In short
Microsoft’s warning about Chinese-linked SharePoint server vulnerabilities leading to ransomware, expanding fallout across hundreds of organizations, and what it signals about cyber espionage and geopolitical tech competition.
Guests
Jennifer Eubanks, founder of Adaman Strategic Advisors; advises on cyber resilience, digital transformation, and geopolitical risk. Former CIA deputy director for digital innovation (2019–2024) and worked 30+ years in tech intelligence and national security.
Key claims
The breach began like classic espionage (information/IP theft) by government-affiliated Chinese APT groups, then within about six days shifted to ransomware/extortion. Microsoft-linked groups include “Lunen Typhoon,” “Violet Typhoon,” and “Storm 2603,” operating via a contractor ecosystem blending state and criminal actors. The U.S. approach differs; the PRC is characterized as conducting large-scale IP theft and then escalating to ransomware.
Notable examples
SolarWinds and the 2021 Exchange Server compromise as comparable “milestone” breaches; the U.S. National Nuclear Security Administration reportedly among breached entities. Safety tip: patch immediately, rotate encryption keys, hunt for compromise, and unplug if suspected.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOMicrosoft SharePoint Security Fallout
0:30 to 1:00
Discussion on the Microsoft SharePoint security breach and its impact.
“When you're running a business, the best days are the ones where priorities stay on track.”
Microsoft SharePoint Security Fallout
1:56 to 3:01
Discussion on the Microsoft SharePoint security breach and its impact.
“from the Microsoft SharePoint security issue.”
Interview with Jennifer Eubanks
3:01 to 4:23
Jennifer Eubanks discusses the implications of the cybersecurity breach.
“I am curious about how you are seeing it and kind of the level that it seemed to be able to penetrate.”
Espionage vs. Ransomware
4:23 to 6:45
Exploration of the nature of cyber threats from China and the distinction between espionage and ransomware.
“From your work in the government, is China our friend?”
U.S. Cybersecurity Strategy
6:45 to 10:46
Insights into the U.S. cybersecurity stance and the implications of technology exports to China.
“Jennifer, I've been doing this show with Carol for almost five years at this point, so I can steal a question from you that I know you're thinking about.”
Transcript
Automatic transcript. May contain errors.0:00The thing about AI for business, it may not automatically fit the way your business works. At IBM, we've seen this firsthand. But by embedding AI across HR, IT, and procurement processes, we've reduced costs by millions, slash repetitive tasks, and freed thousands of hours for strategic work. Now we're helping companies get smarter by putting AI where it actually pays off, deep in the work that moves the business. Let's create smarter business, IBM.
0:30Jennifer Ewbank:When you're running a business, the best days are the ones where priorities stay on track. For midsize and large companies, risk can affect multiple parts of the organization at once, from property and liability to cyber and regulatory challenges. At that level, managing risk becomes an ongoing discipline. At the Hartford, the focus is on helping businesses manage risk before it turns into something more disruptive. And when losses do happen, that work is paired with insurance coverage shaped by years of underwriting, risk engineering, and claims experience. Learn more at thehartford.com slash risk mitigation.
1:04Jennifer Ewbank:Policies provided by Hartford Fire Insurance Company and its property and casualty affiliates, Hartford, Connecticut. As industries evolve faster than ever, companies need an environment that accelerates strategic growth, and Michigan delivers on that promise. From emerging startups to global enterprises, Michigan offers what executives value most, a resilient, innovative ecosystem, Diverse communities that attract top talent and a quality of life that supports work-life balance. With our unified Team Michigan approach, businesses scale faster and compete at the highest level. Michigan, pure opportunity.
1:38Seize your opportunity at michiganbusiness.org. Bloomberg Audio Studios. Podcasts. Radio. News. You're listening to Bloomberg Business Week with Carol Masser and Tim Stenevek. on Bloomberg Radio. We begin this hour with the latest on the fallout from the Microsoft SharePoint security issue. Microsoft saying that a Chinese hacking group exploiting security vulnerabilities in the company's SharePoint servers to deploy ransomware follows a cyber attack discovered last week. Carol, this cyber attack has affected hundreds of entities around the world, including about 400 government agencies, corporations, and other groups.
