CIO Brief: On-Prem SharePoint Is Now a Liability
Retrospective: this article looks back at events from July 2025, written in 2026 with the benefit of hindsight.
The short version: In July 2025, Chinese state hackers and ransomware groups exploited flaws in SharePoint servers that companies ran themselves — compromising hundreds of organizations, including government agencies. Microsoft's cloud version wasn't affected.
The pattern repeats
Exchange Server (2021–2022) and SharePoint Server (2025) followed the same story: self-hosted Microsoft collaboration servers exposed to the internet, zero-day vulnerabilities, rapid mass exploitation, and attackers stealing keys that kept them inside after patching.
The business impact
- Data theft from document repositories.
- Ransomware deployment.
- Emergency patching and investigation under pressure.
- Ongoing exposure if stolen keys weren't rotated.
Questions to ask your team
- Do we still run SharePoint Server on-premises?
- Is it reachable from the internet?
- Did we patch and rotate keys during ToolShell, and did we check for compromise?
- What would it take to move to SharePoint Online?
What good looks like
SharePoint in Microsoft 365, with any remaining on-premises servers isolated from the internet, patched quickly and monitored.
The decision
Ask for a plan to retire on-premises SharePoint, or a documented justification and isolation plan for keeping it. Two waves of Exchange attacks and ToolShell make the risk clear.
- ToolShell (July 2025): On-Prem SharePoint Zero-Days Exploited Worldwide Incident Teardowns
- How to Migrate or Isolate On-Premises SharePoint Servers How-To & Hardening
- Detecting SharePoint Server Exploitation: Defender XDR and Sentinel Hunting Queries Detection & Response