Russian Hackers Exploit Outlook Flaw to Maintain Access in US and Europe
AI-generated from multiple sources. Verify before acting on this reporting.
LONDON (AP) — Russian threat actors known as Laundry Bear have exploited a vulnerability in Microsoft's Outlook Web Access service to maintain persistent access to email accounts across government agencies and private sector organizations in the United States and Europe. The cyber intrusion, detected on Aug. 3, 2026, utilized a custom JavaScript browser-based implant codenamed OWAReaper to bypass standard security controls within Microsoft's webmail client.
The attack campaign targets high-value email infrastructure, allowing the threat group to retain control over compromised mailboxes even after users change passwords or administrators reset credentials. By embedding malicious code directly into the Outlook Web Access interface, Laundry Bear ensures that their access remains active as long as victims interact with the service through a web browser.
Microsoft identified the flaw and issued patches on Aug. 3 following reports of suspicious activity originating from Russian-linked infrastructure. The vulnerability allowed attackers to inject scripts that executed in the background whenever an authorized user logged into Outlook Web Access, effectively creating a backdoor that was invisible to traditional email security filters. Security researchers noted that OWAReaper is designed specifically for long-term espionage and data exfiltration rather than immediate disruption.
Affected entities span both public and private sectors across North America and Western Europe. While specific organizations have not been publicly named, the scope of the intrusion suggests a coordinated effort to monitor communications within critical industries including energy, finance, and national security. The use of OWAReaper marks an evolution in Laundry Bear's tactics, shifting from initial access via phishing or stolen credentials to maintaining presence through client-side exploits.
Cybersecurity officials warn that organizations relying on web-based email clients remain at risk until they apply the latest Microsoft updates. Experts advise administrators to review logs for unusual JavaScript activity and monitor for unauthorized forwarding rules within compromised accounts. The persistence mechanism employed by OWAReaper requires users to simply visit their inbox, making detection difficult without specialized endpoint monitoring tools.
The incident raises concerns about the resilience of cloud-based email platforms against state-sponsored actors who are increasingly targeting web interfaces rather than server-side infrastructure. As Microsoft works with affected customers to remediate the breach, questions remain regarding how long Laundry Bear maintained access before the vulnerability was discovered and whether any sensitive data has already been exfiltrated.
Investigations into the full extent of the compromise continue as security teams scan for indicators of OWAReaper deployment across global networks. The attack underscores the growing sophistication of Russian cyber operations, which now leverage browser-based implants to sustain access within widely used enterprise applications.