Why the Exchange OWA Zero-Day Exploit Is a Corporate Email Crisis
A sophisticated Russian-linked threat actor has been actively exploiting a zero-day vulnerability in Microsoft Exchange's Outlook Web Access (OWA) interface to gain persistent, long-term access to corporate mailboxes — and the attack is largely flying under the radar of conventional security tooling. The Exchange OWA zero-day exploit allows attackers to silently authenticate and monitor email accounts over extended periods, giving adversaries the ability to exfiltrate sensitive communications, harvest credentials, and conduct intelligence gathering without triggering standard alerts. For IT decision-makers, developers building on Microsoft infrastructure, and privacy professionals operating under GDPR obligations, the implications are severe and demand immediate attention.
What makes this campaign particularly alarming is not just the technical sophistication of the vulnerability itself — it is the dwell time. Security researchers have found evidence suggesting that compromised mailboxes remained under attacker control for weeks, if not months, before any detection occurred. This is consistent with a broader pattern of state-sponsored intrusion operations, where the goal is persistent intelligence access rather than immediate financial gain. According to a widely cited finding from breach and attack simulation firm Picus Security, security teams successfully log only 54% of attacks and generate alerts on just 14% — meaning the vast majority of intrusions move through enterprise environments entirely unseen.

How the Attack Works: OWA as an Entry Point for Credential Theft
Outlook Web Access is Microsoft Exchange's browser-based email client, commonly exposed to the public internet to allow employees to access their email remotely. Its internet-facing nature makes it a high-value target for threat actors — and a zero-day in this component is particularly dangerous because it bypasses authentication controls that organisations rely upon without realising they are compromised.
In this campaign, the attackers appear to have leveraged the vulnerability to establish persistent access tokens or session cookies that survive password resets and conventional remediation steps. This is a hallmark of advanced persistent threat (APT) groups: rather than smashing and grabbing, they burrow in quietly and maintain access across remediation cycles. The technique echoes earlier Exchange-focused campaigns such as those leveraging ProxyLogon and ProxyShell vulnerabilities, which were also attributed in part to Russian and Chinese state actors and documented extensively by cybersecurity firms including Mandiant and CrowdStrike.
For organisations running on-premise Exchange servers — a setup that remains common in European enterprises, government agencies, and regulated industries precisely because of data sovereignty concerns — this vulnerability represents a direct threat to the integrity of internal communications. Even organisations that have migrated to Microsoft 365 may retain hybrid Exchange deployments that are equally exposed.
"The most dangerous adversaries are not the ones making noise — they are the ones sitting quietly inside your email system reading everything you send and receive, for months at a time, before you ever know they are there."
— Senior threat intelligence analyst, European cybersecurity consultancyThe Detection Gap: Why 86% of Alerts Are Never Generated
The statistical reality of enterprise security detection is sobering. Research from Picus Security's Red Report — which analyses millions of attack simulations across real-world enterprise environments — reveals that security information and event management (SIEM) systems and endpoint detection and response (EDR) tools fail to alert on the overwhelming majority of attack activity. Only 14 out of every 100 attacks that successfully penetrate an environment generate any security alert at all.
This is not simply a resourcing problem. It reflects fundamental gaps in how detection rules are written, tested, and maintained. Many SIEM rules are created at deployment time and never validated against evolving attacker techniques. Threat actors — particularly state-sponsored groups with access to zero-day exploits — actively probe detection boundaries and craft their intrusion techniques to fall beneath the threshold of common rule sets.
For organisations subject to GDPR, this detection gap creates an acute compliance crisis. Under Article 33 of the General Data Protection Regulation, controllers must notify their supervisory authority of a personal data breach within 72 hours of becoming aware of it. The operative phrase is "becoming aware" — but what happens when attackers have been inside your mail server for three months and your security tooling never fired a single alert? The answer is a regulatory exposure that compounds the original security incident significantly. European data protection authorities have already levied fines in cases where organisations failed to detect breaches promptly, as documented in the GDPR enforcement tracker maintained by CMS Law.
Who Is Most at Risk from the Exchange OWA Zero-Day?
