BREACH WATCH BRIEF High 💀 Ransomware

Warlock Ransomware Strikes Water Utility and Telecom Operator via SharePoint Zero‑Days

Longlegs used SharePoint zero‑day exploits to infiltrate a water utility and a telecom provider, disabling security tools and deploying ransomware on dozens of hosts. The incident underscores the need for auditable incident‑response controls and continuous monitoring.

SeverityHigh
Type💀 Ransomware
ConfidenceHigh
ReportedOct 1, 2026
Energy & Utilities Utilities (water) Telecommunications Vulnerability Exploit

What happened

The Longlegs group exploited four Microsoft SharePoint Server CVEs to gain footholds in a water utility and a telecom operator, disabled security software on ~40 hosts with a signed driver, and spread Warlock ransomware to at least 33 machines via the domain’s SYSVOL share.

Why it matters for trust and compliance

  • The attack illustrates why continuous control‑assurance around incident detection, evidence collection, and ransomware response is essential for regulators and auditors.
  • Map ransomware detection and response controls to multiple frameworks for audit readiness.
  • Collect and retain logs from SharePoint, domain controllers, and endpoints as defensible evidence.

Who is affected

Utilities (water) Telecommunications

Recommended actions

  1. Patch all on‑premises SharePoint servers against CVE‑2025‑49704, CVE‑2025‑49706, CVE‑2025‑53770, CVE‑2025‑53771.
  2. Enhance EDR to alert on driver‑based AV disable attempts.
  3. Update ransomware incident‑response playbooks to include SYSVOL propagation detection.
  4. Implement continuous logging and evidence retention for SharePoint and domain activities.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.