SharePoint exploitation is now also being used to deploy ransomware
Microsoft indicated that some attackers were beginning to use SharePoint vulnerabilities to deploy ransomware.

News summary
Microsoft indicated that some attackers were beginning to use SharePoint vulnerabilities to deploy ransomware. The campaign had started with more targeted activity, but the vector was eventually adopted by more actors.
A critical vulnerability exposed to the Internet can quickly become subject to mass exploitation. Public assets require inventory, monitoring and an emergency patching procedure.
Source: Reuters — 23 July 2025
What happened
On 23 July 2025 Microsoft said some attackers had started using SharePoint vulnerabilities to deploy ransomware, according to Reuters. The campaign, which had begun with more targeted activity, ended up being adopted by more actors once the vulnerability became public.
The pattern is common: a critical flaw discovered by a small group of attackers can quickly become widely exploited once the vulnerability is broadly known, even after a patch is available.
What it means for a mid-sized business
An internet-facing asset, such as a self-managed SharePoint server, needs active management for as long as it is published. It is not enough to install it and forget about it: it requires an inventory, monitoring and an emergency patching procedure that can be activated within hours, not weeks.
The risk increases when the vulnerability affects widely used software, because attackers know many organisations will be slow to patch, extending the window of exposure.
What to review
Measures to reduce the risk of internet-exposed servers:
- Which own systems are accessible from the internet and whether they really need to be.
- Whether there is an up-to-date inventory of versions and patches for those exposed systems.
- How long the organisation typically takes to apply a critical patch once released.
- Whether active monitoring is in place to detect anomalous activity on those systems.
Frequently Asked Questions
- What is the difference between this campaign and the initial SharePoint zero-day?
- The zero-day was initially exploited by a small group; this later phase involves more attackers using the same flaw to deploy ransomware.
- Did it affect SharePoint Online?
- According to Microsoft's information, the flaw affected self-managed SharePoint servers, not SharePoint Online.
- Which measure reduces the risk most in these cases?
- Having an emergency patching procedure capable of being applied within hours for critical internet-exposed assets.
Concepts mentioned in this article: Ransomware · Vulnerability · Monitoring
Every company has different risks and needs. At Seintec, we can analyse your infrastructure and propose a tailored solution, without oversizing or overcomplicating your environment. Contact us.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.