๐Ÿ”
Security ๐Ÿ“… 2026-07-30 ยท 09:41 AM IST โฑ 3 min read

Attackers Find Way to Keep Email Access Even After Password Changes, Microsoft System at Risk

Russian-linked hackers discovered a weakness in Microsoft's webmail system that lets them maintain unauthorized mailbox access despite password resets.

The Vulnerability Explained

Security researchers have discovered that Russian-linked hackers are exploiting a previously unknown weakness in Microsoft Outlook Web Access (OWA) โ€” the browser-based version of Outlook that lets people check email from any computer. The problem is significant: even when victims change their passwords, the attackers retain the ability to access compromised email accounts.

Think of it like this: imagine a burglar makes a copy of your house key. When you change your locks, the burglar's old key no longer works โ€” that's what should happen. But in this case, the burglar has found a backdoor that stays open even after the locks change. That backdoor in Microsoft's system allows persistent access.

How the Attack Works

The exploitation method takes advantage of how OWA handles authentication tokens โ€” essentially digital permission slips that prove you're allowed to access an account. When users log in normally, they receive these tokens that expire after a set time. However, attackers have found a way to manipulate or preserve these tokens so they remain valid even after a password change occurs.

This is particularly dangerous because most people believe changing their password solves a hacking problem. They don't realize that in this scenario, the attacker already has another way inside that bypasses the new password entirely.

What This Means

Organizations relying on Microsoft Exchange Server and OWA are potentially at risk. Email is where sensitive information lives โ€” passwords for other services, confidential business communications, financial details, and personal information. If an attacker maintains hidden access to someone's mailbox, they can steal ongoing communications, reset passwords for connected accounts, and monitor victim activity indefinitely.

The threat is amplified because victims may never realize they've been compromised. They change their password, assume they're safe, and continue using their email while the attacker watches from the shadows.

Why You Should Care

If you work for a company using Microsoft Exchange or access email through OWA, this affects your security posture. Business email compromise attacks are increasingly common, and this vulnerability provides attackers with a powerful tool to establish long-term access to organizational networks.

For individuals, this means your personal email accounts could be compromised without your knowledge. Attackers could use your email to launch attacks against your contacts, reset passwords on financial accounts, or gather personal information for identity theft.

What You Can Do

Until software makers issue and distribute fixes, organizations should prioritize enhanced monitoring of email access patterns and consider temporarily restricting OWA access to specific trusted networks.

This reminder shows why timely security updates and layered protection strategies matter more than ever.

๐Ÿ“Ž This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters โ†’