Hafnium: How China Hacked Microsoft Exchange in 2021
Chinese state-sponsored hackers compromised tens of thousands of servers worldwide — and a security patch accidentally made it worse
Published June 6, 2025

Case Details
Quick Facts
Classification:
Quick facts
January 2021: Hafnium Strikes Microsoft Exchange Servers
In January 2021, Hafnium — a Chinese state-sponsored hacking group linked to China's Ministry of State Security (MSS) — launched one of the most far-reaching cyberattacks in recent memory. The group exploited four previously unknown vulnerabilities in Microsoft's Exchange Server. Microsoft publicly disclosed the attack on March 2, 2021. By that point, the intrusions, which had begun in January, had already compromised tens of thousands of servers belonging to thousands of organizations worldwide. Victims included government institutions, defense contractors, law firms, and research organizations. Despite Microsoft's rapid release of patches, the attackers had installed backdoors that gave them persistent access to victims' networks — a latent threat that lingered long after the official disclosure.
Who Is Hafnium? Chinese Specialists in Espionage
Microsoft Exchange Server is a cornerstone of communication infrastructure for countless organizations, making it a prized target for sophisticated state-sponsored actors. Microsoft described Hafnium as a "highly specialized and sophisticated" group tied to China's Ministry of State Security, believed to have operated largely undetected since the 2010s. Their primary espionage targets were typically entities in the United States, including organizations in critical sectors such as bioscience, the defense industry, and human rights groups, with the aim of harvesting sensitive intelligence.
The Technical Details: Four Vulnerabilities That Opened the Door
The attack exploited four specific vulnerabilities, collectively known as ProxyLogon, which were especially dangerous in combination. First, a Server-Side Request Forgery flaw (CVE-2021-26855) was used to bypass authentication and gain administrator access. Next, a bug in the Unified Messaging service (CVE-2021-26857) enabled remote code execution. Two file-write vulnerabilities (CVE-2021-26858 and CVE-2021-27065) then allowed the installation of webshells, including the notorious China Chopper, giving attackers persistent backdoor access. A critical factor was that the attacks could be carried out over the standard HTTPS port 443, making them difficult to distinguish from legitimate encrypted internet traffic.
Timeline
Microsoft is informed
Microsoft receives the first information about the vulnerabilities in Exchange Server from security researchers.
First documented attack
Log data shows the first Hafnium attacks against selected targets in the US and Europe. Targeted exfiltration of email mailboxes begins.
Microsoft releases patches
Microsoft discloses the vulnerabilities and releases security updates for Exchange Server. Tens of thousands of servers have already been compromised.
Mass attacks begin
After the patches are released, various hacker groups begin attacking unpatched servers on a large scale. Escalation to a global security emergency.
Over 250,000 servers affected
Security researchers estimate that more than 250,000 Exchange servers worldwide have been compromised. Ransomware attacks increase.
Official attribution to China
The US, EU and allies officially hold China responsible for the Hafnium attacks. Diplomatic tensions increase.
Early January 2021: Mailboxes Stolen, Microsoft Alerted
Log analyses from security firms indicate the earliest phases of the attack began as early as January 6, 2021. At this stage, Hafnium focused on extracting complete mailboxes from carefully selected, high-profile targets, primarily in the United States and Europe — constituting a serious data breach. Microsoft was notified of the vulnerabilities on January 5. Patches were not released until March 2, 2021, approximately two months later.
The Patch Paradox: How the Security Update Spread the Attack
The release of the patch unfortunately triggered an unexpected escalation. Both security researchers and criminal groups immediately began analyzing it through reverse engineering to understand exactly how the vulnerabilities worked. This opened the door for at least nine other state-sponsored and criminal actors, who rapidly developed their own tools to exploit the flaws. The result was an explosive global spread of cybercrime, striking a wide range of organizations including oil companies, IT suppliers, and government bodies, particularly in the Middle East.
March 2021: Ransomware Spreads Through Compromised Servers
On March 12, 2021, Microsoft observed a serious new development: ransomware was being distributed through the already-compromised Exchange servers. New ransomware families were deployed to previously infected servers, encrypting entire systems and paralyzing victims' operations. As one example of the consequences, the European Banking Authority (EBA) was forced to shut down its email systems after sensitive banking data was stolen. It is important to note that Hafnium itself was primarily associated with espionage; it was other criminal groups that subsequently exploited the same vulnerabilities to carry out ransomware attacks.
The Human Cost: Stolen Data and Research Espionage
The impact of this massive cyberattack was not limited to large organizations. Small businesses and local authorities were also caught in the crossfire. A local clinic in Texas reported that patients' medical records were stolen in a data breach later used for identity theft. In Norway, the parliament's email systems had to be shut down for three weeks, delaying critical legislative work. Particularly disturbing were allegations that research from Western institutions was stolen through these attacks.
Aftermath: Criticism of Microsoft and CISA's Emergency Patches
The fallout from the Hafnium attack sparked intense debate about Microsoft's crisis management. Although patches were available, many organizations lacked the resources or expertise to quickly deploy the often complex server updates. The severity of the situation prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to issue emergency patches for older, unsupported versions of Exchange — an unusual step that underscored the scale of the threat. Analysis revealed that a striking 45% of affected organizations had not installed the patches within the critical first week. The attack also highlighted the importance of continuous log monitoring, as many victims only discovered the intrusion when their servers began transmitting large volumes of data to unknown destinations — a clear sign of an active breach.
A Grim Turning Point for State-Sponsored Cyber Espionage
The 2021 Microsoft Exchange attack, orchestrated by Hafnium, marks a grim turning point in the history of state-sponsored cyber espionage. By targeting infrastructure as fundamental as Exchange Server, the perpetrators achieved an unprecedented scale of compromise — enabled not only by the exploitation of advanced zero-day vulnerabilities, but also by the aggressive reverse engineering of the very security updates meant to stop them. The episode lays bare the existential risk of placing blind trust in a single security product and underinvesting in robust cybersecurity practices. In July 2021, the United States, the European Union, and their allies formally attributed the attacks to China, further raising diplomatic tensions. In an era where the boundaries of cyberspace are constantly tested and the threat of digital warfare is real, this scandal stands as a stark example of how a single vulnerability can trigger a cascade of global consequences.
Ask about this case
Answers from KrimiNyt's coverage onlyFollow this case
Get an email when a new documentary, podcast or book about Hafnium: How China Hacked Microsoft Exchange in 2021 appears, or when a verdict is reached.