Suspected Chinese Hackers Target University Webmail in Credential-Stealing Campaign
A hacking group tied to China is exploiting a critical flaw in Roundcube webmail to steal login credentials from physics and engineering faculties at US and Canadian universities.

Key points
- A suspected China-aligned hacking group is targeting Roundcube webmail servers at US and Canadian universities, according to research first reported by The Hacker News.
- Attackers focused on physics and engineering departments, which often handle commercially sensitive or defence-adjacent research.
- The break-ins exploit CVE-2024-42009, a critical flaw in Roundcube carrying a severity score of 9.3 out of 10.
- The campaign's goal is stealing staff and student email credentials.
- Roundcube's maintainers have patched the flaw; universities that haven't applied the update remain exposed.
A hacking group believed to be working on behalf of Chinese interests has been quietly breaking into university email systems in the United States and Canada.
The targets share a pattern: all run Roundcube, a free webmail program that lets users read email through a browser, and all belong to physics or engineering faculties. Those are the departments that tend to sit closest to aerospace, energy and defence research.
The campaign was flagged in reporting by The Hacker News.
How did the hackers get in?
They exploited a known bug that university IT teams hadn't yet patched. The flaw, tracked as CVE-2024-42009, carries a severity score of 9.3 out of 10, placing it firmly in the critical band.
The bug lets an attacker hide code inside an ordinary-looking email. When a victim opens the message in Roundcube, that code runs silently inside their browser session and lifts the victim's login details along with inbox contents. This class of attack is called cross-site scripting: the attacker tricks a trusted site into running malicious instructions on a visitor's machine. The victim does nothing wrong. They just open an email.
Who is behind it?
Investigators haven't publicly named the group, but the behaviour matches a cluster of activity long linked to Chinese state interests. That's a careful phrase: it means the tools and targeting fit a known pattern without a formal government attribution. We covered a separate China-linked intrusion campaign against Southeast Asian critical infrastructure on 3 July 2026, a sign that this activity cluster is ranging well beyond any single region.
The victim profile matters. Physics and engineering faculties hold draft research papers, grant correspondence and contacts inside government and industry. Stealing a professor's password is a cheap way into that world.
What happens to the stolen credentials?
With a working username and password, the attackers can log directly into a victim's mailbox, read messages and set up hidden forwarding rules. They can also send email from a real, trusted address, which makes follow-on phishing, meaning fake messages designed to deceive recipients, far more convincing than anything sent from an unknown account. A small break-in becomes a much larger one quickly.
That forwarding-rule tactic is worth flagging specifically. It's silent, it survives a password reset if the rule isn't removed first, and many users never check their mailbox rules at all.
What should staff and students do?
Ask your IT team whether Roundcube has been updated. The patch has been available for months.
Change your webmail password if you haven't done so recently, and turn on multi-factor authentication, a second verification step such as a code sent to your phone, wherever it's offered. Check your inbox rules for anything you didn't create, and look through your Sent folder for messages you don't remember writing.
The attackers are counting on the gap between a fix being released and a fix being installed. On many campuses, that gap is still open.



