Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Belnet says attackers copied incoming email for more than two months

A supplier zero-day exposed message content and attachments. We explain who should respond and how people and organisations can reduce the impact.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
27 September 2026
READING TIME
10 min read
TOPIC
Supply Chain Security
Belnet says attackers copied incoming email for more than two months

Belgian research-network operator Belnet has disclosed an incident in which attackers copied incoming email and transferred it to external infrastructure. The exposure window runs from 22 July until the morning of 25 September 2026. The copies included both message content and attachments.

This matters even to people and organisations that are not Belnet customers. If they sent a message to Belnet or the identified customer during that period, a copy may have left the controlled environment. The incident also shows why email risk cannot be assessed solely by securing the sender’s own mailbox.

What Belnet has confirmed

Belnet detected the security and privacy incident on 24 September. Its notice attributes the cause to a previously unknown vulnerability in technology provided by an external supplier. Belnet calls it a zero-day but does not name the product, provide a CVE identifier or disclose technical exploitation details.

The vulnerability was resolved at 08:10 on 25 September and the breach contained. Belnet says the attackers copied every incoming email sent to Belnet and one of its customers during the stated period. Copies of the messages, their contents and attachments were transferred to external infrastructure.

The organisation notified customers, competent authorities and the Centre for Cybersecurity Belgium. The investigation continues, so the precise scope may be refined. People who are not registered customers but sent email to Belnet during the affected period can contact its data protection officer.

First establish what was actually sent

Having an address in a contact list does not by itself mean someone was involved. The important question is whether a message was sent to an affected recipient between 22 July and the morning of 25 September. An organisation should search its email gateway, Sent folders, ticketing systems and other services that may have generated correspondence automatically.

The next step is to classify the content. A routine scheduling question calls for a different response from a message containing personal data, a contract, a technical report, an invoice, health information, a configuration file or an active access link.

Not every confidential message creates the same legal duty. The type of data, number of people, potential misuse, safeguards and the sender’s role in processing all matter. The assessment should be documented by the data owner, security team, legal function and data protection officer as appropriate to the organisation.

A password is not the only secret that may be hiding in email

Messages can contain invitation tokens, reset links, API keys, single-use download URLs, recovery codes, configuration files and passwords for encrypted archives sent through the same channel. If any such item still works, it should be revoked or changed. Deleting a message from the sender’s mailbox does not remove a copy already captured by an attacker.

For documents, determine whether they contain details that support convincing impersonation: names of case owners, contract numbers, amounts, deadlines, signature samples or approval procedures. An attacker does not have to publish a document to use it in a later fraud attempt.

People connected with exposed correspondence should therefore expect messages that refer to a genuine matter. Knowledge of an email’s contents is not proof that a subsequent sender is authorised. Requests for payment, a bank-account change, another sign-in or more documents should be verified through an independent channel.

What a sending organisation should do

The first task is to appoint an incident owner and build an inventory of potentially affected messages. The inventory should connect sender, recipient, date, subject, data type and attachments without becoming another uncontrolled store of sensitive information.

Further actions should be prioritised by risk:

  • revoke active secrets, links and invitations;
  • notify data owners and the people responsible for the recipient relationship;
  • assess contractual, regulatory and data-protection requirements;
  • alert the help desk, finance team and people named in the correspondence to possible impersonation;
  • monitor the domains, accounts and processes discussed in the messages;
  • retain evidence of decisions and the basis for the risk assessment.

A vague warning to the entire company is unlikely to help. A targeted notice to people who are actually involved should explain the period, type of correspondence, credible misuse scenarios and the official reporting channel.

The lesson for supplier contracts and email design

Belnet points to an external supplier’s technology as the source of the vulnerability. That does not automatically assign all consequences to the supplier, but it shows the value of contractual terms covering incident disclosure, investigation support, logs, remediation timing and the information customers need to meet their own obligations.

It is also worth reducing the volume of sensitive content carried directly in email. For higher-value documents, a controlled portal with separate authentication, expiring access and revocation may be safer. Such a portal still requires security, but it can prevent permanent attachment copies from accumulating in many mailboxes.

An organisation should know which gateways, filters and services handle a message before it reaches the recipient. Availability, spam protection and archiving form an email supply chain in which each component may gain access to content.

What the notice does not yet establish

Belnet has not disclosed the supplier, product or exploitation method. It has not provided a message count, a complete list of affected organisations or evidence of subsequent misuse. The notice does not support attributing the attack, its motive or its full scale.

It does, however, establish a defined time window and data type: copies of incoming email, including content and attachments. That is enough for senders to conduct their own assessment rather than wait passively for the entire investigation to conclude.

Source facts and Breachroad’s conclusions

Belnet confirms the detection date, an external supplier zero-day, remediation at 08:10 on 25 September, and copying of incoming messages between 22 July and the morning of 25 September. The source says captured copies included content and attachments, and that the investigation continues.

Message prioritisation, secret revocation, impersonation warnings, organisational response and safer file-exchange design are Breachroad’s conclusions. Organisations can strengthen the process through third-party risk management and an incident response plan. The misuse of captured correspondence is also a useful scenario for cybersecurity awareness training.

SHARE / COPY