Attackers copied two months of incoming mail at Belgium's research network Belnet
Belgium's national research network Belnet says attackers copied all of its incoming email for more than two months. Every message sent to Belnet and to one of its customers between 22 July and the morning of 25 September was duplicated, together with its content and attachments, and moved to outside infrastructure. The cause, Belnet wrote in a statement on its site, was "a zero-day vulnerability affecting technology provided by an external supplier".
The copying ran for 65 days. Belnet found the intrusion on 24 September and closed the hole the next morning at 08:10. How many messages were taken is still unknown. The Centre for Cybersecurity Belgium is assisting with incident response and forensics, and the competent authorities have been notified.
Belnet connects Belgian universities, research institutes, schools and government bodies. That makes the people affected mostly outsiders: everyone who emailed a Belgian research or public address over the summer, from thesis supervisors to contractors sending signed documents. None of them will get a notification, because none of them are Belnet's customers.
The supplier is not named
Belnet has not said which supplier, which product, or which CVE. Without those, no other organisation running the same software can check whether it is exposed. Registered customers are pointed at the support desk; everyone else is given the address of the data protection officer.
A supplier's flaw becoming the customer's breach is the recurring shape of these incidents. Sweden's data protection authority made the same point in August when it fined an IT contractor over a leak that reached one in five people in the country.
A mail gateway sees everything that arrives
Encryption in transit does not cover an incident like this. Mail servers talk over TLS, but the gateway is the legitimate end of that connection and decrypts by design, because that is how it scans for spam and malware. Whatever arrives readable is readable to whoever controls the gateway.
The dates also overlap with a public case of exactly this kind. On 15 September Cisco patched CVE-2026-76461, an actively exploited flaw in its Secure Email Gateway that gave unauthenticated attackers root access. Attackers could "maintain access to the email gateway and monitor communications", VulnCheck's Spencer McIntyre told CyberScoop. Whether Belnet ran that product is unknown: Belnet does not say, and Cisco has not named victims.
For senders the practical advice is short. Treat anything sent into that window as read by a third party, attachments included, and look first for identity documents, contracts and invoices with bank details. Copied correspondence is the raw material for convincing invoice fraud. Similar breaches in education have run large: one at the University of Nottingham exposed 455,000 students.
A VPN would not have changed the outcome. The copying happened inside the recipient's own infrastructure, after delivery, not on the wire.