Your safety profile is now part of the free plan. Tell us what you use, and we'll customize your alerts and guidance to match your online life.Build My Profile
MERENA
Advisory Alert

Microsoft Outlook bug let attackers run code on a user’s computer

Microsoft has fixed a flaw in Outlook Web Access that may have let attackers take over email accounts simply by getting someone to open a message in the web version of Outlook. Reports suggest the activity focused on government and organizations, but anyone using this webmail service should make sure protections are up to date.


Who is at risk

People and organizations that use Outlook Web Access, especially government offices and workplaces that rely on the web version of Outlook, are most at risk.

What to watch for

Watch for unusual email activity such as messages you did not send, missing emails, unfamiliar inbox rules, or sign-in alerts you do not recognize.

What to do

Make sure Microsoft security updates have been applied, sign out of all Outlook web sessions, change your email password, and turn on two-step verification if it is available.