While any organisation running an internet-facing Exchange OWA instance is technically at risk, certain sectors face disproportionate threat exposure. According to threat intelligence reporting from Microsoft's own Digital Crimes Unit and corroborated by findings from the European Union Agency for Cybersecurity (ENISA), Russian-linked APT groups consistently prioritise the following target categories:
| Target Sector | Primary Risk | GDPR Exposure |
|---|---|---|
| Government & Public Sector | Intelligence gathering, policy leaks | High — public authority obligations |
| Defence & Critical Infrastructure | Operational security breach | Very High — NIS2 directive applies |
| Financial Services | M&A intelligence, wire fraud enablement | High — financial data classification |
| Legal & Professional Services | Client confidentiality, legal strategy | High — privileged communication risk |
| Technology Companies | IP theft, source code access | Medium–High — employee data exposure |
| SMBs on Hybrid Exchange | Weakest detection posture | Medium — but least resourced to respond |
Small and medium-sized businesses are not typically the primary targets of state-sponsored espionage, but they frequently sit in the supply chains of high-value targets. Compromising a smaller supplier's email environment can give attackers visibility into the procurement, personnel, or operational communications of much larger organisations — a technique sometimes called "island hopping" in threat intelligence circles.
What Security and Privacy Teams Should Do Right Now
In the absence of a confirmed patch for a zero-day vulnerability, defenders must shift from reliance on signature-based detection toward behavioural monitoring and architectural hardening. Several concrete steps are available to security teams today, regardless of whether a formal vendor patch has been issued.
Restrict OWA exposure immediately. If your organisation does not have a business-critical need for public-internet OWA access, place it behind a VPN or zero-trust network access (ZTNA) gateway. This single step eliminates the externally reachable attack surface that makes this zero-day exploitable remotely. European organisations increasingly have access to open-source and privacy-respecting ZTNA solutions that avoid routing traffic through US-based cloud providers, an important consideration for data sovereignty under GDPR.
Validate your SIEM and EDR rules against known Exchange attack patterns. Breach and attack simulation (BAS) tools — such as those provided by Picus Security, as referenced in their whitepaper — allow security teams to continuously test whether detection rules would actually fire against techniques like those used in this campaign. Given that 86% of intrusions generate no alert, reactive monitoring alone is insufficient. Testing must be continuous and cover the full MITRE ATT&CK framework, not just commodity malware signatures.
Audit active mailbox sessions and OAuth tokens. Attackers maintaining persistent access via session tokens will often survive password resets. Security teams should audit all active sessions, revoke long-lived OAuth tokens, and enforce conditional access policies that require re-authentication from trusted devices and locations. Microsoft's own guidance on post-compromise hardening, available through the Microsoft Security Response Center, provides detailed steps for Exchange-specific token auditing.
Review GDPR breach notification obligations proactively. If your organisation operates Exchange infrastructure in the EU and cannot rule out exposure to this vulnerability, legal and compliance teams should begin preparing a preliminary breach assessment now. Waiting until a confirmed incident is documented may put you outside the 72-hour notification window. ENISA's guidance on personal data breach notification provides a practical framework for this assessment process.

The Bigger Picture: State-Sponsored Attacks on European Email Infrastructure
This incident does not exist in isolation. It is the latest chapter in a sustained, multi-year campaign by Russian-affiliated threat actors to compromise Western email infrastructure. The SolarWinds campaign, disclosed in late 2020, involved the compromise of Microsoft 365 email accounts at numerous US government agencies and European organisations. The HAFNIUM campaign targeting on-premise Exchange servers exposed hundreds of thousands of organisations globally. According to reporting by Wired and subsequent analysis by Volexity and Mandiant, these campaigns consistently targeted email as the primary intelligence channel — because email is where decisions are made, strategies are discussed, and sensitive data flows continuously.
The European context adds additional regulatory and geopolitical dimensions. The EU's NIS2 Directive, which entered force in October 2024, significantly expands the scope of critical infrastructure operators required to implement appropriate cybersecurity measures and report incidents. Organisations that fall under NIS2 and are running unpatched Exchange infrastructure face dual liability: a security incident and a regulatory compliance failure simultaneously. The directive covers sectors including energy, transport, finance, health, digital infrastructure, and public administration — a broad mandate that captures a substantial proportion of Exchange deployments across the continent.
From a digital sovereignty standpoint, incidents like this Exchange OWA zero-day reinforce the case being made by European cloud providers and open-source advocates: centralised dependency on a single US-based productivity platform creates systemic risk that cannot be fully mitigated at the application layer. Sovereign cloud alternatives, including Nextcloud for collaborative communication
Originally reported by BleepingComputer. Summarised and curated by European Purpose.