Exchange Servers Under Siege & Teams Help Desk Scams – Sept 1

by The Creator | Sep 1, 2026

Nearly 22,000 Microsoft Exchange servers remain unpatched against a critical flaw that allows attackers to hijack all user mailboxes and access company email, according to BleepingComputer. If your business runs Exchange, apply the patch immediately to prevent account compromise and data exposure.

Why is the Exchange server patch critical for your business?

The vulnerability affects Exchange on-premises installations and allows unauthenticated attackers to gain full control of every mailbox without needing user credentials. For small businesses using Exchange, this means an attacker could read all email, send messages as your company, and access customer or financial data within hours of exploitation. CISA tracks this as a high-priority threat. The patch is straightforward to apply and requires no downtime if staged properly. Contact your IT provider or Microsoft support today to confirm your Exchange version and deployment method (on-premises vs. cloud), then schedule the update during low-traffic hours. Delaying this patch is equivalent to leaving your front door unlocked with a sign showing the combination to your safe.

Key takeaways

  • 22,000 Exchange servers remain vulnerable to mailbox hijacking attacks that bypass all authentication.
  • Apply the critical patch immediately; delay puts customer data and business email at direct risk.
  • Verify your Exchange deployment (on-premises or hybrid) with your IT team before patching to avoid unexpected downtime.
  • Also watch for Teams impersonation scams: verify support requests through official channels, never grant remote access without callback confirmation.

Frequently asked questions

How do I know if my business uses Exchange servers?

If your company runs Outlook email on a server you own or maintain (not Outlook.com or Microsoft 365), you likely use Exchange. Microsoft 365 Exchange Online is cloud-hosted and receives patches automatically. Contact your IT provider to confirm whether your deployment is on-premises, hybrid, or cloud. The patch applies only to on-premises and hybrid setups.

What happens if we don't patch the Exchange server?

An attacker can take full control of every user mailbox without knowing passwords, read confidential emails, send fraudulent messages posing as your company, and extract customer or financial data. Manufacturing and professional services firms are high-value targets. Once in, the attacker can pivot to steal credentials and move laterally through your network. Patching closes this door in hours.

How long does the Exchange server patch take to install?

The patch itself installs in 15-30 minutes, but plan for 1-2 hours of downtime if your Exchange server must restart. Schedule the update outside business hours. Microsoft provides a maintenance window and rollback steps in case of issues. Your IT provider can prepare and test the patch in your environment first, then coordinate with your team on timing.

What is the Spring Ring Teams impersonation campaign and how do we protect against it?

Hackers create fake Microsoft Teams accounts that impersonate your IT help desk, then contact employees asking for remote access credentials or approval. Train staff to never share passwords or grant remote access to anyone via Teams message or call. Always verify support requests by calling your IT team directly using a known phone number. Use Multi-Factor Authentication (MFA) on all email and remote access tools to block unauthorized login even if credentials are stolen.

Sources

Keep reading