Wire flash
TechUS, allies warn Russian hackers exploiting Zimbra zero-click flaw to steal government emails
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
U.S. and allied cyber-intelligence agencies warned that Russian state-backed hackers, known as Laundry Bear, have exploited a vulnerability in the Zimbra Collaboration Suite email software to steal messages, passwords, and authentication data from over 10 Western organizations since July 2025. The campaign uses a zero-click exploit that activates when a victim simply opens or previews a malicious email, requiring no link click or attachment download. Targets include defense, federal and local governments, law enforcement, technology firms, educational institutions, media, and NGOs. The hackers sought email addresses, passwords, two-factor authentication tokens, email directories, and up to 90 days of communications. Proofpoint described the technique as a 'half-click' exploit. CISA urged organizations to patch Zimbra software, monitor for suspicious activity, and follow remediation guidance. The advisory was backed by agencies from Australia, Canada, New Zealand, the UK, and over a dozen European countries.
Source report
U.S. and allied cyber-intelligence authorities warned Thursday that Russian state-backed hackers have exploited a vulnerability in widely used email software to steal messages, passwords, and authentication data from Western government agencies and other organizations.
Key Details of the Campaign
The campaign is notable because it does not require victims to click a malicious link or download an attachment. According to a joint advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the FBI, the exploit can activate when someone simply opens or previews an email in an unpatched version of the Zimbra Collaboration Suite — a popular alternative to major collaborative messaging platforms like Microsoft Exchange or Google Workspace.
The Russian hacking group, known primarily as Laundry Bear, has successfully targeted more than 10 organizations since July 2025. The campaign has affected:
- The defense industrial base
- Federal and local governments
- Law enforcement agencies
- Technology companies
- Educational institutions
- Media outlets
- Nongovernmental organizations
What the Hackers Sought
The hackers aimed to steal:
- Email addresses
- Passwords
- Two-factor authentication tokens — potentially allowing continued access to compromised accounts even after obtaining a victim's password
Their tools also attempted to collect an organization's email directory, up to 90 days of a victim's communications, and other sensitive information.
U.S. Government Exposure
The Treasury Department's Financial Crimes Enforcement Network (FinCEN) purchased a Zimbra standard support subscription in February 2025, according to federal contracting data from GovTribe, a federal market intelligence platform owned by Nextgov/FCW parent company GovExec. The purchase does not indicate whether FinCEN used the vulnerable version of the software or was targeted in the campaign.
Technical Analysis
"Unlike traditional phishing that attempts to persuade a user to take an action, such as clicking a link or downloading a file, Laundry Bear's current campaign uses a zero-click exploit that only requires a user to view a malicious email," CISA said in a statement.
Proofpoint, which also investigated the activity, describes the technique as a "half-click" exploit because the victim must still open or preview the email. The company said no additional interaction is required once the message appears in a vulnerable Zimbra webmail client.
The emails were sent from both attacker-controlled Proton Mail accounts and addresses that had already been compromised, according to Proofpoint.
Example Attack Vector
In one example released by Proofpoint, the sender claimed to represent a Belgian media-verification organization and proposed cooperation among European institutions combating disinformation. The message contained a legitimate-looking link to a European Union events calendar, but the malicious code was embedded directly in the email itself.
Recommended Actions
CISA urged organizations to:
- Update all Zimbra mail software
- Monitor email systems for suspicious activity
- Review the technical indicators included in the advisory
Organizations that find evidence of a compromise should follow the agencies' remediation guidance rather than relying solely on installing the available patch.
Official Statement
"CISA continues to see sophisticated and less sophisticated nation-state cyber groups deploy increasingly novel exploits into a highly successful capability to disrupt critical infrastructure or conduct espionage," said Chris Butera, CISA's acting executive assistant director for cybersecurity.
International Support
The advisory was also backed by defense, cybersecurity, and intelligence agencies from Australia, Canada, New Zealand, the United Kingdom, and more than a dozen European countries.
Source
Government Executive - All ContentWestern
Part of this Story
Russian hackers can steal government emails without victims clicking a link, cyber agencies warn