Russian Hackers Steal Government Emails via Zero-Click Zimbra Exploit, Cyber Agencies Warn
U.S. and allied cyber-intelligence authorities warned that Russian state-backed hackers, known as Laundry Bear, have exploited a vulnerability in the Zimbra Collaboration Suite to steal emails, passwords, and two-factor authentication tokens from over 10 Western organizations since July 2025. The campaign is notable for using a 'zero-click' or 'half-click' exploit that activates when a victim simply opens or previews a malicious email, without needing to click a link or download an attachment. Targets include defense contractors, federal and local governments, law enforcement, technology firms, educational institutions, media outlets, and NGOs. The hackers used attacker-controlled Proton Mail accounts and compromised addresses to send emails, embedding malicious code directly in the message body. CISA, NSA, FBI, and agencies from Australia, Canada, New Zealand, the UK, and over a dozen European countries jointly issued the advisory, urging organizations to patch Zimbra software and monitor for suspicious activity.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection