Threats · 102 days ago
A senior executive’s mailbox can be more valuable to an attacker than the messages themselves. Five months of quiet access gave them a live view of deal timing, enforcement plans, contacts, and calendar signals that can be used for market or intelligence advantage long before anything is public.
Researchers said the actor maintained near-continuous access to a senior global exchange executive’s Outlook mailbox using native Windows tools and system-level access, not a loud one-off theft. The reporting ties the mailbox exposure to emails, contacts, and calendar data at a major financial exchange, where non-public listings, enforcement actions, and market-moving events can map an organization’s near-term direction.
For firms that keep sensitive decisions in email, the real exposure is persistence: once an executive inbox is readable for months, the attacker can reconstruct business intent and timing from ordinary correspondence. That kind of visibility can outlast the initial intrusion and remain useful to traders, competitors, or foreign collectors.
3 sources covering this story
Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
Unknown attackers maintained at least five months of access to a senior global stock exchange executive’s Outlook mailbox.
Hackers Target Global Stock Exchange in Espionage Operation
The attackers had access to a senior executive’s email account for 150 days and exfiltrated data for months.
Global Stock Exchange Hit by Monthslong Email Campaign
A threat actor got a near-continuous view into an influential finance executive's email inbox, thanks to clever use of legitimate, native Windows tools.
Part of the PlainSec briefing for 2026-06-04