DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Microsoft Used China-Based Engineers to Maintain SharePoint Before China-Linked Hackers Exploited It

Microsoft used China-based engineers to maintain SharePoint before China-linked groups exploited on-premises SharePoint Server. The staffing overlap raises governance questions, but no public evidence proves the engineers caused or enabled the attack.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: ProPublica documented that Microsoft used a China-based engineering team to maintain SharePoint, including the on-premises product later targeted in 2025. China-linked threat groups did exploit SharePoint Server vulnerabilities, but no public evidence establishes that those engineers caused, enabled, or participated in the intrusion.

What ProPublica reported

In an August 1, 2025 investigation, ProPublica said it reviewed screenshots of Microsoft’s internal work-tracking system showing China-based employees fixing bugs for “SharePoint OnPrem.” That is the self-hosted SharePoint Server product, not the Microsoft 365-hosted service. ProPublica reported that the arrangement had existed for years. ProPublica’s report is the basis for the staffing claim.

Microsoft confirmed that a China-based team existed. Microsoft said the team was supervised by a U.S.-based engineer, followed Microsoft security requirements, and had its code reviewed by managers. It also said work was being moved to another location. Those are Microsoft’s stated controls, not independent findings.

The public record does not identify each engineer’s permissions, repositories, build systems, production access, or access to customer environments. Maintaining product code is not the same as logging in to a customer’s live farm or viewing customer data.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

What the 2025 attack actually involved

Microsoft said attackers were actively exploiting vulnerabilities in on-premises SharePoint Server. SharePoint Online in Microsoft 365 was not affected by the vulnerabilities covered in its July 2025 guidance. Microsoft’s customer guidance identified supported affected products as SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.

Microsoft’s threat-intelligence account described an earlier spoofing flaw, CVE-2025-49706, and remote-code-execution flaw, CVE-2025-49704. Attackers then exploited CVE-2025-53770 and CVE-2025-53771 after earlier July fixes did not fully protect every customer. Microsoft’s July 22 account describes that sequence.

CISA said the vulnerabilities could let attackers reach SharePoint content, file systems, and internal configuration and execute code over the network. Its alert and malware analysis provide technical indicators and affected CVEs: CISA alert and CISA malware analysis.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Who was reported as exploiting it?

TechRepublic’s summary of the reporting associated exploitation with the China-linked groups Linen Typhoon, Violet Typhoon, and Storm-2603; it reported that Storm-2603 deployed Warlock ransomware. These are threat-actor assessments, not proof that the Chinese government ordered every intrusion. TechRepublic’s account distinguishes those assessments from the separate question of an insider compromise.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does the evidence show Microsoft’s China-based engineers caused the breach?

No. The evidence shows a potentially consequential overlap:

  • China-based staff reportedly maintained the affected product.
  • Internal records reportedly showed recent SharePoint bug-fixing activity.
  • China-linked groups exploited SharePoint vulnerabilities.
  • Microsoft acknowledged the team and said it was relocating the work.

It does not show that a particular engineer introduced a flaw, disclosed a vulnerability, accessed a customer farm, or cooperated with attackers. ProPublica reported that any role by the China-based staff in the hack remained unclear. “China-based” also does not, by itself, establish Chinese-government control or coercion.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

The questions Microsoft’s safeguards leave open

  • Did U.S. supervision include independent technical review and reproducible builds?
  • Were source repositories segmented and privileged credentials restricted?
  • Were all code, test, and administrative accesses logged and audited?
  • Were engineers barred from production systems and customer support environments?
  • Did the arrangement cover only engineering, or also operational support?

Those are legitimate supply-chain and governance questions. They are not evidence that the SharePoint attack was an insider operation.

Timeline of the overlap

Date Event
May 2025 TechRepublic reported that ToolShell-related exploit activity was identified at a hacking competition.
July 7, 2025 Microsoft said its analysis showed Chinese hackers exploiting SharePoint weaknesses by this date.
July 8, 2025 Microsoft released an initial patch that attackers reportedly bypassed.
July 19, 2025 Microsoft published emergency customer guidance describing active attacks.
July 22, 2025 Microsoft published its threat-intelligence account.
August 1, 2025 ProPublica published its report on China-based SharePoint maintenance.
July 14, 2026 SharePoint Server 2016 and 2019 reached Microsoft end of support.
August 18, 2026 Those two versions remain beyond support; Subscription Edition remains supported under its lifecycle policy.

