Microsoft Exchange cyberattack carried out by China, says US

Zero-day attack
(Image credit: Shutterstock) (Image credit: Shutterstock.com)

The US has formally accused China of being behind the cyberattack on Microsoft Exchange servers that occurred back in March of this year.

However, the US wasn't alone in its condemnation of China as it was joined by NATO, the European Union and its allies Britain, Australia, Japan, New Zealand and Canada. According to US Secretary of State Antony Blinken, the cyberattack posed “a major threat to our economic and national security”.

US President Joe Biden provided further insight on the situation to reporters during an event discussing his infrastructure plan, saying:

"My understanding is that the Chinese government, not unlike the Russian government, is not doing this themselves, but are protecting those who are doing it. And maybe even accommodating them being able to do it."

At the same time as the US government called out China for its role in the attacks on Microsoft Exchange servers, the US Department of Justice charged four Chinese nationals with (three security officials and one contract hacker) with targeting dozens of companies, universities and government agencies around the world.

Lack of consequences

Back in April of this year, the US government hit Russia with sanctions as a result of the country's connections to last December's SolarWinds hack.

This time around though, the US has called out China, who it believes is either behind or at least supported those responsible for attacking vulnerable Microsoft Exchange servers, though it has not placed sanctions on the country. Cybersecurity experts that spoke with Reuters find the lack of consequences for China over its involvement in the hack concerning.

The US could take further action though as White House Press Secretary Jen Psaki said that: "We are not holding back, we are not allowing any economic circumstance or consideration to prevent us from taking actions ... also we reserve the option to take additional action".

While the US has formally accused China's Ministry of State Security (MSS) of being behind the cyberattack, NATO has said that its members “acknowledge” the allegations leveled against China by the US, Canada and the UK.

We'll have to wait and see as to how China responds and whether or not the cybercriminals responsible decide to ramp up their attacks or wind them down following this formal accusation.

Via Reuters

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
China
Chinese hackers who targeted key US infrastructure charged by Justice Department
China
US Treasury declares ‘major incident’ after apparent state-sponsored Chinese hack
An American flag flying outside the US Capitol building against a blue sky
More alleged Chinese intrusions into the US Treasury revealed
An American flag flying outside the US Capitol building against a blue sky
Chinese cybersecurity firm sanctioned by US Treasury over alleged links to Salt Typhoon hackers
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
A major FBI operation has deleted Chinese malware from thousands of US computers
Latest in Security
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
Scam alert
A new SMS energy scam is using Elon Musk’s face to steal your money
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
Latest in News
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
iOS 18 Control Center
iOS 19: the 3 biggest rumors so far, and what I want to see
Doom: The Dark Ages
Doom: The Dark Ages' director confirms DLC is in the works and says the game won't end the way 2016's Doom begins: 'If we took it all the way to that point, then that would mean that we couldn't tell any more medieval stories'
DVDs in a pile
Warner Bros is replacing some DVDs that ‘rot’ and become unwatchable – but there’s a big catch that undermines the value of physical media
A costumed Matt Murdock smiles at someone off-camera in Netflix's Daredevil TV show
Daredevil: Born Again is Disney+'s biggest series of 2025 so far, but another Marvel TV show has performed even better
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024