Russian hackers can steal government emails without victims clicking a link, cyber agencies warn
U.S. and allied cyber-intelligence agencies warned that Russian state-backed hackers, known as Laundry Bear, have exploited a vulnerability in the Zimbra Collaboration Suite email software to steal messages, passwords, and authentication data from over 10 Western organizations since July 2025. The campaign uses a zero-click exploit that activates when a victim simply opens or previews a malicious email, requiring no link click or attachment download. Targets include defense, federal and local governments, law enforcement, technology firms, educational institutions, media, and NGOs. The hackers sought email addresses, passwords, two-factor authentication tokens, email directories, and up to 90 days of communications. Proofpoint described the technique as a 'half-click' exploit. CISA urged organizations to patch Zimbra software, monitor for suspicious activity, and follow remediation guidance. The advisory was backed by agencies from Australia, Canada, New Zealand, the UK, and over a dozen European countries.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection