Belnet Email Breach Exposes Messages and Attachments From Outside Senders

Stephanie Adlam
3 Min Read
An envelope produces a second copy that slips away from the intended mail tray
Belnet says incoming correspondence was copied to external infrastructure.

Emails sent to Belgium’s Belnet were copied by attackers, including their attachments. Its September 25 disclosure covers incoming mail to Belnet and one customer between July 22 and the morning of September 25, 2026. For an outside sender, that creates an uncomfortable distinction: correspondence can escape through its destination without anyone signing in to the sender’s account.

The copy was taken at the receiving end

Belnet says it detected the incident on September 24 and contained it the following morning after fixing a supplier’s zero-day vulnerability. The stolen messages went to external infrastructure. The supplier, affected customer and message count were not named; the investigation continues with Belgium’s Centre for Cybersecurity.

The important word is copied. A message still sitting in your Sent folder, or a normal reply from its recipient, cannot establish that the correspondence remained private. Delivery and confidentiality answer different questions. Fixing the vulnerable system can stop further exposure; it does not retrieve copies already taken.

This also differs from the phone-record extortion case involving Wagenius, where non-content records exposed connections between people. Here the disclosed scope includes what the messages actually said and the files attached to them.

Start with what you sent

If you corresponded with Belnet during the stated window, review those sent messages and their attachments. The useful first question is which information left your control. A routine scheduling exchange and a document containing reusable access details call for different responses.

If a message contained a password, API token or other still-valid secret, invalidate that specific secret through the service’s normal controls. If it contained personal or confidential business information, give your security or privacy contact an inventory so they can assess the affected people and documents. These are conditional response steps, not claims that Belnet has confirmed those particular data types.

Be cautious if a later message uses details from that correspondence to request a payment, a new document or a sign-in. Check the request through a previously established contact route. Familiar project names or accurate attachment details are weaker evidence of identity once the underlying conversation may have been copied. Belnet’s notice does not establish that such follow-on phishing has occurred.

Registered customers can contact Belnet Support; other affected senders can use the data-protection contact in the official notice below. The immediate task is to identify exposed correspondence and respond to its contents. This incident alone does not prove that your own mailbox or computer was compromised.

References

  1. Belnet. “Security and privacy incident affecting Belnet’s IT infrastructure.” September 25, 2026. Official incident notice and contact information.
Share This Article
Follow:
Stephanie is our wordsmith, transforming technical research into engaging content that resonates with users. Her expertise in cybercrime prevention and online safety ensures that Gridinsoft's advice is accessible to everyone—whether they’re tech-savvy or not.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?