Russian state-backed hackers are breaking into email servers with no click and no attachment, then planting a hidden back door that survives a password reset and even survives wiping the machine. This is what an unpatched door really looks like, and why “we’ll just reinstall it” may not be enough.
Find Your Open Door First →
A plain-English computer security scan. No card needed to see your results.
The problem: Most owners assume the worst case is “we get hacked, we clean it up, we move on.” This story breaks that assumption. When a criminal gets in through an unpatched door, “we will just reinstall it” may not get them back out.
The straight answer: The businesses getting hit here are simply the ones that did not install a fix that was available for months. You do not have to run this exact software for the lesson to land. The whole game is finding your open door before someone else walks through it. Let me show you what happened and how to find yours first.
Hey folks! I want to walk you through a story that broke a rule I thought most business owners could count on. The rule was simple: if the worst happens and you get hacked, you wipe the machine, reinstall everything, and start clean. This one does not play by that rule, and I need you to see why.
Russian state-backed hackers, a crew Microsoft actively tracks, are breaking into Microsoft Exchange. That is the email server plenty of businesses still run in-house, on their own hardware, instead of in the cloud. The way in is nasty. A booby-trapped email takes over the mailbox the second it is opened in the web browser. No click. No attachment to fall for. Nothing for a careful employee to catch. Just opening the message is the whole attack.
Then comes the part that stops me cold. Once they are in, they plant a hidden back door that researchers named OWAReaper. And here is the gut-punch: it survives a password reset, and it survives wiping the machine and reinstalling it from scratch. The one move every business is told to fall back on, wipe and rebuild, does not evict this thing. That is a whole new level of “stuck with a problem.”
Now the important, honest part. The businesses getting hit are the ones that did not install a fix that already existed. Microsoft flagged this hole back in the spring and shipped fixes in June and July. This was never a mystery attack out of nowhere. It was a known door, a fix on the shelf for months, and the victims were simply whoever left it open.
Sources: Ars Technica, 2026, on the actively-exploited on-prem Exchange flaw (CVE-2026-42897); corroborated by BleepingComputer, The Hacker News, and Help Net Security. Reported victims to date have been government and large-enterprise targets; the patching lesson here is universal, not a claim that small businesses are the named targets.
Let me take the scary edges off and get to the part that actually matters for you. You may not run Exchange in your building. Most smaller businesses moved their email to the cloud years ago, and that is fine. So why should this land on your desk?
Because the shape of this attack is the shape of almost every serious breach, and it has nothing to do with email in particular. Watch the pattern:
That pattern does not care whether the software is Exchange, or your accounting program, or the firewall at your front door, or an old Windows machine in the back. Swap in any program you run. The story is the same. A hole gets found, a fix gets shipped, and the businesses that do not install it in time become the target list.
This is where I earn my keep, so let me be direct. In more than 35 years doing this, I have watched the “we will just clean it up later” mindset cost people dearly, and this OWAReaper mess is the loudest proof yet of why. Getting in was step one. Staying in, even after a full rebuild, was the real trick. Once a determined criminal is inside an unpatched system, getting them all the way back out is a nightmare you do not want to learn about from the inside. Keeping them out in the first place is the entire ballgame.
None of this matters as a tech story. It matters as a business story, so let me tell it that way. When a criminal gets in through a door you did not know was open, here is what is actually on the table.
That is the real stakes, and it is why the timeline is the whole lesson. Months of warning. A fix on the shelf. The difference between the businesses that are fine and the ones in a nightmare was not luck or brains. It was whether somebody made sure the door got closed.
My own father fell for a phishing email. That is a fake message built to trick you into handing over a password or your money. More than three decades in this field, and it still reached the person I most wanted to protect. The hosers got into his computer from far away and started hunting for his financial papers. My step-mother noticed something was wrong and called me. I stopped them before they reached his bank logins. We were lucky. We caught it in time. A day slower and it would have been a very different phone call.
That is what an open door feels like when it is your family, and it is why I would rather find the door for you now than help you clean up after someone else finds it. More than 35 years at this, since 1991. FBI InfraGard trainer. Not one client I manage has ever been hit by ransomware. That is not luck. It is closing the known doors while the fix is still fresh, instead of hoping nobody comes knocking.
You are right that a foreign government is probably not hand-picking your business. But that is not how this works anymore, and that is the trap. The hosers do not choose targets one at a time. They build a tool that scans the whole internet for one specific unpatched hole, and then it hits everybody who has it, from a government office to the plumber down the street. The tool does not know how big you are and does not care. It only knows whether your door is open.
So the honest question is not “am I important enough to be targeted.” It is “do I have a known, unpatched hole that an automated tool is already hunting for.” If nobody can answer that with a straight no, then small is no protection at all.
Let me ask you one plain question, and just answer it in your head. Would you rather find the open door yourself this week, calmly, on your own schedule, or find out it was open after someone already walked through it? Nobody picks the second one on purpose. And yet the second one is what happens by default, every time, to the business that never got around to looking. Sit with that for a second, because you are a careful owner, and careful owners are exactly the ones who assume this is handled. Those two things are both true, and that is uncomfortable.
That discomfort is not a sign you did something wrong. Keeping a running list of every piece of software you own and whether it is patched was never the job you signed up for. It drifted onto the pile quietly, the way most of this does, while you were busy running the place. That is not a knock on you. It is just a door that went unwatched because watching it was nobody’s clear job.
Here is the thing about that door. You only get to close it two ways. You can tell yourself you are too small to matter, and carry that quiet itch into the next headline like this one, and the one after that. Or you can take a few minutes, find out exactly where your doors stand, and put the question to bed. One of those roads ends the worry. The other just reschedules it, and after an attack like this one, rescheduling can get very expensive. Acting is not the scary option here. Acting is the thing that makes the worry stop.
The whole lesson of this story is that finding the door first beats cleaning up after. The next move is simple, and you do not have to do it alone.
Book a call, on us. We scan your computers and hand you a plain-English list of what is unpatched and what is exposed, then fix the single most important thing first. You will not pay a dime, and you decide what happens next.
Not one client we manage has ever been hit by ransomware. That is not luck. That is closing the known doors before anyone comes knocking.
You run your business. We keep it running.
Book My Scan →
A few minutes with a real person, straight talk on where your business stands. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#UnpatchedSoftware #ExchangeServer #SmallBusinessCybersecurity #PatchManagement #ForwardToSafety
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.