TL;DR — 15 Second Read
- →What is it? Hackers are sending specially crafted "poisoned" emails. If you open one in your browser-based work email, it runs a hidden script to hijack your account.
- →How does it affect YOU? Scammers can read your private work emails, steal sensitive documents, and send fake messages to your colleagues or vendors asking for money.
- →What should YOU do? Do not open suspicious emails at work, immediately alert your IT department so they can apply Microsoft's emergency patch, and report any financial fraud to the 1930 helpline.
When we think about cybersecurity, we usually worry about fake calls or shady WhatsApp messages. But right now, a massive threat is sitting right in the office inbox. Hackers are actively exploiting a new flaw (called CVE-2026-42897) in Microsoft Exchange—the system many Indian companies use to run their corporate email. This Microsoft Exchange email attack is incredibly sneaky because it doesn't require you to download a file; just opening a "poisoned" email on your web browser can give a hacker the keys to your professional life. Let’s break down exactly what this means for your digital security and how to keep your hard-earned money and private data safe.
Step-by-step remediation
- 1Don't Click: If an email looks even slightly suspicious, do not open it. Delete it immediately.
- 2Alert Your IT Department: This is crucial. Tell your IT team about this threat. Microsoft has released an "Exchange Emergency Mitigation Service" that acts as a digital shield. Your IT team needs to run a specific script (the EOMT tool) on the company servers to stop the attack.
- 3Change Your Passwords: If you think you opened a bad email, log out, clear your browser history, and change your work email password immediately from a safe device.
- 4Report Financial Fraud: If a vendor or your company actually lost money because of a hijacked email, freeze the accounts and immediately report it to cybercrime.gov.in or call the National Cybercrime Helpline at 1930.
What Happened
In the infosec world, this is known as a "Cross-Site Scripting" (XSS) attack. Here is how it works:
- 1The Poisoned Email: A hacker sends an email to your official work address. It might look like a normal vendor invoice or an HR alert, but hidden inside the email's formatting is invisible, malicious code.
- 2The Trigger: You log into your work email using Outlook Web Access (checking your email through a web browser instead of a desktop app) and simply click to read the email.
- 3The Hijack: The moment the email loads, the hidden code runs in the background. It bypasses your basic computer security and allows the hacker to trick the system into thinking they are you. They can now secretly perform actions from your account.
Signs You Are Being Targeted:
- •You receive strange, unexpected emails at work containing blank spaces, weird characters, or urgent requests from unknown senders.
- •You notice emails in your "Sent" folder that you definitely did not write.
- •Your colleagues or clients call to ask why you are sending them new bank account details or strange links.
Real-World Impact
If a hacker takes over your work email, your information security completely collapses. They can search your inbox for copies of your Aadhaar card, PAN card, or salary slips to steal your identity. Worse, they can use your trusted email address to message your company's vendors or accounting department, tricking them into sending lakhs of Indian Rupees (₹) to fraudulent bank accounts via UPI or wire transfer. A single compromised email account can threaten the entire network security of your workplace.
Prevention Tips
- •Verify Off-Platform: A core rule of internet security is to never trust an email blindly. If your boss or a vendor emails you asking for an urgent payment or a change in bank details, call them on the phone to verify.
- •Audit Your Account: Check your email "Rules" or "Forwarding" settings. Hackers often set up hidden rules to auto-forward your incoming emails to their own accounts.
- •Maintain Good Cyber Security Hygiene: Never store highly sensitive passwords, UPI PINs, or unencrypted personal documents in your work email inbox. Treat your data security as seriously at work as you do at home.
Frequently Asked Questions
I check my work email on the Outlook app on my phone. Am I at risk?
This specific bug triggers when you open the email using Outlook Web Access (checking mail via a web browser like Chrome or Edge). However, you should always treat suspicious emails with extreme caution regardless of the app you use.
My company uses regular Gmail. Do I need to worry?
No. This specific vulnerability only impacts organizations that host their own physical "on-premise" Microsoft Exchange servers (versions 2016, 2019, or SE). Cloud users are safe from this specific bug.
Can the hackers install a virus on my physical laptop through this?
The immediate threat is that the malicious script executes in your web browser to hijack your email session. However, once they control your email, they can easily send you convincing links to download actual malware, so remaining vigilant is essential.
Read Next
Threat Watch
How the Fake OpenAI Download Scam Works and What To Do
Threat Watch
CVE-2026-33626: LMDeploy SSRF Flaw Exploited in 12 Hours — Attackers Stole AWS Cloud Credentials via AI Image Loader
Threat Watch
CVE-2026-28950: Apple Patches iOS Flaw That Let FBI Extract Deleted Signal Messages From Push Notification Database
Threat Watch
OpenClaw AI Agent Attacks — Hidden Commands in a Contact Card Can Steal Your AWS Keys
Indian Scams
FIFA World Cup 2026 Scams Are Everywhere — Indian Fans Must Read This Before June 11
Last updated: May 15, 2026