2:18That's according to estimates from the security firm iSecurity, including the National Nuclear Security Administration. That's right. That U.S. agency is responsible for maintaining and designing the nation's cache of nuclear weapons. That was among those breached. For more, let's bring in Jennifer Eubanks. She's the founder of Adaman Strategic Advisors. They advise companies and clients on cyber resilience, digital transformation, and geopolitical risk. She spent great background, more than three decades in tech intelligence and national Security and served as the deputy director of the CIA for digital innovation from 2019 through 2024.
2:52She joins us from Virginia. So great to have you with us. We've been dying to kind of do a little bit of a deeper dive into this story. This was a serious attack. I am curious about how you are seeing it and kind of the level that it seemed to be able to penetrate. Yeah, it's a great question. and thanks for your invitation today, Carol. You hit the high points in the introduction. I think that's really important, but I'm going to just shape it slightly differently and say that I think we'll look back on this breach as one of those milestone ones where you measure the developments of strategic attempts to infiltrate our networks and our systems.
3:34We'll look back on it like SolarWinds, like the Exchange Server compromise in 2021. So what is most interesting to me here is that this was looked like an espionage operation classic espionage to collect information sensitive data intellectual property you name it launched by three government affiliated entities and then as you mentioned just about six days ago about six days ago it has flipped to ransomware one of those three entities has started dropping ransomware on uh affected servers and then you know, demanding ransom extortion. So this is really something new that we've not seen previously.
4:15Can I just ask you, China, you know, Microsoft accusing hackers associated with the Chinese government of breaking into computer systems. From your work in the government, is China our friend? And I ask that kind of innocently, naively, but I kind of know the answer. But tell me, from a government perspective, how you look at China and how, especially, didn't we just open up Nvidia chips to go back to China? Like, how do you look at what is the right relationship, especially with advanced technology, American technology, how we should be? Yeah, that's a really complex question. And I'm going to hit it first from the cyber perspective, since we're talking about this massive breach today.
4:55And in terms of cyber capabilities, the People's Republic of China is amongst the most capable, most aggressive, most ambitious, is most well-resourced kind of actors anywhere in the world. If you took, and there's a scale issue here, if you took all of the cyber actors affiliated with the Chinese government, it probably outnumbers everything the U.S. and all of our allies could bring to the fight together. The scale is really huge. And these three entities that have been identified by Microsoft are two, The names don't really matter to all the viewers, perhaps, but Lunen Typhoon and Violet Typhoon, they've been seen for a long time.
5:34They're considered advanced persistent threats. They have their own APT moniker numbers. The other is Storm 2603, if I'm not mistaken, 2603. And that's less visible. And it hints at this ecosystem that has taken shape in the People's Republic of China, where they have scaled their cyber operations globally by tapping into contract hackers. So each of these government entities in each province around the country can then reach out to contractors in pretty large numbers. And then the other interesting thing in that is that within that contractor hack ecosystem are also criminal actors. So there's this weird overlap between government, contract entities, and criminal entities such that the lines are becoming blurred.
6:24And that's one of the really interesting things about this particular breach, because we're seeing what looked like classic espionage, sort of government on government, or China, of course, considers commercial espionage to be national security operations. So collecting on commercial interests, but then flipping to ransomware that starts to raise questions about what's going on here. Jennifer, I've been doing this show with Carol for almost five years at this point, so I can steal a question from you that I know you're thinking about. It's something that you remind us of all the time, Carol, and that's the idea that, wait a second, doesn't the United States do stuff like this as well?
7:02I'm going to say no. Yes and no. Okay, so there's an understanding that in the world today and the world forever, espionage is a reality. And that's generally governments seeking information of strategic value about the plans and intentions of adversaries and competitors around the world. That has generally been within the realm of allowable activity, if you will. So if I wanted to understand what a hostile government plan to do to harm the United States, and I had the hacking capability to do that, that would generally be, let's say, within the boundaries. What's different is that the PRC has a different approach.
7:46They do, as you know, hack U.S. companies on a very large scale. It's the greatest illegal transfer of wealth in human history has been through IP theft by the People's Republic of China from the United States and companies here. That's not something that the U.S. does. And when we look at what's happening with this particular breach, where you have government-sponsored activity that has now in the last six days flipped to be ransomware, that's a whole other area. That's definitely something that the U.S. government has not and would not do. So I'm going to go back to the second part of my question then.
8:21You know, we have, once again, NVIDIA is going to be selling chips right into China. So I'm just wondering what you're, you know, the thinking is, if they're going to build it, build it on U.S. technology, right? Like the tech war is on. But what's your observation on this? So this is a really interesting one. And I'll try to be very quick about it because it could be deep and weedy here. But in essence, what we're seeing is the emergence of two parallel digital ecosystems around the world. One that's U.S. innovation and our partners and allies around the world, and it's rooted in concepts around democracy.
9:01So privacy, we try. Privacy, data sovereignty, security, independence or sovereignty, you name it. Another model, more digital authoritarian, is really modeled around monitoring, controlling societies and maintaining state power. And that model is disseminating around the world through the infrastructure that the People's Republic of China is selling, largely in the global south, but not exclusively there. And so it's a long way of saying that I really appreciated the CEO of NVIDIA's comments yesterday about how he wanted America to maintain that lead and be the standard. Because this issue of digital standards is really a battlefield for the future of technological leadership.
9:48And technological leadership in this way, in my opinion, is really about global leadership, about superpower status. And we're going to have to lead in digital technology if we want to maintain that global need more broadly. And so I can see the logic. I'm not saying good or bad, but I can see the logic behind promoting American innovation and standards so that we can weaken the emergence of that, say, parallel digital ecosystem could compete with us. Jennifer, we only have 10 seconds left. Can you just give us one tip to stay safe in an environment such as this? Oh, yeah. Apply all your patches immediately.
10:25rotate your encryption keys if you're affected and hunt for anything that might be on your systems and unplug your system if you think you might be affected while you're taking these measures. Okay. I said one thing that's four, but it's okay. We're going to let it slide. Do you have encryption keys? I'm going to Google this stuff in an encrypted setting. Jennifer, come back real soon. This was fabulous. Jennifer Eubank, founder of Andamand Strategic Advisors, joining us right here on Bloomberg Business Week Daily.
10:56Jennifer Ewbank:When you're running a business, the best days are the ones where priorities stay on track. For midsize and large companies, risk can affect multiple parts of the organization at once, from property and liability to cyber and regulatory challenges. At that level, managing risk becomes an ongoing discipline. At the Hartford, the focus is on helping businesses manage risk before it turns into something more disruptive. And when losses do happen, that work is paired with insurance coverage shaped by years of underwriting, risk engineering, and claims experience. Learn more at the Hartford.com slash risk mitigation.
11:31Jennifer Ewbank:Policies provided by Hartford Fire Insurance Company and its property and casualty affiliates, Hartford, Connecticut. Before you sign off, you tuned in for ways to help teams move faster, make sharper decisions, and turn scattered context into work they can use. ChatGPT for Business can help. ChatGPT for Business gives teams a shared workspace with admin controls, permissions, and access to work and codecs in ChatGPT. This means your business can move from question to answer and code to rollout quicker. Join over 10 million business and enterprise users worldwide already using ChatGPT for work.
12:06Download the ChatGPT desktop app or contact sales to learn more. It's time to plan ahead and make sure your brand is showing up in ways that can have an impact. For Imprint's promotional products are designed to work as hard as you do and make a lasting impression. From quality apparel, including exclusive brands, to drinkware, tech, and totes, they've got thousands of options to fit your brand and budget. Plus, you get free samples, expert help, and their 360-degree guarantee. So you can be 4imprint certain everything shows up just right, right on time. Explore more at 4imprint.com. 4imprint.
12:424certain.
From the publisher
Microsoft Corp. said a Chinese hacking group is exploiting security vulnerabilities in the company’s SharePoint servers to deploy ransomware, following a cyberattack discovered last week that has affected hundreds of entities around the world. The group, which Microsoft has named Storm-2603, has a history of waging ransomware attacks, which use malicious software to lock down computers and render them inoperable. Ransomware groups usually then demand payment from their victims to unlock the computers.
Jennifer Ewbank, a veteran CIA operations officer who rose to become Deputy Director for Digital Innovation, now advises companies and clients on cyber resilience, digital transformation, and geopolitical risk through her company, Andaman Strategic Advisors. Jennifer examines today's pressing national security and tech issues, including the Microsoft SharePoint breach, with Tim Stenovec and Carol Massar on Bloomberg Businessweek Daily.
See omnystudio.com/listener for privacy information.
