Case File

Hafnium: How China Hacked Microsoft Exchange in 2021

Chinese state-sponsored hackers compromised tens of thousands of servers worldwide — and a security patch accidentally made it worse

🌍 International

Published June 6, 2025

A compromised Microsoft Exchange server displays a terminal screen filled with cryptic code, cables snaking out as a technician in the background examines the setup, symbolizing the widespread impact of the 2021 Hafnium cyberattack.
EVIDENCE

Quick facts

LocationChina (Hafnium operations origin)

January 2021: Hafnium Strikes Microsoft Exchange Servers

In January 2021, Hafnium — a Chinese state-sponsored hacking group linked to China's Ministry of State Security (MSS) — launched one of the most far-reaching cyberattacks in recent memory. The group exploited four previously unknown vulnerabilities in Microsoft's Exchange Server. Microsoft publicly disclosed the attack on March 2, 2021. By that point, the intrusions, which had begun in January, had already compromised tens of thousands of servers belonging to thousands of organizations worldwide. Victims included government institutions, defense contractors, law firms, and research organizations. Despite Microsoft's rapid release of patches, the attackers had installed backdoors that gave them persistent access to victims' networks — a latent threat that lingered long after the official disclosure.

Who Is Hafnium? Chinese Specialists in Espionage

Microsoft Exchange Server is a cornerstone of communication infrastructure for countless organizations, making it a prized target for sophisticated state-sponsored actors. Microsoft described Hafnium as a "highly specialized and sophisticated" group tied to China's Ministry of State Security, believed to have operated largely undetected since the 2010s. Their primary espionage targets were typically entities in the United States, including organizations in critical sectors such as bioscience, the defense industry, and human rights groups, with the aim of harvesting sensitive intelligence.

The Technical Details: Four Vulnerabilities That Opened the Door

The attack exploited four specific vulnerabilities, collectively known as ProxyLogon, which were especially dangerous in combination. First, a Server-Side Request Forgery flaw (CVE-2021-26855) was used to bypass authentication and gain administrator access. Next, a bug in the Unified Messaging service (CVE-2021-26857) enabled remote code execution. Two file-write vulnerabilities (CVE-2021-26858 and CVE-2021-27065) then allowed the installation of webshells, including the notorious China Chopper, giving attackers persistent backdoor access. A critical factor was that the attacks could be carried out over the standard HTTPS port 443, making them difficult to distinguish from legitimate encrypted internet traffic.

Timeline

5 January 2021

Microsoft is informed

Microsoft receives the first information about the vulnerabilities in Exchange Server from security researchers.

6 January 2021

First documented attack

Log data shows the first Hafnium attacks against selected targets in the US and Europe. Targeted exfiltration of email mailboxes begins.

2 March 2021

Microsoft releases patches

Microsoft discloses the vulnerabilities and releases security updates for Exchange Server. Tens of thousands of servers have already been compromised.

3 March 2021

Mass attacks begin

After the patches are released, various hacker groups begin attacking unpatched servers on a large scale. Escalation to a global security emergency.

10 March 2021

Over 250,000 servers affected

Security researchers estimate that more than 250,000 Exchange servers worldwide have been compromised. Ransomware attacks increase.

19 July 2021

Official attribution to China

The US, EU and allies officially hold China responsible for the Hafnium attacks. Diplomatic tensions increase.

Early January 2021: Mailboxes Stolen, Microsoft Alerted

Log analyses from security firms indicate the earliest phases of the attack began as early as January 6, 2021. At this stage, Hafnium focused on extracting complete mailboxes from carefully selected, high-profile targets, primarily in the United States and Europe — constituting a serious data breach. Microsoft was notified of the vulnerabilities on January 5. Patches were not released until March 2, 2021, approximately two months later.

The Patch Paradox: How the Security Update Spread the Attack

The release of the patch unfortunately triggered an unexpected escalation. Both security researchers and criminal groups immediately began analyzing it through reverse engineering to understand exactly how the vulnerabilities worked. This opened the door for at least nine other state-sponsored and criminal actors, who rapidly developed their own tools to exploit the flaws. The result was an explosive global spread of cybercrime, striking a wide range of organizations including oil companies, IT suppliers, and government bodies, particularly in the Middle East.

March 2021: Ransomware Spreads Through Compromised Servers

On March 12, 2021, Microsoft observed a serious new development: ransomware was being distributed through the already-compromised Exchange servers. New ransomware families were deployed to previously infected servers, encrypting entire systems and paralyzing victims' operations. As one example of the consequences, the European Banking Authority (EBA) was forced to shut down its email systems after sensitive banking data was stolen. It is important to note that Hafnium itself was primarily associated with espionage; it was other criminal groups that subsequently exploited the same vulnerabilities to carry out ransomware attacks.

The Human Cost: Stolen Data and Research Espionage

The impact of this massive cyberattack was not limited to large organizations. Small businesses and local authorities were also caught in the crossfire. A local clinic in Texas reported that patients' medical records were stolen in a data breach later used for identity theft. In Norway, the parliament's email systems had to be shut down for three weeks, delaying critical legislative work. Particularly disturbing were allegations that research from Western institutions was stolen through these attacks.

Aftermath: Criticism of Microsoft and CISA's Emergency Patches

The fallout from the Hafnium attack sparked intense debate about Microsoft's crisis management. Although patches were available, many organizations lacked the resources or expertise to quickly deploy the often complex server updates. The severity of the situation prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to issue emergency patches for older, unsupported versions of Exchange — an unusual step that underscored the scale of the threat. Analysis revealed that a striking 45% of affected organizations had not installed the patches within the critical first week. The attack also highlighted the importance of continuous log monitoring, as many victims only discovered the intrusion when their servers began transmitting large volumes of data to unknown destinations — a clear sign of an active breach.

A Grim Turning Point for State-Sponsored Cyber Espionage

The 2021 Microsoft Exchange attack, orchestrated by Hafnium, marks a grim turning point in the history of state-sponsored cyber espionage. By targeting infrastructure as fundamental as Exchange Server, the perpetrators achieved an unprecedented scale of compromise — enabled not only by the exploitation of advanced zero-day vulnerabilities, but also by the aggressive reverse engineering of the very security updates meant to stop them. The episode lays bare the existential risk of placing blind trust in a single security product and underinvesting in robust cybersecurity practices. In July 2021, the United States, the European Union, and their allies formally attributed the attacks to China, further raising diplomatic tensions. In an era where the boundaries of cyberspace are constantly tested and the threat of digital warfare is real, this scandal stands as a stark example of how a single vulnerability can trigger a cascade of global consequences.

Ask about this case

Answers from KrimiNyt's coverage only

Follow this case

Get an email when a new documentary, podcast or book about Hafnium: How China Hacked Microsoft Exchange in 2021 appears, or when a verdict is reached.

Share this post: