Russian Hackers Exploit Exchange Zero-Day: What SMBs Must Know

A recently disclosed cyberattack campaign has confirmed what security professionals have warned about for years: your business email could be compromised right now, and you might not know it for months. Russian state-linked hackers have been exploiting an Exchange OWA zero-day vulnerability — a previously unknown security flaw in Microsoft's Outlook Web Access — to gain persistent, long-term access to corporate mailboxes. For small and medium businesses, the implications deserve serious attention.

What the Exchange OWA Zero-Day Attack Actually Means

A zero-day vulnerability is a flaw in software that the vendor hasn't had the chance to patch yet, meaning attackers can exploit it freely until a fix is released. In this case, the target was Microsoft Exchange's Outlook Web Access — the browser-based interface that millions of organisations use to access their email remotely. The attackers didn't smash and grab. They moved quietly, maintaining persistent access to inboxes over an extended period. That kind of long-term access allows them to read sensitive communications, intercept financial instructions, harvest credentials, and map out an organisation's relationships and workflows.

This isn't exclusively a large enterprise problem. SMBs are frequently targeted precisely because they tend to run older, less-monitored infrastructure and often lack a dedicated security team watching for anomalies.

Why Persistent Email Access Is So Dangerous for Small Businesses

When an attacker sits inside your email environment for weeks or months, the damage goes well beyond reading messages. They learn your suppliers, your payment processes, your staff names, and your communication patterns. That intelligence fuels convincing phishing attacks, Business Email Compromise (BEC) fraud — where attackers impersonate executives or vendors to redirect payments — and credential harvesting that spreads laterally into other systems.

The credentials stolen during campaigns like this one don't disappear when the attacker is done. They get packaged and sold. Within days or weeks of an initial breach, those usernames, passwords, and session tokens can appear in infostealer logs shared in closed Telegram channels, bundled into credential dumps on dark web marketplaces, or embedded in combolists circulating among cybercriminal communities. By the time your IT manager notices something unusual, your data has often already changed hands several times.

How to Tell If Your Organisation Has Already Been Exposed

The uncomfortable truth is that most SMBs have no reliable way to know whether their credentials or email data have surfaced somewhere on the dark web or in a breach database. Checking Have I Been Pwned occasionally is a starting point, but it covers only a fraction of the exposure landscape. It won't show you infostealer logs, freshly traded credential dumps, or data scraped from your company's domain that's circulating in private forums.

A thorough exposure check needs to cover breach databases, infostealer dump repositories, dark web markets, public code repositories where credentials get accidentally committed, and your domain's infrastructure footprint. That means looking at every email address associated with your domain, not just the ones you think are important. A forgotten staff account or an old contractor login can be just as damaging as the CEO's credentials.

Organisations using on-premises or hybrid Microsoft Exchange environments should treat this latest campaign as an urgent prompt to audit their external access points, review authentication logs for unusual activity, and verify that their Exchange installation is fully patched. Enabling multi-factor authentication on OWA, if not already active, is non-negotiable at this point.

What Breachrr Recommends After the Exchange Zero-Day Disclosure

In the wake of this Exchange OWA zero-day campaign, the businesses most at risk are those operating without any visibility into where their credentials and data currently exist outside their own walls. Attackers exploiting vulnerabilities like this one generate exposure that persists long after the initial intrusion is closed. Patching the vulnerability stops new access — it doesn't claw back the data already extracted.

At Breachrr, we monitor breach databases, infostealer dumps, dark web markets, public code repositories, and domain infrastructure to give SMBs a clear picture of their current exposure. You can't protect what you can't see. If this story has prompted you to wonder whether your organisation's credentials are already out there, the right next step is to find out. Run a free audit at breachrr.com/audit and get a real answer within minutes.

Want to see if your company is exposed?

Want to see if your company is exposed?

Run a free audit →
Russian Hackers Exploit Exchange Zero-Day: What SMBs Must Know · Breachrr · Breachrr