What's happening in email security: June 29 – July 5, 2026
Last week the story was that phishing can pass your authentication checks. This week it's the sequel: once an attacker has a token, they don't need to phish you again. A ToddyCat tool quietly read corporate Gmail by riding an OAuth session, a Russia-linked crew phished Ukrainian targets with booby-trapped remote-desktop files, and a flaw in Apple's Hide My Email re-exposed the addresses it was built to hide. The through-line on the token story is persistence: modern email compromise is increasingly about holding access, not just getting in.
ToddyCat's "Umbrij" reads Gmail with a token, not a password
Kaspersky attributed a new .NET tool called Umbrij to the ToddyCat APT, and the technique is worth understanding. It launches a Chromium browser in headless mode through a remote debugging port, rides the victim's already-active Gmail session to grab an OAuth authorization code, then trades that for an access token. From there it reads corporate Gmail, Drive, Contacts, Calendar, and Tasks straight through the Google API.
The important part is how it gets in. Umbrij never needs the password and never faces an MFA prompt. It rides a Gmail session the user already authenticated, extracts an OAuth authorization code, and trades it for an access token that reads mail straight through Google's API, off the box entirely. The compromise happens after the login, so the login is never the thing that fails. We've spent recent weeks on device-code and token theft against Microsoft 365, and Umbrij is the reminder that Google Workspace has exactly the same exposure. If you're only watching for failed logins and password anomalies, this kind of access is invisible to you. Auditing which apps and OAuth grants can reach your mail, and alerting when new ones appear, is the control that actually applies here, and it applies to both major mail platforms.
Turla is phishing Ukraine with malicious RDP files
Check Point's threat intelligence roundup flagged a Russia-linked Turla campaign, tracked as StockStay, targeting Ukrainian organizations with phishing emails carrying malicious remote-desktop configuration files. A .rdp file is an underrated lure, because it looks mundane and can hand an attacker a foothold with a double-click. Worth adding to your gateway rules and your user-awareness examples if you're in a targeted sector.
Apple's Hide My Email can be unmasked
A researcher reported that a flaw in Apple's email-relay service can reveal the real address behind a masked alias, and said that in limited testing every Hide My Email address tested was unmaskable. Apple was reportedly told over a year ago and it's still unfixed, so technical details are being withheld. Masked-email relays are a common privacy control, and a reliable unmasking flaw re-exposes users' true addresses to spam, phishing, and correlation.
- The KDDI breach kept rippling out
Reporting through the week put last week's Japanese ISP breach at up to 14.2 million sets of email credentials across the six providers. KDDI still hasn't disclosed the hashing algorithm for the passwords that were protected, which is reason enough to treat the whole set as compromised.
Want email security news in your inbox every week?
Subscribe here and stay up to date with what's happening in email security.




