Belnet, the Belgian government and research network, confirms a supplier zero-day let attackers copy all incoming mail to Belnet-owned domains and the transfer links its FileSender and FedSender services sent directly for 65 days
A national research and government network had mail to its domains copied for 65 days via an unnamed supplier's zero-day
Analysis
Belnet identified the incident on 2026-09-24 and says an attacker exploited a zero-day in technology from an external supplier, remediated on 2026-09-25 (Belnet, 2026-10-01). Between 2026-07-22 and the morning of 2026-09-25, a window of 65 days, the attackers copied to external infrastructure all incoming mail to Belnet-owned domains (for example guest-roaming and BNIX addresses) and every download link its FileSender and FedSender services generated and sent directly, which could let them fetch the transferred files; password-protected or authenticated transfers are described as unreadable unless the password was written in the upload comment, and Risky Bulletin adds that mail sent to one of its customers was also stolen (Belnet, 2026-10-01; Risky Bulletin, 2026-09-30).
Exposure: organizations that sent mail to Belnet-owned addresses or shared files through Belnet's FileSender or FedSender between 2026-07-22 and 2026-09-25, and any shared mail or file-transfer service run for government or education clients on technology from an external supplier (Belnet, 2026-10-01).
Cited evidence
On 24 September 2026, Belnet identified a security and privacy incident within its IT infrastructure. The incident was caused by the exploitation of a zero-day vulnerability affecting technology provided by an external supplier.
During the affected period, emails were copied by the attackers and transferred to external infrastructure.
At this stage, no further information is available regarding the identity or affiliation of the threat actor responsible for the incident.
Sources2
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.