Microsoft
Disclosed Mar 2, 20215 years agoConfirmed
Hafnium exploits Exchange Server zero-days to breach on-premises mail servers
Microsoft disclosed that a China-based state-sponsored actor it calls Hafnium used previously unknown exploits in on-premises Exchange Server to access email accounts and install web shells, and released emergency patches; many organizations worldwide were compromised.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Mar 2, 2021 |
| Attack | Hacking |
| Data exposed | Emails, Credentials and tokens, Messages |
| Sector | Tech · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| New nation-state cyberattacksblogs.microsoft.com · The organization | The organization |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Mar 2, 2021 |
Other breaches at Microsoft
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.