# When Changing Your Password Doesn't Actually Change Anything: Russian Hackers Found a Way to Stay Inside Microsoft OWA
The call every security team dreads comes in — possible email compromise, suspected Russian access, executives' mailboxes potentially exposed. The incident response playbook kicks in. Passwords reset, MFA enforced, credentials rotated. Everyone breathes a little easier. Containment achieved.
Except it wasn't. The attacker is still there.
That's the scenario Microsoft disclosed this week, confirming that a Russian threat actor — assessed with high confidence to be tied to SVR, Russia's foreign intelligence service — had been exploiting a vulnerability in Outlook Web Access to maintain persistent mailbox access that survives credential rotation entirely. Change the password. Rotate the tokens. Kick them out the front door. They're already back in through the window.
## The Persistence Problem Nobody Was Advertising
OWA has always been a high-value target. It's the exposed face of Exchange infrastructure, sitting on the perimeter, accessible from anywhere, authenticating thousands of users a day. State-sponsored actors have abused it for years — the 2021 Hafnium campaign burned through Exchange Server flaws to compromise tens of thousands of organizations before Microsoft patched them, and that wave of exploitation still hasn't fully resolved across on-premises deployments.
But this is different. What's described here isn't a break-in exploit in the traditional sense. It's a persistence mechanism — something designed not to get you in, but to make sure you stay in once you're already there.
The technical core: SVR actors were leveraging a flaw in how OWA handles certain authenticated sessions or token states that allows them to maintain mailbox access independently of the account password. When credentials get rotated — the cornerstone of virtually every enterprise IR playbook — the attacker's access doesn't terminate. The authentication artifact they're holding remains valid.
The specific mechanism matters here. Microsoft's Exchange ecosystem has, over the years, accumulated a significant attack surface around OAuth application permissions, legacy authentication protocols, and delegated access grants. APT29 has repeatedly exploited exactly these seams — using registered OAuth apps and service principal abuse to survive password resets in previous campaigns. The SolarWinds aftermath in 2020 and 2021 featured exactly this: even after organizations believed they'd evicted the actors, forensic investigations kept finding residual access paths through OAuth app registrations and delegated mailbox permissions that hadn't been audited or revoked.
This flaw appears to be a variant of that same fundamental problem: Microsoft's identity and access layer in Exchange Online and OWA contains states that can be weaponized to outlast a credential rotation event.
## The Targets and Why They Were Chosen
SVR doesn't pick random organizations. Their campaigns consistently focus on high-value intelligence targets — government agencies, foreign ministries, defense contractors, technology companies with access to government contracts, and NGOs touching policy. Email is the crown jewel for intelligence collection. Persistent, invisible mailbox access means weeks or months of reading correspondence, tracking relationships, watching deal negotiations unfold, and monitoring internal communications that never were intended to leave the building.
The sophistication of the persistence mechanism tells you something about operational priority. Building a technique that survives incident response — that lets you watch while the defenders congratulate themselves on containment — takes significant resources and detailed knowledge of Microsoft's authentication internals. This is not ransomware affiliate work. This is a patient adversary with a specific collection requirement.
## What Defenders Got Wrong (and What to Do About It)
Here's what this disclosure should crack open in every enterprise security team: credential rotation is necessary but not sufficient for email compromise IR.
The playbook needs to expand significantly:
Mail.ReadWrite, Mail.Read, MailboxSettings.ReadWrite, or full_access_as_app. This is where persistence hides.The patch timeline matters too. If you're on Exchange Online, Microsoft's response cadence is faster than on-premises. If you're running hybrid or fully on-premises Exchange, the attack surface is larger and the remediation window is wider — and that's where the laggards are.
## HackWire Analysis
This disclosure lands at an uncomfortable moment for Microsoft's identity security narrative. Redmond spent the last two years on an aggressive public posture around the Secure Future Initiative — a direct response to Congressional pressure after the 2023 Storm-0558 breach, in which Chinese actors accessed senior US government officials' email accounts through a forged Microsoft signing key. The message was clear: we're taking identity security seriously, the problems are being fixed.
This SVR persistence technique suggests the attack surface in Microsoft's authentication and access layer is deeper than the public timeline implies. The fact that credential rotation — advice that's essentially table stakes in incident response — doesn't terminate attacker access represents a meaningful gap between what the security community assumes about Microsoft's architecture and what's actually true.
What's missing from most coverage is the organizational cost of what this technique enables. Getting detected and ejected from a network is a significant setback for a state actor. They lose visibility, potentially burn infrastructure, risk exposure of their tooling. A persistence mechanism that survives IR means they don't lose anything — they watch the defenders clean up and then continue collecting. The asymmetry is severe.
There's also a Microsoft 365 Copilot wrinkle worth watching. As organizations integrate AI assistants with deep mailbox and calendar access, the blast radius of a persistent mailbox access technique grows. If the attacker sees your email, they increasingly also see your AI assistant's context, summaries, and drafts. That's not addressed here, but it's a logical extension of the threat model.
For defenders: the immediate ask is an OWA and Exchange access audit, not just a password reset. Treat any suspected SVR contact as a reason to rebuild your application permission baseline from scratch. The actors have demonstrated they know your IR playbook better than you know their persistence toolkit.
— HackWire Editorial
## Related Coverage