CSIDB logo
Incident

SmarterTools

Incident posture

Attack window
Jan 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 10:04

Linked entities

Victim
SmarterTools
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An IT management software company fell victim to a ransomware attack through an unpatched instance of its own SmarterMail email server, with the incident impacting its office network and a data center that hosted quality control testing systems, the company's portal, and its Hosted SmarterTrack network. The attack's point of entry was a virtual machine running an outdated SmarterMail build, which allowed attackers to compromise the mail server and move laterally across the network to compromise 12 Windows servers. Upon discovering the breach, the company immediately shut down all servers at the affected locations, disabled internet access, eliminated compromised systems, removed Active Directory services, and reset passwords network-wide. The ransomware group known as Warlock, which emerged in mid-2025 and is believed to operate out of China, was identified as the perpetrator of the attack, likely exploiting a high-severity unauthenticated remote code execution vulnerability along with two other flaws that had been previously patched.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 29, SmarterTools, an IT management software company, suffered a ransomware attack that entered through an unpatched instance of its own SmarterMail email server product. The compromised mail server was a virtual machine located within the company's environment, and it was running a build of SmarterMail that did not yet include the security fixes released earlier that month. From this initial foothold, the attackers moved laterally through the network, identifying and compromising Windows servers they could reach. In total, 12 Windows servers were compromised during the intrusion. The ransomware operators behind the attack have been identified as Warlock, a group that emerged in June 2025 and is believed to be operating out of China. The specific vulnerability used to breach the SmarterMail server is tracked as CVE-2026-24423, an unauthenticated remote code execution flaw with a CVSS score of 9.3. This flaw, along with two others identified as CVE-2026-23760 and CVE-2025-52691, was patched by SmarterTools on January 15 in SmarterMail build 9518, with an additional update, build 9526, released on January 22 to provide further improvements. Notably, CVE-2026-24423 was the subject of a warning from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) the week prior to the SmarterTools incident, which indicated the vulnerability had been exploited in ransomware attacks without initially disclosing the specific victims. Given that SmarterTools has stated the Warlock gang also compromised some of its customers, it is likely that these customer compromises were among the incidents CISA referenced in its advisory. SmarterTools CCO Derek Curtis publicly disclosed details about the attack and the entry vector.

The impact of the incident was confined to two specific locations within SmarterTools' infrastructure: the company's office network and a data center. The affected data center hosted the company's quality control testing systems, the SmarterTools portal, and its Hosted SmarterTrack network. Services hosted on a separate network, including the company's main website, shopping cart, My Account portal, and other customer-facing services, were not impacted by the attack. When the breach was initially detected, SmarterTools responded by immediately shutting down all servers at the two affected locations and disabling all internet connectivity. This measure was taken to allow the company to conduct a complete evaluation of every aspect of the breach. Following this evaluation, servers deemed safe were restored, while others were eliminated. Because the attackers specifically targeted Windows systems during their lateral movement, SmarterTools eliminated as many Windows servers as possible from its environment. As part of the remediation process, the company also removed Active Directory services from its environment and reset passwords across the network. All customers were advised to update their SmarterMail installations to the latest version as soon as possible to prevent similar compromises.

Sources

Sources available to members: 1 source.

CSIDB