Russian-linked hackers discovered a weakness in Microsoft's webmail system that lets them maintain unauthorized mailbox access despite password resets.
Security researchers have discovered that Russian-linked hackers are exploiting a previously unknown weakness in Microsoft Outlook Web Access (OWA) โ the browser-based version of Outlook that lets people check email from any computer. The problem is significant: even when victims change their passwords, the attackers retain the ability to access compromised email accounts.
Think of it like this: imagine a burglar makes a copy of your house key. When you change your locks, the burglar's old key no longer works โ that's what should happen. But in this case, the burglar has found a backdoor that stays open even after the locks change. That backdoor in Microsoft's system allows persistent access.
The exploitation method takes advantage of how OWA handles authentication tokens โ essentially digital permission slips that prove you're allowed to access an account. When users log in normally, they receive these tokens that expire after a set time. However, attackers have found a way to manipulate or preserve these tokens so they remain valid even after a password change occurs.
This is particularly dangerous because most people believe changing their password solves a hacking problem. They don't realize that in this scenario, the attacker already has another way inside that bypasses the new password entirely.
Organizations relying on Microsoft Exchange Server and OWA are potentially at risk. Email is where sensitive information lives โ passwords for other services, confidential business communications, financial details, and personal information. If an attacker maintains hidden access to someone's mailbox, they can steal ongoing communications, reset passwords for connected accounts, and monitor victim activity indefinitely.
The threat is amplified because victims may never realize they've been compromised. They change their password, assume they're safe, and continue using their email while the attacker watches from the shadows.
If you work for a company using Microsoft Exchange or access email through OWA, this affects your security posture. Business email compromise attacks are increasingly common, and this vulnerability provides attackers with a powerful tool to establish long-term access to organizational networks.
For individuals, this means your personal email accounts could be compromised without your knowledge. Attackers could use your email to launch attacks against your contacts, reset passwords on financial accounts, or gather personal information for identity theft.
Until software makers issue and distribute fixes, organizations should prioritize enhanced monitoring of email access patterns and consider temporarily restricting OWA access to specific trusted networks.
This reminder shows why timely security updates and layered protection strategies matter more than ever.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters โ