WASHINGTON: More than 20,000 U.S. organizations have been compromised through a back door installed via recently patched flaws in Microsoft Corp's email software, a person familiar with the U.S. government's response said on Friday.
The hacking has already reached more places than all of the tainted code downloaded from SolarWinds Corp, the company at the heart of another massive hacking spree uncovered in December.
The latest hack has left channels for remote access spread among credit unions, town governments and small businesses, according to records from the U.S. investigation.
Tens of thousands of organizations in Asia and Europe are also affected, the records show.
The hacks are continuing despite emergency patches issued by Microsoft on Tuesday.
Microsoft, which had initially said the hacks consisted of "limited and targeted attacks," declined to comment on the scale of the problem on Friday but said it was working with government agencies and security companies to provide help to customers.
It added, "impacted customers should contact our support teams for additional help and resources."
One scan of connected devices showed only 10% of those vulnerable had installed the patches by Friday, though the number was rising.
Because installing the patch does not get rid of the back doors, U.S. officials are racing to figure out how to notify all the victims and guide them in their hunt.
All of those affected appear to run Web versions of email client Outlook and host them on their own machines, instead of relying on cloud providers. That may have spared many of the biggest companies and federal government agencies, the records suggest.
The federal Cybersecurity and Infrastructure Security Agency did not respond to a request for comment.
Earlier on Friday, White House press secretary Jen Psaki told reporters that the vulnerabilities found in Microsoft's widely used Exchange servers were "significant," and "could have far-reaching impacts."
"We're concerned that there are a large number of victims," Psaki said.
Microsoft and the person working with the U.S. response blamed the initial wave of attacks on a Chinese government-backed actor. A Chinese government spokesman said the country was not behind the intrusions.
What started as a controlled attack late last year against a few classic espionage targets grew last month to a widespread campaign. Security officials said that implied that unless China had changed tactics, a second group may have become involved.
More attacks are expected from other hackers as the code used to take control of the mail servers spreads.
The hackers have only used the back doors to re-enter and move around the infected networks in a small percentage of cases, probably less than 1 in 10, the person working with the government said.
"A couple hundred guys are exploiting them as fast as they can," stealing data and installing other ways to return later, he said.
The initial avenue of attack was discovered by prominent Taiwanese cyber researcher Cheng-Da Tsai, who said he reported the flaw to Microsoft in January. He said in a blog post that he was investigating whether the information leaked.
He did not respond to requests for further comment.
Reuters
Sat Mar 06 2021
A Microsoft logo is seen on an office building in New York City on July 28, 2015. REUTERS pic
MOE’s mental health screening identifies students with emotional challenges
Deputy Minister of Education says, those identified with severe emotional issues undergo screening twice a year.
Israel, Hezbollah agree to ceasefire brokered by US and France, to take effect Wednesday
Israel will gradually withdraw its forces over 60 days as Lebanon's army takes control of territory near its border with Israel to ensure that Hezbollah does not rebuild its infrastructure there.
'No one will win a trade war,' China says after Trump tariff threat
Donald Trump says he would impose the tariffs until China stops the flow of illegal drugs, particularly fentanyl, into the United States.
What has caused Pakistan's deadly clashes between police and supporters of Imran Khan?
Topping the demands of Khan's Pakistan Tehreek-e-Insaf (PTI) party is the release of all its leaders, including Khan, who has been jailed on a series of corruption charges since August 2023.
One woman or girl killed every 10 minutes by intimate partner or family member - UN
The report highlights that "60 per cent of all female homicides" are committed by "people closely related to them".
Sweden urges Chinese ship to return for undersea cable investigation
Two subsea cables, one linking Finland and Germany and the other connecting Sweden to Lithuania, were damaged in less than 24 hours.
[COLUMNIST] Building more highways won’t solve traffic congestion - reducing demand will
It is clear that adding more lanes and highways doesn't work, because we are still attempting the same approach to solve the issue.
Hyundai to invest RM2.16 bil in Malaysia through strategic partnership with INOKOM
This investment includes efforts to upgrade INOKOM's existing assembly capacity to meet Hyundai's automotive needs.
‘C4Cinta’ sets record as highest-grossing Malaysian Tamil film
'C4Cinta', directed by young filmmaker Karthik Shamalan, has set a new benchmark in Malaysian Tamil cinema.
Man charged with mother's murder, storing body in freezer
The court denied bail and scheduled case mention on Feb 7 for the submission of forensic, autopsy, and chemist reports.
Abolition of examination in schools to reduce pressure on pupils - Fadhlina
The classroom assessment approach offers a much more interesting learning ecosystem, says Fadhlina Sidek.
Google, Meta urge Australia to delay bill on social media ban for children
Google and Meta says the government should wait for the results of an age-verification trial before going ahead.
Judge tosses Trump 2020 election case after prosecutors' request
It represents a big legal victory for Donald Trump, who won the Nov. 5 US election and is set to return to office on Jan. 20.
DHL plane crash in Lithuania leaves authorities searching for answers
Rescue services said the plane hit the ground, split into pieces and slid over 100 metres (110 yards).
National squad to hold friendly matches for 2025 Indoor Hockey World Cup
The warm-up matches will involve matches against better ranked teams in the world, namely Austria (first) and Belgium (third).
G7 seeks unity on ICC arrest warrant for Netanyahu
The United States, part of the G7, has rejected the ICC decision, with President Joe Biden describing it as outrageous.
Francissca Peter remembers Tan Sri Ahmad Nawab: A tribute to a musical legend
A legend who has influenced our music for decades, was one of the highlights of my career, says Francissca Peter.
TikTok decision coming soon as Jan. 19 divestment deadline looms
Judges are reviewing TikTok's challenge to a law requiring ByteDance to sell its US assets by Jan. 19 or face a ban.
Lebanese sources: Biden, Macron set to announce Israel-Hezbollah truce
In Washington, White House national security spokesperson John Kirby said, "We're close" but "nothing is done until everything is done".
PM meets chaebol tycoon to attract more FDI to Malaysia
Chaebols are prominent figures from South Korea's family-owned conglomerates.