Security Stop-Press : Microsoft 365 Loophole Could Allow Ransomware Attack

Published on

If you use Microsoft 365, here’s a security warning you can’t ignore. Cybersecurity researchers at Proofpoint have discovered a loophole that could allow hackers to launch ransomware attacks using SharePoint Online and OneDrive.
The scariest part? This attack could leave victims without backups or a way to recover their files – forcing them to either pay a ransom or lose their data forever. Let’s break it down and see what you need to do to stay safe.
How Does This Attack Work?
Cybercriminals can exploit a vulnerability in Microsoft 365’s file versioning system. Here’s how it happens:
1 Hackers gain access to a compromised SharePoint Online or OneDrive account – often through phishing or stolen login credentials.
2 They change the file versioning settings – reducing the number of saved file versions to one or zero. Normally, version history allows users to restore previous versions of a file if something goes wrong.
3 They encrypt the files – once encrypted, the files become inaccessible, and with version history disabled, there are no backups to restore from.
4 They demand a ransom – the victim is left with a terrible choice: pay up or lose their data forever.
This method is particularly dangerous because traditional ransomware defences may not stop it. Since the attack happens within a Microsoft 365 account, it doesn’t involve downloading malicious files or running external malware – making it harder to detect.
How Can You Protect Yourself?
Since this loophole relies on attackers modifying file settings, businesses and individuals need to take proactive security measures. Here’s what you should do:

  • Enable Alerts for File Configuration Changes – Make sure your Microsoft 365 admin settings are set to detect changes in versioning configurations. If a hacker tries to lower the version limit, you’ll get an alert.
  • Use Multi-Factor Authentication (MFA) – This makes it much harder for hackers to gain access in the first place, even if they steal a password.
  • Implement Cloud Security & Threat Intelligence – Solutions like Microsoft Defender for Office 365 can help detect unusual activity in SharePoint and OneDrive.
  • Use Data Loss Prevention (DLP) Tools – These tools help monitor and control data movement, reducing the risk of unauthorised file encryption or deletion.
  • Regular Backups Outside of Microsoft 365 – Since this attack targets built-in Microsoft 365 backups, consider keeping separate offline or cloud backups that aren’t tied to SharePoint or OneDrive.
    Why Does This Matter?
    Ransomware is already one of the biggest cybersecurity threats, and this loophole bypasses traditional defences. Since many businesses rely on Microsoft 365 for file storage and collaboration, a successful attack could mean losing critical business data permanently.
    Microsoft is expected to address this vulnerability, but until then, users must take extra precautions to prevent attacks.
    Final Thoughts: Stay Alert & Secure Your Data
    If you’re using Microsoft 365, SharePoint Online, or OneDrive, don’t wait for an attack to happen – review your security settings now. Hackers are always looking for new ways to bypass defences, and this loophole is a perfect example of how they adapt their tactics.
    Set up alerts, enable MFA, and back up data securely.
    Stay informed about Microsoft security updates.
    If you’re an IT admin, take immediate steps to tighten security policies.
    Would you be prepared if ransomware hit your cloud storage? Let us know your thoughts!