Russian Hackers Steal Government Emails Without Victims Clicking a Link, Cyber Agencies Warn
U.S. and allied cyber-intelligence authorities warned that Russian state-backed hackers, known as Laundry Bear, have exploited a vulnerability in the Zimbra Collaboration Suite to steal emails, passwords, and authentication data from over 10 Western organizations since July 2025. The zero-click exploit activates when a victim simply opens or previews a malicious email in an unpatched version of the software, requiring no link click or attachment download. Targets include the defense industrial base, federal and local governments, law enforcement, technology companies, educational institutions, media outlets, and NGOs. The hackers sought email addresses, passwords, two-factor authentication tokens, email directories, and up to 90 days of communications. Proofpoint described the technique as a 'half-click' exploit. CISA, NSA, and FBI issued a joint advisory urging organizations to patch Zimbra software and monitor for suspicious activity. The advisory was also backed by agencies from Australia, Canada, New Zealand, the UK, and more than a dozen European countries.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection