Microsoft Outlook Breach Likely Hit CUs

By Ray Birch

SAN DIEGO—Many more credit unions will likely be included among the organizations affected by the massive breach of Microsoft’s Outlook email service that was announced this week, according to sources who believe the full extent of the hack has yet to be revealed—and copycat attacks may follow.

Feature Microsoft Hack low

The hack—called a “ticking time bomb” by security blogger Brian Krebs, who says crooks will likely execute “Stage 2” of the attack by entering networks through back doors created during the initial breach—is also a strong sign credit unions need to move away from hosting Microsoft Exchange servers in-house and instead move to the cloud, experts say.

As CUToday.info has reported, one cybersecurity researcher has identified “large credit unions” as among the businesses and government agencies that use a Microsoft Exchange email service compromised in an aggressive hacking campaign that was likely sponsored by the Chinese government. The credit unions allegedly targeted and potentially breached have not been identified.

When contacted by CUToday.info regarding what risk there might be to one or more credit unions, NCUA declined comment.

The hackers are exploiting four newly-discovered flaws in Microsoft Exchange server email software, and “has seeded hundreds of thousands of victim organizations worldwide with tools that give the attackers total, remote control over affected systems,” according to analysts. The hackers were able to steal emails and install malware to continue surveillance of their targets, Microsoft said in a blog post.

‘Just Hard to Know’

Al Pascual, SVP of security firm Sontiq, described the breach as “massive,” adding the size of the hack will only grow as more businesses are identified as being part of the hack.

“It is just hard to know now how many credit unions and banks were hit,” said Pascual. “The number of organizations that have been affected just continues to grow. First, we’re hearing 30,000 (in the U.S.), and then we're hearing 60,000. You’re talking small, medium and large enterprises globally. The Exchange server is just so pervasive.”

Pascual noted the Chinese hacking group Hafnium, which has been identified as allegedly being behind the attack, is more interested in compromising national defense organizations and government agencies.

“They're after state or industrial secrets,” Pascual explained. “That being said, these vulnerabilities, we think, have been around potentially for a decade.”

‘About As Serious As It Gets’

pascual

Al Pascual

What should be concerning for credit unions, according to Pascual, is that in the aftermath of the Microsoft attack more criminal organizations are likely trying to exploit this weakness in Exchange servers.

“What we're starting to see now is other criminal groups are taking the new Microsoft Exchange fix and trying to reverse engineer it, so they can do the same thing,” said Pascual. “But the bad thing for the financial services industry is these crooks are the ones who are more likely to attack banks and credit unions than a state-sponsored criminal organization.”

Pascual said the attack exploited four vulnerabilities in Exchange servers.

“Used in concert, they basically gave you unfettered access to any organization with an Exchange server,” Pascual said. “You can install back doors, remain persistent, and then go deeper. At a minimum, you have access to everything that's on the server. You're getting access to information on all the users on the server. And you are potentially gleaning the credentials they may also use elsewhere in the organization…This is about as serious as it gets.”

‘Extremely Disconcerting’

Security Expert Jim Stickley said the attack has been “extremely disconcerting” to the clients he knows have been affected by the Microsoft attack.

“This is about a threat in which you are exploited even before you knew the threat existed,” said Stickley. “Now, you learn about it all of a sudden, and then you find out you have been exploited; that’s devastating. That’s terrifying. That’s a punch to the gut.”

Stickley, CEO of Stickley on Security, said he has been working with several financial institutions that have been compromised.

“The minute they heard there were vulnerabilities in Exchange, they moved to get the vulnerabilities patched,” said Stickley. “But while they were patching the servers they realized they had already been compromised and knew this was a much bigger issue.’”

On his blog, Krebs emphasized compromised organizations must monitor for future attacks from the criminals who may have dropped back doors into networks, Stickley said another big concern must be addressed.

‘Extra Risk’

“I would evaluate if you really need to host your own Exchange server.” said Stickley. “The in-house Exchange server is becoming a more dated practice, but some companies really want to control their data, and that, I guess, means in-house. But in doing so now you bring on extra risk.”

