← All issues

This Week In Email — September 30, 2026

Not a blockbuster week, but a busy one on two fronts: a major AI-enabled phishing takedown and a critical WordPress/Mailgun bug on the security side, plus a stack of regulatory movement on tracking pixels and "urgency" subject lines. Let's get into it.

In This Issue

Top Stories

Microsoft Dismantles EvilTokens: The First Takedown of an End-to-End AI-Run Phishing-as-a-Service Platform

Here's the number that should get your attention: 12,000+ compromised inboxes across 10,000+ organizations, reported losses of roughly $1.7M in FBI complaints so far — almost certainly an undercount. Microsoft's Digital Crimes Unit seized 50 websites and disabled 150+ domains under a September 22 court order out of the Eastern District of Virginia. It's DCU's 40th court-authorized disruption, and the first against a cybercrime service that was AI-enabled end to end.

The mechanism is what makes this one different. EvilTokens combined device-code phishing — stealing OAuth tokens that survive a password reset — with an AI layer that read the victim's compromised mailbox, mapped payment approvers and invoice workflows, and suggested which trusted contact to impersonate. That's the "figure out who to spoof and how" step, the part that used to require a human criminal with patience, now automated. The Metropolitan Police arrested two suspects on September 11; the takedown pulled in Health-ISAC, Cloudflare, Coinbase, OpenAI, SpyCloud, TRM Labs and Shadowserver.

If your org runs Microsoft 365, the operational lesson isn't "we have MFA, we're fine." Device-code phishing steals a live session token, and that token doesn't get invalidated when the victim changes their password. Train people to recognize device-code prompts specifically, not just generic phishing red flags — this attack class doesn't care how strong your MFA policy is on paper.

Sources: Microsoft Security Blog, The Hacker News, emailexpert

Critical Mailgun WordPress Plugin Flaw Let Attackers Hijack Sites' API Keys — No Login Required

CVE-2026-78003. CVSS 9.8. 80,000+ active installs. If you run WordPress with the Mailgun plugin, that string of facts should already have your attention.

An unvalidated array-key/path-traversal bug in the plugin's add_list() function let unauthenticated attackers make authenticated requests to arbitrary Mailgun API endpoints using the site's own stored API key. No login. No credentials needed at all. The most damaging use of the bug: silently creating inbound mail routes to intercept password-reset emails and take over WordPress admin accounts from the outside. It's fixed in 2.2.1/2.2.3 depending on source. Worth noting: a related, less-severe flaw (CVE-2026-14834) was patched back in July with vague changelog language that masked how serious the underlying issue really was — the kind of quiet patch note that should make you nervous about what else is downplayed in a changelog.

Update immediately. Audit for inbound routes you didn't create. Rotate your Mailgun API key regardless of whether you think you were hit — an unauthenticated, trivially automatable bug with this reach means "probably fine" isn't a security posture.

Sources: emailexpert, OpenCVE, LinuxPanda

Regulatory & Compliance

UK's DMA Wants Email Tracking Pixels Exempted From Cookie-Consent Rules

The Data & Marketing Association submitted a paper to the UK government this week asking for consent exemptions covering measurement, service delivery, security, fraud detection and advertising within existing customer relationships. Nothing has changed yet — this is a proposal, not a rule — but it's a live one, and it's worth watching closely.

The ICO's April 2026 guidance currently treats email tracking pixels exactly like website cookies under PECR regulation 6, meaning consent is required. The DMA's argument — "almost nobody reads a cookie banner" — isn't wrong as a description of user behavior, but any exemption ministers grant will apply to email open-tracking whether or not email gets named specifically in the final text. There's no timeline yet.

If you send into the UK and rely on open-tracking pixels, this is a "watch this space" story, not a "do something today" story. But it's exactly the kind of quiet policy shift that becomes a surprise if you're not paying attention when it moves.

Source: emailexpert

Washington Judge Sends PacSun, Tommy Bahama and Bebe "Urgency" Email Suits Back to State Court

All three retailers got sued for promotional subject lines that created a "false sense of urgency" about how long a promotion or product would be available, under Washington's Commercial Electronic Mail Act (CEMA). All three tried to move the cases to federal court, arguing the email "intrusion, distraction, and cost" caused real injury sufficient for federal standing. Judge Rothstein wasn't having it — she called the alleged harm merely "technical or procedural" under federal Article III standards and remanded all three to state court, effective October 5, 2026.

This isn't a one-off. The same district previously remanded similar cases against Papa John's and True Religion. The pattern is now clear: retailers keep trying federal court, judges keep sending them back to Washington state court, where CEMA is far more plaintiff-friendly.

If you send urgency-framed subject lines to Washington recipients — "ends tonight," "last chance," "selling out" — this is live legal exposure, not a hypothetical. State court is where these claims are increasingly landing, and that's the venue you should assume you'll be defending in.

Source: emailexpert

Links worth your time

Events & Community


That's the week. If something is wrong, reply and tell me — I read every response.

— John

This Week In Email — thisweekin.email

Enjoyed this issue?

Subscribe to This Week in Email and get future issues delivered to your inbox.