Your email might be safe even if you change your password, but a new trick from hackers could keep them reading your messages. Russian government-backed hackers, known for past attacks, have found a way to maintain access to Microsoft Outlook email accounts, even after the account owner resets their password. This isn't about guessing your new password, it's about bypassing the usual security steps.

Here's what happened: These hackers exploited a weakness in Microsoft Outlook Web Access (OWA), which is how many people check their work emails through a web browser. Normally, if someone has your password and you change it, they lose access. But with this OWA flaw, the hackers could create a "backdoor," essentially a secret spare key, that still worked even after you threw out the original key (your old password).

Think of it like this: Imagine you have a house key that someone steals. You quickly change the locks, thinking you're safe. But what if the thief, before you changed the locks, installed a hidden keypad on the back door that still lets them in, no matter how many times you change the front door key? That's what these hackers did with OWA. They found a way to keep their access alive, even after the usual security measure (changing your password) was taken.

This attack, which started in late July 2026, targeted a range of important organizations. These included government bodies in the U.S. and Europe, plus companies in telecommunications, finance, hospitality, and aerospace. While the specific vulnerability they used in OWA has now been fixed by Microsoft, the incident highlights a broader trend: highly sophisticated groups are constantly looking for new ways to keep their access secret, even after initial detection. Unlike simpler phishing attacks, this isn't about tricking you, it's about finding deep technical weaknesses.

This matters because it shows that even with good practices like strong passwords and regular changes, sophisticated attackers can sometimes find workarounds. It's a reminder that digital security is a continuous cat-and-mouse game. If your organization uses Microsoft OWA, you should ensure all your systems are fully updated with Microsoft's latest patches to close this specific loophole.

Even after changing your password, sophisticated hackers can find ways to maintain access to your email if underlying system vulnerabilities are present.