China-linked Warlock ransomware exploits SharePoint in water, telecom attacks
The China-linked ransomware group Warlock has breached a water utility, telecom provider, regional government body, and university by exploiting SharePoint vulnerabilities for initial access. The attacks indicate a coordinated campaign targeting critical infrastructure and public sector entities, with the water utility attack raising concerns about potential impact on essential services. The full scope and data impact remain unclear as investigations are ongoing.
Score Breakdown
Intelligence Tags
Entities
Part of 2 situations
China — 121 developments
China-linked Warlock Group Exploits SharePoint in Critical Infrastructure Attacks
The China-linked Warlock ransomware group is actively exploiting SharePoint vulnerabilities for initial access, confirmed in attacks against a water utility, telecom provider, regional government body, and university. This campaign, ongoing since July 2025, indicates a sustained and expanding cyber espionage effort targeting critical infrastructure and public sector entities. The full scope of affected organizations and data impact remains unclear.