Attackers Copied Every Incoming Belnet Email for Two Months
Belnet says attackers copied every incoming email sent to it and one customer from 22 July until the morning of 25 September 2026. The copied material included message contents and attachments and was transferred to external infrastructure.
Its incident notice attributes the breach to an external supplier’s zero-day vulnerability. Belnet detected the incident on 24 September and says the flaw was resolved at 08:10 the following morning. Belgium’s Centre for Cybersecurity is assisting. The supplier, product, actor, affected customer and message count are not named; the investigation remains open.
Senders need an exposure review too
The practical response should follow the correspondence, not just the recipient accounts. An organisation that sent a contract, a support bundle or a recovery link needs to identify that specific material and decide whether it still creates risk. Those are examples to check, not a confirmed inventory of what was taken.
A successful delivery receipt says nothing about whether another copy exists. Likewise, containment cannot recall material already transferred elsewhere. Separate the mail service’s recovery from the sender’s work to revoke secrets, notify the right people and watch for convincing follow-up requests.
Turn the two-month window into a manageable review
Build a restricted exposure list with the sending team, date, recipient and information category. Assign an owner to each item. Prioritise credentials and sensitive attachments rather than copying all affected correspondence into a new widely accessible spreadsheet. Keep the review auditable without creating another unnecessary repository of private data.
What senders and affected organisations should do
- Search the period. Identify messages sent to Belnet between 22 July and the morning of 25 September, including automated notices and forwarded attachments.
- Classify the content. Record whether the messages contained credentials, recovery links, personal data, contracts, financial instructions, research material or protected operational information.
- Rotate live secrets. Replace passwords, API keys, tokens or private links that were sent in clear text or attached documents. Do not assume a message remained private because it was delivered successfully.
- Warn participants about thread hijacking. Verify payment changes, credential requests and unexpected follow-ups through a second channel.
- Preserve evidence. Keep copies and headers of relevant messages so future notifications or indicators can be matched to the actual exposure.
- Ask Belnet for scoped guidance. Organisations should confirm whether their addresses, domains or shared services fall within the affected customer environment.
BlackTree’s analysis of the recent Roundcube exploitation warning made the same operational point from a different incident: email infrastructure is not merely a communication layer. It is a store of identity, history and authority.
Sources
- Belnet, Security and privacy incident affecting Belnet’s IT infrastructure, published 25 September 2026 at 17:19 CEST. The notice says the vulnerability was resolved at 08:10 that morning and the investigation remains ongoing.
Continue the series: European National Cyber & Digital Law Series index


