Tech

The Microsoft Exchange hack shows attackers are working 'smarter, not harder,' experts say

Microsoft.
Microsoft announced a hack in its Exchange email servers on March 3. Cindy Ord/Getty Images
Read in app

News about a hack that impacted hundreds of thousands of global organizations has largely flown under the radar. 

On March 3, Microsoft announced Hafnium, a Chinese-sponsored hacker group, exploited vulnerabilities in its Exchange email servers. Microsoft said hackers left behind "web shells," or tools that allow bad actors to access victims' systems remotely after initial access.

The attack impacted hundreds of thousands of organizations globally and 30,000 in the US. Experts recently told Insider's Aaron Holmes the hack could be "1,000 times more crippling" than the widely publicized SolarWinds attack. 

Cyber security experts say though the Exchange server hack has not shocked Americans the way the SolarWinds attack did last year, but citizens must pay attention because of the likely increase in hacks this year and the different ways bad actors are exploiting victims.

Read more: Congress looks to tap big companies like Microsoft to prevent the next SolarWinds cybersecurity disaster, but critics warn that approach could stifle innovation

"This attack underscores just how vulnerable even the most secure organizations or individuals are when targeted by skilled cybercriminals," Marcin Klecyznski, the CEO of Malwarebytes, told Insider.

Why you should care about the attack

One takeaway from the Exchange Server attack is that no one is safe from a hack.

Microsoft is an industry leader that accelerated cloud-based security efforts as offices transitioned to remote work during the pandemic. But getting hacked means companies need to develop software with security in every step, as well as have an incident response plan to patch flaws and notify users, per Jonathan Knudsen, a senior security strategist at Synopsys Software Integrity Group.

The hack also suggests cybercriminals are working "smarter, not harder," said Klecyznski. Bad actors know IT security teams' resources have become more stretched due to the rise in remote work, and hackers are looking to advantage of that gap in oversight, he said.

Read more: Cybersecurity execs from Visa, Netflix, Uber, and more share their underrated security tips, from vetting supply chains to 'devaluing data'

Knudsen advises anyone responsible for a Microsoft Exchange server to patch the system and check for signs of an attack. Systems administrators also need to update servers and carefully examine systems at all times, because hackers can have access to a device for months or years before someone notices. 

Kelvin Coleman, the executive director at the National Cyber Security Alliance, said security experts are still unsure of the hackers' motivations, and whether the incident may have been a "test run" for a larger attack — which makes protecting user accounts with quality passwords and multi-factor authentication imperative.

"It can impact a lot of things if folks don't have confidence that their information is protected and secure," Coleman said.

How the Microsoft Exchange hack differs from other attacks

SolarWinds hackers were able to spy on federal agencies like the Department of Homeland Security and Treasury Department. Coleman said the Microsoft attack has received relatively less media attention due to the victims being small- to mid-size organizations and local governments, but that still leaves systems and personal information vulnerable.

The attack also differs from others because hackers did not need to interact with victims to get access to their information, said Ben Read, the senior manager for Cyber Espionage Analysis in FireEye's Intelligence unit. Unlike a phishing scam, which relies on users clicking into a link with malware, the Exchange Server attack gave hackers more control.

Read said that, though this isn't the first time this kind of attack happened, there's been a rise in vulnerabilities in web-facing applications in the past 18 months. Analysts predict cyber attacks will dramatically increase this year as hackers exploit uncertainty around COVID-19 and take advantage of remote workers.

"The sheer number of victims makes it a big deal," Read said in an interview with Insider. "Anyone who hasn't taken mitigation efforts...they're vulnerable as other groups kind of figure out how to exploit these vulnerabilities."

Read next

Allana Akhtar was a senior health reporter for Insider, where she covers the emerging wellness industry and general health topics. During the COVID-19 pandemic, Allana wrote extensively about nurses, mask mandates, the vaccine rollout, and disparities in access to health. Her articles include features on nurses needing to re-use PPE in the early days of the pandemic, ones who struggled to get paid time off after getting COVID-19, and those who left bedside care after grueling pandemic working conditions. Allana also spoke to flight attendants and retail workers who faced violence as they enforced mask mandates, and community health workers who said they struggled to receive equitable vaccine access during the initial rollout. Allana now reports on emerging trends within the wellness industry, including the Westernization of indigenous medicine and dangerous wellness trends spread through social media. She also writes about plastic surgery, racial disparities in healthcare, and breaking health news. Allana has won numerous awards for her work, including the Best News Story by the Michigan Press Association in 2015, Best Reporter Covering Nurses in 2019, and the Morris and Lola Wasserstein Award for her contribution to the the University of Michigan's student paper as an Honors student. Before Insider, Allana wrote for USA TODAY, US News & World Report, Money Magazine, Health Magazine, Jalopnik, and more. You can email her at aakhtar@bjinnox.com, call/text her at (646) 376-6058, or follow her on Instagram, TikTok, Twitter, and LinkedIn. Secure tips line: Signal # 248 760 0208'We're grossly unprepared': Nurses share their frustration as the coronavirus spreads with little direction from the government or hospitals on how to mitigate it'Sexy nurse' costumes demean one of the most in-demand professions in American life — and they're a bestseller on Amazon right nowFlight attendants describe 'unprecedented' violence as travel returns and passenger aggression soarsG/O Media fired a queer employee of color who wore crop tops, shorts, and heels to work, violating a brand-new dress code that others say they routinely violated without being punishedContractors at controversial startup Rev say they worked long hours for little pay, feared they could lose their job at any time, and had to transcribe interviews with sexual-abuse survivors without warning