, 2025

3 min

Mass Shutdown Firings to Begin 'In a Day or Two'

Oct 2, 2025

2 min

Bomb Squad Detonates Device Before TPUSA Utah Event

Oct 2, 2025

2 min

ADP: US Lost 32,000 Jobs in September

Oct 2, 2025

2 min

FBI Cuts Ties with ADL

Oct 1, 2025

2 min

J.K. Rowling Slams Emma Watson Over Trans Views

Oct 1, 2025

2 min

Chimp Expert Jane Goodall Dies at 91

Oct 1, 2025

2 min

Hegseth Declares End to 'Woke' Military

Oct 1, 2025

6 min

Trump Wants Military Training in Dem Cities

Oct 2, 2025

1 min

Trump and Pfizer Announce Deal to Lower Drug Prices

Oct 2, 2025

3 min

US Deports 120 Iranians Back to Tehran

Oct 1, 2025

3 min

Trump’s Presidential Library to Be Built in Florida

Oct 1, 2025

2 min

Scientists Use Cloning Tech to Swap DNA in Human Eggs

Oct 1, 2025

2 min

Trump Wins $24.5M YouTube Settlement

Sep 30, 2025

1 min

Trump, Dems Leave Meeting Without Shutdown Deal

Sep 30, 2025

<1 min

  • Today's Fastrack
  • About
  • Contact
  • Policy & Terms
  • Recaptcha