Map of Australia with highlighted cities

Businesses are urged to take steps immediately to mitigate massive data breach tied to Chinese hackers

Published on March 9, 2021

Tweet

CISA urges ALL organizations across ALL sectors to follow guidance to address the widespread domestic and international exploitation of Microsoft Exchange Server product vulnerabilities; see CISA’s newly released web page for details. https://t.co/VwYqAKKUt6. #Cyber #InfoSec

— US-CERT (@USCERT_gov) March 9, 2021

The alarm about the ongoing hack of Microsoft Exchange Server, which began as early as January, appears quite justified. Microsoft believes a state-sponsored Chinese group called Hafnium orchestrated the attack that exploited flaws in Exchange software to gain access to email accounts and install unauthorized software, gaining full control of affected systems.

Hafnium primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks and NGOs, according to Microsoft.

In a tweet, the United States Cybersecurity and Infrastructure Security Agency (CISA) urged “ALL organizations” across “ALL sectors” to follow its guidance to address the email software’s vulnerabilities.

The number of U.S.-based organizations affected is estimated to be at least 30,000, while worldwide that number is close to 100,000. The vulnerability can be exploited to compromise networks, steal information, encrypt data for ransom, or even execute a destructive attack. CISA advises business leaders at all organizations to ask IT personnel to immediately address this incident or get third-party IT support.

A Hafnium attack should trigger any cyber insurance an organization has in place, according to Lockton, an insurance broker.  Lockton recommends that organizations contact their insurer only if they discover that the vulnerabilities being exploited are present in the system. If an attack is underway, it should be reported to cyber insurers immediately.

Related Articles

Map of Australia with highlighted trades

June 10, 2019

J.D. Power Study on insurers and data: a matter of trust

Read more >
Map of Australia with highlighted trades

February 13, 2020

Uncertainty Clouds Business Risks Related to Covid-19 Coronavirus

Read more >
Map of Australia with highlighted trades

May 12, 2020

U.S. Treasury weighs in on debate surrounding business interruption insurance

Read more >
Map of Australia with highlighted trades

August 22, 2023

National Black Business Month – Dale Sharpe Jenkins, M.S., CIC, AINS, Owner, The Jenkins Agency Incorporated, Celebrates 25 Years in Business

Read more >
Map of Australia with highlighted trades

September 15, 2020

Student Hacker Teams Showcase Their Winning Skills at PennApps 3rd Annual Hack-for-Resilience Competition

Read more >
Map of Australia with highlighted trades

March 2, 2022

Political & Trade Credit Insurers Protect Against Asset, Profit Losses for Businesses in Ukraine

Read more >