Stickley said cloud services are a way to better control the organization’s exposure to attacks.

“Ten years ago there's no way I would have said that,” stressed Stickley, who added those with Exchange servers in-house that were compromised in the Microsoft attack are now dealing with “all of the ramifications and the fallout. On the other hand, if you're using something like Office 365 where Microsoft hosts everything in the cloud and is managing everything, after this attack all you are dealing with is did the attack have any impact on email addresses or our emails? And then Microsoft follows up quickly and says, ‘You're fine. You have nothing to worry about.’ It just offloads the risk to somebody else. It’s just so much easier, and more secure, to outsource the whole thing.”

A Word of Caution

Stickley cautioned that organizations continuing with Exchange servers in-house must make sure those servers are isolated from other servers and can’t communicate with them.

“These Exchange servers need to be on an island by themselves,” Stickley advised. “If they become infected and can communicate with another server, that server will likely become infected, along with all other servers in that chain. This attack is just another example of how everybody's needs to move to z

stickleyJim

Jim Stickley

ero trust technology—because everything now has to be so segmented and locked down.”

Zero trust is a security model based on the principle of maintaining strict access controls and not trusting anyone by default, even those already inside the network perimeter.

Size and scale, too, are becoming greater factors in securing organization’s data, something Microsoft has, reminded Stickley.

“The big guys like Microsoft, they have teams, obviously, that just do security every day. No credit union has that kind of capability,” he said.

A Huge Vulnerability

The recent hack exposed a huge vulnerability, both Stickley and Pascual pointed out: If companies had an Exchange server and were receiving emails, their systems could have been compromised.

Pascual said in addition to now installing the patches, organizations are scouring their networks looking for indicators of compromise.

“It’s basically hunting through your network to find out if you've been breached and, if so, where you have been affected. All of this is unfolding now,” said Pascual, who believes the extent of the breach will be revealed to be much larger in the coming months.

‘Tens of Thousands’

Pascual, formerly COO and co-founder of Breach Clarity (Sontiq recently acquired Breach Clarity), a website that provides a severity score for most of the known data breaches over the years, and provides advice on how to best address each breach, said the Microsoft breach won’t get a score, because it is a series of breaches of thousands of organizations.

“As more of those trickle out from this attack, and more names of organizations who have been affected become known, we will score each one based on the data that has been compromised,” he said. “But we’re talking about tens of thousands of organizations. This is going to be a very long trickle of significant disclosures in the next year.”

Microsoft Security Update

Microsoft has reported four vulnerabilities were discovered in the Microsoft Exchange servers from 2013 and later (including 2016, 2019). The vulnerable servers appear to host Web versions of Microsoft’s email program Outlook on their own machines instead of cloud providers. It also appears that the vulnerabilities were being exploited for some time before March 2, and that widespread exploitation of the vulnerabilities is ongoing, according to Microsoft.
Microsoft has released several security updates for vulnerabilities affecting the on-premises versions of Microsoft Exchange Server. The Common Vulnerabilities and Exposures (“CVE”)[i] exploited were CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.  Microsoft stated that these exploits “require the ability to make an untrusted connection to Exchange server port 443."
“This can be protected against by restricting untrusted connections or by setting up a VPN to separate the Exchange server from external access,” Microsoft said.
The other vulnerabilities that were also fixed in the March 2nd updates were CVE-2021-26412, CVE-2021-26854, and CVE-2021-27078 and, according to Microsoft, are “not related to known attacks.”
CISA Recommendations:
A CISA Emergency Directive 21-02: Mitigate Microsoft Exchange On-Premises Product Vulnerabilities recommends immediate patching of the vulnerabilities and preserving forensics of the cyber event.  CISA reported that the threat actors deployed web shells on the compromised servers to establish persistent access to the victims network.
CISA noted web shells can allow attackers to steal data and perform additional malicious actions, installing the patches alone will not remove malicious web shells that were deployed before patching.

Section: Standard
Word Count: 1959
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Microsoft-Outlook-Breach-Likely-Hit-CUs