Warlock keeps hitting SharePoint servers across Latin America and Iberia, Symantec says
The ransomware group is still breaking into Microsoft SharePoint servers in Portuguese and Spanish-speaking countries, hitting hospitals, government offices and schools.

Key points
- Researchers at Symantec and the Carbon Black Threat Hunter Team say Warlock is still exploiting Microsoft SharePoint vulnerabilities in Portuguese and Spanish-speaking countries.
- The hackers are hitting critical infrastructure, government bodies and education organisations, according to Symantec.
- Warlock is suspected of links to China, though attribution remains at medium confidence.
- No new Warlock victims have appeared on the group's leak site in the last 30 days, based on Threat Vectr tracking.
A ransomware crew tracked as Warlock is still forcing its way into Microsoft SharePoint servers, and defenders in the affected regions are running out of time to patch.
Symantec and the Carbon Black Threat Hunter Team published the latest activity this week. Targets are organisations in Portuguese and Spanish-speaking countries: critical infrastructure operators, government departments and education providers. Warlock is suspected of ties to China. The researchers are careful with that call, and so are we. Tooling overlaps with activity other vendors track under different names, and single-source attribution rarely holds.
SharePoint is the Microsoft software organisations use to store and share internal documents. An internet-facing server that hasn't been patched is a convenient front door.
Who is Warlock?
Warlock is a ransomware operation: criminals break into a network, encrypt files, steal data first, and threaten to publish it on a leak site if the victim won't pay. We first covered the group on 1 October 2026.
Our leak-site tracking has found no fresh names on the Warlock leak site in the past 30 days. That could mean a lull, a quiet rebrand, or negotiations happening without public pressure. None of those options is reassuring.
How are they getting in?
Through SharePoint, and most likely through a mix of old and recent flaws in that software. Symantec's write-up, first reported by The Hacker News, says Warlock is still weaponising SharePoint vulnerabilities to land on servers before dropping ransomware.
The pattern tracks with the ToolShell cluster of SharePoint bugs Microsoft began patching over the summer. On-premises SharePoint Server flaws that let an unauthenticated attacker run their own code on a machine are particularly valuable at scale, and this crew appears to be working that angle hard. Microsoft's guidance has been updated repeatedly since July.
Once inside, the hackers disable security software, move across the network, and deploy the encryption payload. That disabling step is why victims often don't notice until the ransom note appears.
What does this mean for ordinary people?
If you work for a hospital, a council or a school in Brazil, Portugal, Spain or Latin America, your IT team should already be checking whether its SharePoint servers are on the latest patch level. For everyone else the practical risk is second-hand: services going offline, appointment systems failing, or personal records stolen in bulk and later appearing in phishing emails, which are fake messages designed to trick you into handing over passwords or card details.
If a service you rely on goes dark and the organisation blames a cyber incident, assume any data it held on you could be in criminal hands. Change the password for that service and for any account where you've reused it.
Should you worry about the quiet month?
My read: the silence on the leak site deserves more attention than the fresh Symantec report. Warlock's heavy reliance on a single family of SharePoint bugs makes a rebrand cheap if the current name gets too hot. Crews that go dark on their own extortion platforms often resurface under new branding within weeks. We've covered sixteen SharePoint-related stories in the last 90 days, and the volume alone tells you how busy this attack surface has become. Watch for a cluster of new victims under an unfamiliar name hitting the same sector mix.



