






Hafnium and DearCry have compromised more than 30,000 companies that use on-prem Exchange servers making it one of the largest known cyberattacks to date – larger than the recent SolarWinds’ Sunburst. The impact of Hafnium/DearCry is staggering. Imagine every supplier, trade secret, customer name, formula, research project, key customer relationship, source code, and new product activity being downloaded, indexed, and examined by bad actors. To make matters worse, after stealing the secrets embedded in your emails, the bad actors piggyback the DearCry ransomware on the infected servers encrypting your email history and holding it hostage unless you pay them huge sums of money. It’s the ultimate double whammy.
There are millions of Exchange servers whose status remains unknown. Sure, many were patched but many remain unpatched and vulnerable. Regardless of your Exchange server state (patched or not), Intrusion Shield alone offers real-time protection for those servers impacted by this (or an undocumented variant) Zero-Day which installed back doors that remain unknown and undiscovered – but will run remote instructions on-demand from the malware team in the future. Intrusion Shield is an affordable Security-as-a-Service that requires no capital expense, no configuration, and installs automatically without human intervention. It works in real-time and keeps you safe within minutes of plugging it in. It’s a new kind of defense that protects against Zero-Day attacks by taking an inside-out approach to preventing cyberattacks. For example, our customers were protected from the SolarWinds Sunburst and the Microsoft Exchange Hafnium Zero Days.
Intrusion Shield works differently from typical network security products: it uses reputation, behavior, and complete knowledge of every Internet node as input for our AI to make kill or pass decisions. In addition, it watches real-time behavior on all inbound and outbound communications to protect against malware or other ‘back-door’ code that may already be installed on your network. We refer to this as inside-out defense. Using this approach, we consider traffic into and out of your network as equally un-trustworthy and typically find existing devices (servers, desktops, and other endpoints such as IoT devices) inside your network are already compromised.
Contrast this with the rest of the security industry that focuses on signatures and use an outside-in approach. Using this approach, your internal network is considered trustworthy and can communicate with virtually any IP, good or bad, with very little consequence resulting in countless businesses and government organizations being successfully breached. Because Shield has a zero-trust approach to all traffic, it provides proactive protection before a cyberattack can harm your business. The following are some of the advantages of Shield:
If you use Shield, you don’t have to do anything. You are and were protected even before this breach. For all other organizations using Microsoft Exchange, we advise the following:
Any non-Shield customer should follow the advice on the Microsoft Blog (below) and run the MSERT scan as part of assumed breach and incident response.
INTRUSION Shield is inexpensive enough to be affordable to every business, large or small. For a small fee per seat, per month - with no annual contract and no hardware to buy - you can get immediate protection.

See what INTRUSION can do for your company with risk-free demo.

Simply enter your URL and get a detailed report emailed to you.