How the State Department discovered Chinese hackers reading its emails
politico.com
politico.com
Also: how long before email is simply too great a risk to use meaningfully any more?
Much email traffic is already encrypted through TLS, as data-in-flight.
A fair amount of email storage is encrypted as data-at-rest, but the problem is that email processing systems need access to that, so the encrypted storage itself is available as cleartext either at specific moments (spam and ad processing, for example), or within applications.
Sideband attacks such as phishing / spearphishing are used to obtain credentials, at which point GAME OVER: YOU LOSE.
Even with encryption, metadata related to email (sender, recipient(s), subject, date, references and other headers) are transmitted in the clear, at least at the server level, and often at the network level. Monitoring these is often more valuable than acquiring the full message contents themselves. "We kill people based on metadata", former NSA director General Michael Hayden <https://www.nybooks.com/online/2014/05/10/we-kill-people-bas...>.
Tools for using and managing email, including forwarding (often to systems which don't employ similar, or any, encryption), searching (difficult on an encrypted corpus), printing (hardcopy hole, as well as potential attacks within local networks, WiFi, or the printer itself, which is in fact a general-purpose computer whose principle display mechanism is hardcopy, but which is networked and often has considerable storage), etc., etc.
A general case of the problem is that bulk data archival directly connected to high-speed and difficult-to-monitor networking capabilities[1] seems increasingly to me a catastrophic own goal. How to effectively mitigate this isn't entirely clear, but the practices of those who avoid email, don't carry smart or any otherwise mobile phones, airgap critical systems, and rely increasingly on paper-based information systems ... seems increasingly prescient and sensible. A side-branch of the US intelligence agencies (CIA grew from the State Department, diplomatic cover continues to be used by spies), military branches, attorneys general (at national and state levels), political parties, political campaigns to the chief executive level, courts, and One of the World's Richest Men have all been very high profile victims of data breaches and exploits. I see the news of this as less due to their technical naivete and far more a matter of general vulnerability* combined with the obligation for such entities to disclose, and the interest in news media in reporting, such attacks.
For reasons expressed above, bolting encryption onto extant email systems is unlikely to work. Instead, an alternative general, open standards, open source alternate messaging protocol and system must be devised in which both encryption and security-conscious practices and management of messaging are inherent. Even then I'll have my doubts.
________________________________
Notes:
1. The same encryption which protects your own data works to the attackers advantage in shielding theirs, and disrupting monitoring and detection.