NCSC Annual Review 2021
Pages
Page 11 of 44
Microsoft Exchange
Research and analysis carried out by the NCSC enabled the UK Government in July 2021 to call out Chinese state-backed actors for gaining access to computer networks around the world via Microsoft Exchange servers in what is the most significant and widespread cyber intrusion against the UK and allies ever observed by the NCSC.
NCSC experts assessed the attack was highly likely to enable large-scale espionage, including acquiring personally identifiable information and intellectual property. It was reported that at least 30,000 organisations were compromised in the US alone, with many more affected worldwide.
As part of a UK Government response, the NCSC issued tailored advice to over 70 affected organisations to enable them to mitigate the effects of the compromise.
The NCSC used its technical understanding of the Chinese cyber threat to inform the attribution and the subsequent multi-lateral efforts when the UK joined 38 partners, including the Five Eyes, NATO, the EU and Japan, to attribute variously HAFNIUM,
APT31 and/or APT 40 to the Chinese state. Acts included the targeting of maritime industries and naval defence contractors in the US and Europe, and targeting of foreign democratic institutions, including the Finnish parliament in 2020.
The attack on Microsoft Exchange servers was another serious example of a malicious act by Chinese state- backed actors in cyberspace. This kind of behaviour is completely unacceptable and alongside our partners we will not hesitate to call it out when we see it.
Paul Chichester, NCSC’s Director of Operations