Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

China accuses US of cyberattacks via Microsoft flaw

China has accused the US of using a Microsoft Exchange vulnerability to conduct cyberattacks against its defense sector.

The Cyber Security Association of China claimed US actors controlled servers of a key Chinese military company for nearly a year by exploiting the flaw.

Microsoft has previously attributed several major cyberattacks involving its Exchange software to Chinese groups.

In 2021, tens of thousands of Exchange servers were reportedly compromised in a suspected Chinese operation.

A 2023 incident allegedly led to the breach of senior US officials’ email accounts, which a US review later described as a “cascade of security failures” at Microsoft.

Last month, Microsoft reported that Chinese state-linked groups exploited vulnerabilities in its SharePoint software.

Eye Security estimated about 400 organizations were affected, mostly in the US, with others in Mauritius, Jordan, South Africa, and the Netherlands.

🔗 Source: Bloomberg


🧠 Food for thought

1️⃣ Cyber attribution has become a tool of geopolitical competition

China’s accusation against the US reflects how cyber attribution has evolved into a strategic communication weapon between rival nations.

According to the Council on Foreign Relations’ Cyber Operations Tracker, China, Russia, Iran, and North Korea are responsible for 77% of all suspected state-sponsored cyber operations since 2005, with espionage being the most common activity1.

This creates a climate where accusations flow in both directions. For example, the US Justice Department recently charged seven Chinese nationals with conspiracy to commit computer intrusions, while China now counters with its own attribution claims2.

The back-and-forth nature of these accusations suggests that public attribution has become less about establishing definitive proof and more about shaping international narratives around cyber conflict.

2️⃣ Unpatched vulnerabilities in widely-used software create persistent national security risks

The focus on Microsoft Exchange vulnerabilities highlights how flaws in ubiquitous business software become attractive targets for state-sponsored hackers.

Recent Microsoft developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.