Microsoft 365CIO BriefingsRetrospectives

CIO Brief: On-Prem SharePoint Is Now a Liability

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2025, written in 2026 with the benefit of hindsight.

The short version: In July 2025, Chinese state hackers and ransomware groups exploited flaws in SharePoint servers that companies ran themselves — compromising hundreds of organizations, including government agencies. Microsoft's cloud version wasn't affected.

The pattern repeats

Exchange Server (2021–2022) and SharePoint Server (2025) followed the same story: self-hosted Microsoft collaboration servers exposed to the internet, zero-day vulnerabilities, rapid mass exploitation, and attackers stealing keys that kept them inside after patching.

The business impact

  • Data theft from document repositories.
  • Ransomware deployment.
  • Emergency patching and investigation under pressure.
  • Ongoing exposure if stolen keys weren't rotated.

Questions to ask your team

  • Do we still run SharePoint Server on-premises?
  • Is it reachable from the internet?
  • Did we patch and rotate keys during ToolShell, and did we check for compromise?
  • What would it take to move to SharePoint Online?

What good looks like

SharePoint in Microsoft 365, with any remaining on-premises servers isolated from the internet, patched quickly and monitored.

The decision

Ask for a plan to retire on-premises SharePoint, or a documented justification and isolation plan for keeping it. Two waves of Exchange attacks and ToolShell make the risk clear.

toolshell sharepoint impactToolShell2025

More on this story