Why the “digital escort” controversy is related but different

ProPublica separately reported that Microsoft used foreign-based personnel, including China-based workers, to maintain cloud systems supporting U.S. government agencies. U.S.-based “digital escorts” were meant to supervise or control access; ProPublica reported concerns that some escorts lacked the technical expertise to monitor foreign engineers effectively. See the Pentagon report and the government-support report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That reporting concerns support for government cloud systems, while the SharePoint allegation concerns product engineering. The stories raise a common governance issue, but they do not demonstrate that the same people, credentials, or access path caused the SharePoint attacks.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

ProPublica later reported that Microsoft said it had stopped using China-based engineers for Defense Department cloud support and was considering similar changes for other government customers. The Defense Department tightened requirements for personnel from adversarial countries, technical qualifications, and audit trails. Those rules apply to Defense Department systems and procurement; they do not automatically govern commercial SharePoint customers. Pentagon restrictions and related reporting provide that context.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which SharePoint versions need attention now?

Product Status as of Aug. 18, 2026 Implication
SharePoint Server 2016 Support ended July 14, 2026 No longer a supported long-term platform; see Microsoft’s lifecycle page.
SharePoint Server 2019 Support ended July 14, 2026 Plan migration or upgrade; see Microsoft’s lifecycle page.
SharePoint Server Subscription Edition Supported under the Modern Lifecycle Policy, subject to supported builds Requires recurring public updates; see lifecycle details and the servicing FAQ.
SharePoint Online Not affected by the cited 2025 SharePoint Server vulnerabilities Cloud identity, configuration, insider-risk, and account-compromise controls still matter.

What administrators should do

  1. Identify the deployment. Confirm whether each workload is SharePoint Online or an on-premises farm, then record the farm version, build, servers, language packs, and internet exposure.
  2. Patch every server. Microsoft’s July guidance listed KB5002768 for Subscription Edition; KB5002754 plus language-pack KB5002753 for SharePoint Server 2019; and KB5002760 plus language-pack KB5002759 for SharePoint Server 2016. Verify current Microsoft guidance and update history rather than relying on this static list.
  3. Complete the farm upgrade. Installing binary files may not finish the SharePoint upgrade process. Follow Microsoft’s software-update procedure and apply required language-dependent updates: software updates overview.
  4. Enable defenses. Configure Antimalware Scan Interface, use AMSI Full Mode where available, and deploy Microsoft Defender Antivirus or an equivalent solution.
  5. Rotate machine keys. Microsoft advised rotating SharePoint ASP.NET machine keys. Treat this as coordinated key and credential remediation, especially after suspected exploitation.
  6. Reduce exposure during remediation. If AMSI cannot be enabled, disconnect the server from the internet where feasible or restrict access through a VPN, authenticated proxy, or authentication gateway.
  7. Investigate before rebuilding. Preserve evidence; review IIS, SharePoint, Windows, PowerShell, identity-provider, endpoint, and network logs; search for web shells and unexpected files; check new or modified service accounts, privileged identities, persistence, and lateral movement into SQL Server, Active Directory, file shares, Exchange, Teams, OneDrive, and management systems.
  8. Choose a supported destination. Evaluate Subscription Edition for continued self-hosting or SharePoint Online for Microsoft-managed operations. Base the choice on sovereignty, accreditation, custom integrations, staffing, identity maturity, and data-governance requirements.

Migration and operating trade-offs

Remain on premises temporarily

This may be necessary for sovereignty, regulatory, contractual, network-isolation, or specialized-accreditation requirements. It leaves the organization responsible for patching, segmentation, privileged access, monitoring, and incident response.

Move to Subscription Edition

Subscription Edition preserves an on-premises deployment with a continuing-update model. It still requires licensing, infrastructure, compatibility testing, and disciplined recurring updates; it does not remove the security burden of self-hosting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Migrate to SharePoint Online

SharePoint Online can reduce server-patching work and integrate with Microsoft 365. It does not eliminate identity attacks, misconfiguration, insider risk, or data-governance obligations. Migration should inventory custom solutions, workflows, permissions, metadata, retention, search, and residency requirements before cutover.

Bottom line

ProPublica’s reporting establishes a China-based SharePoint maintenance arrangement and Microsoft’s decision to move that work. Microsoft and CISA establish that China-linked actors exploited serious on-premises SharePoint vulnerabilities. The public evidence does not connect the engineers to the intrusion. For organizations, the actionable conclusion is narrower and more urgent: identify any on-premises farm, patch and investigate it as a potential compromise, rotate keys where appropriate, and retire unsupported SharePoint 2016 or 2019 through a supported upgrade or migration.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.