http://j5kv55yiu3rneydqn4f35kyhejbq3fhkkm7glg5nbtvxgaxthou7g2ad.onion/case-study.html
Since your email client will try to load the image from the
attacker-controlled server, the attacker can capture this incoming
request, where the filename contains the full content of the
original encrypted email in plaintext.”