Russian Hackers Abuse Microsoft OWA Bug to Maintain Access Post-Password Change
Threat actors are leveraging a patched Microsoft Outlook Web Access flaw to retain mailbox access even after credentials are rotated. Targets include government agencies and critical infrastructure sectors across the US and Europe.
TL;DR
- Russian state-sponsored hackers exploited a Microsoft OWA vulnerability to maintain persistent access.
- The flaw allowed attackers to bypass credential rotation efforts by high-value targets.
- Sectors affected include government, telecom, finance, hospitality, and aerospace.
- Activity was detected starting July 22, 2026.
- Organizations should review mailbox access logs and enforce full session invalidation post-compromise.
Cybersecurity researchers have uncovered a new campaign attributed to Russian threat actors who leveraged a now-patched vulnerability in Microsoft Outlook Web Access (OWA). This exploitation enabled them to maintain unauthorized access to email accounts even after organizations rotated user credentials.
The ongoing campaign has impacted high-profile entities including government institutions and private sector organizations in the telecommunications, financial services, hospitality, and aerospace industries across the United States and Europe. Initial attacks were first observed on July 22, 2026.
Attack Vector and Persistence Tactics
- Hackers used a previously unknown flaw in Microsoft OWA to establish backdoor access that survived password resets.
- The technique allowed adversaries to maintain long-term presence within compromised environments.
- Session tokens were manipulated to avoid detection during standard security audits.
- Initial compromise likely involved phishing or credential stuffing to gain entry before leveraging the OWA bug.
Impacted Sectors and Defensive Recommendations
- Government agencies in the US and EU were primary targets alongside critical infrastructure operators.
- Telecom, finance, hospitality, and aerospace firms reported suspicious mailbox activity.
- Security teams are advised to audit OWA configurations and monitor for unusual authentication patterns.
- Immediate session termination and token revocation should follow any suspected account takeover.
- Organizations using legacy Exchange versions should prioritize migration to modern, supported platforms.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.