Article Details
Scrape Timestamp (UTC): 2025-10-01 17:54:28.982
Source: https://www.theregister.com/2025/10/01/us_air_force_investigates_breach/
Original Article Text
Click to Toggle View
US Air Force investigates 'privacy-related issue' amid rumored SharePoint shutdown. Uncle Sam can't quit Redmond. Exclusive The US Air Force confirmed it's investigating a "privacy-related issue" amid reports of a Microsoft SharePoint-related breach and subsequent service-wide shutdown, rendering mission files and other critical tools potentially unavailable to service members. "The Department of the Air Force is aware of a privacy-related issue," an Air Force spokesperson told The Register on Wednesday, while declining to answer specific questions about the alleged digital intrusion. Sign in to sound off Register for The Register's Forums here. "The preliminary investigation is ongoing, and we are assessing the scope of any concerns and any necessary required remediation," the spokesperson added. "We are in the process of evaluating technical remediation solutions and will act as appropriate. Compliance with the Privacy Act and identifying a solution for this technical problem is critical to the DAF to ensure warfighter readiness and lethality." The Air Force's confirmation follows what looks like a breach notification, shared with The Register and on social media, that purports to come from the Air Force Personnel Center Directorate of Technology and Information. "This message is to inform you of a critical Personally Identifiable Information (PII) and Protected Health Information (PHI) exposure related to USAF SharePoint Permissions," the notice says. "As a result of this breach, all USAF SharePoints will be blocked Air Force-wide to protect sensitive information." Two other Microsoft services, Teams and Power BI dashboards, will also allegedly be blocked because both access SharePoint, the alert continued, adding that restoration may take up to two weeks. It's unclear what services, if any, are offline right now. A DAF spokesperson said that the military branch "cannot confirm" that SharePoint and Teams have been disabled. Another person we spoke to on the phone claimed that they were "using it right now" when asked about SharePoint on Tuesday. A Microsoft spokesperson told The Register that Redmond "has nothing to share at this time," and declined to answer our specific questions including if the Air Force security snafu is related to July's SharePoint fiasco. Chinese government spies, data thieves, and at least one ransomware gang exploited a couple of SharePoint vulnerabilities over the summer, allowing them to hijack on-premises SharePoint servers belonging to more than 400 organizations and remotely execute code. The targets included a "major Western government," according to Check Point Research. While it's unclear if the SharePoint attacks victimized any US government agencies or military branches, Microsoft's earlier security failings have directly affected Uncle Sam - which continues to funnel billions of dollars into Redmond's coffers. Also this summer, an investigation exposed Microsoft's use of China-based employees to support DoD cloud services. The Pentagon then launched a review and later banned the practice. Both Russian and Chinese government snoops broke into Microsoft systems in recent years, giving Beijing access to government emails, and other important, supposedly secret stuff, prompting a lashing from the feds for a "cascade" of "avoidable errors."
Daily Brief Summary
The US Air Force is investigating a potential privacy breach involving Microsoft SharePoint, which may have exposed Personally Identifiable Information (PII) and Protected Health Information (PHI).
A breach notification suggests a service-wide shutdown of SharePoint, affecting mission files and critical tools for service members, with potential impacts on operational readiness.
The Air Force is assessing the scope of the breach and exploring technical remediation solutions to ensure compliance with the Privacy Act and maintain operational capabilities.
Reports indicate that SharePoint, along with Microsoft Teams and Power BI dashboards, could be blocked Air Force-wide, with restoration efforts possibly extending up to two weeks.
The incident follows previous security vulnerabilities in SharePoint exploited by foreign entities, raising concerns about the integrity of US government systems.
Microsoft has not confirmed any connection to prior SharePoint vulnerabilities exploited by foreign adversaries, leaving questions about the breach's origins and impact.
The breach underscores ongoing challenges in securing military and government digital infrastructure, emphasizing the need for robust cybersecurity measures and vendor accountability.