Warlock Ransomware Strikes Water Utility and Telecom Operator via SharePoint Zero‑Days
Longlegs used SharePoint zero‑day exploits to infiltrate a water utility and a telecom provider, disabling security tools and deploying ransomware on dozens of hosts. The incident underscores the need for auditable incident‑response controls and continuous monitoring.
ADTP Breach Watch· October 1, 2026· Broadcom Symantec Blogs
SeverityHigh
Type💀 Ransomware
ConfidenceHigh
ReportedOct 1, 2026
Energy & UtilitiesUtilities (water)TelecommunicationsVulnerability Exploit
What happened
The Longlegs group exploited four Microsoft SharePoint Server CVEs to gain footholds in a water utility and a telecom operator, disabled security software on ~40 hosts with a signed driver, and spread Warlock ransomware to at least 33 machines via the domain’s SYSVOL share.
Why it matters for trust and compliance
The attack illustrates why continuous control‑assurance around incident detection, evidence collection, and ransomware response is essential for regulators and auditors.
Map ransomware detection and response controls to multiple frameworks for audit readiness.
Collect and retain logs from SharePoint, domain controllers, and endpoints as defensible evidence.
Who is affected
Utilities (water)Telecommunications
Recommended actions
Patch all on‑premises SharePoint servers against CVE‑2025‑49704, CVE‑2025‑49706, CVE‑2025‑53770, CVE‑2025‑53771.
Enhance EDR to alert on driver‑based AV disable attempts.
Update ransomware incident‑response playbooks to include SYSVOL propagation detection.
Implement continuous logging and evidence retention for SharePoint and domain activities.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.