Microsoft SharePoint Attacks: What You Need To Know
In July 2025, a wave of cyberattacks struck Microsoft SharePoint servers worldwide, exploiting zero-day vulnerabilities dubbed “ToolShell.” These flaws were used in a campaign that compromised hundreds of organisations, including government agencies, universities, and energy companies. For IT leaders, this is more than a headline. SharePoint sits at the centre of many businesses’ collaboration and workflow, and a breach can expose sensitive data, disrupt operations, and damage trust. The ToolShell attacks highlight how quickly threat actors can exploit weaknesses and why proactive protection is essential. How the Attacks Unfolded The campaign began in early July and intensified later in the…
In July 2025, a wave of cyberattacks struck Microsoft SharePoint servers worldwide, exploiting zero-day vulnerabilities dubbed “ToolShell.” These flaws were used in a campaign that compromised hundreds of organisations, including government agencies, universities, and energy companies.
For IT leaders, this is more than a headline. SharePoint sits at the centre of many businesses’ collaboration and workflow, and a breach can expose sensitive data, disrupt operations, and damage trust. The ToolShell attacks highlight how quickly threat actors can exploit weaknesses and why proactive protection is essential.
How the Attacks Unfolded
The campaign began in early July and intensified later in the month. Attackers exploited two flaws in SharePoint: one allowing remote code execution, the other enabling spoofing. Together, these exploits became known as “ToolShell.”
Although Microsoft released initial patches during July’s Patch Tuesday, they proved incomplete. Within days, attackers found ways around them, forcing Microsoft to issue emergency updates on 19 July, along with guidance on rotating cryptographic keys to fully mitigate the issue.
Who’s Behind These Attacks?
Nation-State:
Microsoft attributed the first wave to Chinese state-backed groups: Linen Typhoon, Violet Typhoon, and Storm-2603. These groups targeted internet-facing SharePoint servers to steal sensitive data and, in Storm-2603’s case, deploy ransomware.
Opportunistic Threat Actors:
Beyond espionage, opportunistic attackers have also joined in. Researchers spotted a ransomware strain called “4L4MD4R,” deployed in late July by criminals seeking profit. This shows ToolShell is being exploited both for state-level espionage and for quick financial gain.
Microsoft’s Response: Faulty Patches
Patch Insufficiencies:
Microsoft’s first patches for ToolShell did not fully fix the problem, leaving servers vulnerable. Attackers exploited this gap almost immediately.
Security Criticism:
Analysts and lawmakers criticised Microsoft’s patching process, arguing that incomplete updates may have helped attackers. The incident raised wider questions about reliance on legacy on-premises systems when cloud-based SharePoint Online was unaffected.
Implications for Businesses Using SharePoint
The ToolShell exploits directly affect on-premises SharePoint versions (2016, 2019, and Subscription Edition). SharePoint Online remains unaffected.
For businesses still running SharePoint servers in-house, risks include:
- Unauthorised access and impersonation of users
- Persistent backdoors and hidden admin accounts
- Theft of cryptographic keys and authentication tokens
- Data exfiltration and ransomware attacks
Sectors holding sensitive data, such as government, education, and critical infrastructure, face the greatest risk and should act quickly to secure systems.
Future-Proofing IT Infrastructure with Optimising IT
At Optimising IT, we help businesses prepare for, and defend against, fast-moving threats like ToolShell. Our services include:
- Rapid Incident Response: Containing breaches quickly to minimise damage.
- Secure Patch Deployment & Key Management: Applying updates correctly and managing cryptographic keys to prevent backdoor access.
- Vulnerability Assessments: Regular scanning and penetration testing to find weaknesses before attackers do.
- Strategic Cloud Migration: Helping organisations move workloads like SharePoint to secure cloud environments, improving resilience and compliance.
Don’t wait for the next attack to test your defences. Contact us today to book your Cyber Security Audit. Together, we can ensure your business continues to run, protect, and grow with confidence.
Book a Meeting
Run, Protect
and Grow, Your Business
Company News









