Most observers attribute the attack, which leveraged VPN and Microsoft 365 security holes, to state actors working for China.