SmarterTools network breached using auth bypass attack against a single unpatched virtual machine


  • SmarterTools hit by Warlock ransomware exploiting CVE-2026-23760 in SmarterMail
  • Breach affected office networks and data center, but business apps and account data remained secure
  • The company fixed the vulnerability, dropped Windows servers and dropped Active Directory to prevent a recurrence

US software company SmarterTools confirmed it had been hit by ransomware, but said the attack did not affect its business applications or account data.

In a data breach notice published on the company’s website, Chief Commercial Officer Derek Curtis said the company missed updating a server, which was then compromised through a known vulnerability.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top