Wire flash
TechUS, Allies Warn Russian Hackers Steal Government Emails via Zero-Click Zimbra Flaw
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
U.S. and allied cyber-intelligence authorities warned that Russian state-backed hackers, known as Laundry Bear, have exploited a vulnerability in the Zimbra Collaboration Suite to steal emails, passwords, and authentication data from over 10 Western organizations since July 2025. The zero-click exploit activates when a victim simply opens or previews a malicious email in an unpatched version of the software, requiring no link click or attachment download. Targets include the defense industrial base, federal and local governments, law enforcement, technology companies, educational institutions, media outlets, and NGOs. The hackers sought email addresses, passwords, two-factor authentication tokens, email directories, and up to 90 days of communications. Proofpoint described the technique as a 'half-click' exploit. CISA, NSA, and FBI issued a joint advisory urging organizations to patch Zimbra software and monitor for suspicious activity. The advisory was also backed by agencies from Australia, Canada, New Zealand, the UK, and more than a dozen European countries.
Source report
U.S. and allied cyber-intelligence authorities announced Thursday that Russian state-backed hackers have exploited a vulnerability in widely used email software to steal messages, passwords, and authentication data from Western government agencies and other organizations.
Key Details of the Exploit
The campaign is notable because it does not require victims to click a malicious link or download an attachment. According to a joint advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the FBI, the exploit can activate when someone simply opens or previews an email in an unpatched version of the Zimbra Collaboration Suite — a popular alternative to major collaborative messaging platforms like Microsoft Exchange or Google Workspace.
The Threat Actor and Targets
The Russian hacking group, known primarily as Laundry Bear, has successfully targeted more than 10 organizations since July 2025. The campaign has affected:
- The defense industrial base
- Federal and local governments
- Law enforcement agencies
- Technology companies
- Educational institutions
- Media outlets
- Nongovernmental organizations
Stolen Data and Techniques
The hackers sought to steal:
- Email addresses
- Passwords
- Two-factor authentication tokens (allowing continued access to compromised accounts even after obtaining a victim's password)
Their tools also attempted to collect an organization's email directory, up to 90 days of a victim's communications, and other sensitive information.
U.S. Government Exposure
The Treasury Department's Financial Crimes Enforcement Network (FinCEN) purchased a Zimbra standard support subscription in February 2025, according to federal contracting data listed in GovTribe, a federal market intelligence platform owned by Nextgov/FCW parent company GovExec. The purchase does not indicate whether FinCEN used the vulnerable version of the software or was targeted in the campaign.
Technical Analysis
"Unlike traditional phishing that attempts to persuade a user to take an action, such as clicking a link or downloading a file, Laundry Bear's current campaign uses a zero-click exploit that only requires a user to view a malicious email," CISA said in a statement.
Proofpoint, which also investigated the activity, describes the technique as a "half-click" exploit because the victim must still open or preview the email. The company said no additional interaction is required once the message appears in a vulnerable Zimbra webmail client.
The emails were sent from both attacker-controlled Proton Mail accounts and addresses that had already been compromised, according to Proofpoint.
Example of the Attack
In one example released by Proofpoint, the sender claimed to represent a Belgian media-verification organization and proposed cooperation among European institutions combating disinformation. The message contained a legitimate-looking link to a European Union events calendar, but the malicious code was embedded directly in the email itself.
Recommended Actions
CISA urged organizations to:
- Update all Zimbra mail software
- Monitor their email systems for suspicious activity
- Review the technical indicators included in the advisory
Organizations that find evidence of a compromise should follow the agencies' remediation guidance rather than relying solely on installing the available patch.
Official Statement
"CISA continues to see sophisticated and less sophisticated nation-state cyber groups deploy increasingly novel exploits into a highly successful capability to disrupt critical infrastructure or conduct espionage," said Chris Butera, CISA's acting executive assistant director for cybersecurity.
International Support
The advisory was also backed by defense, cybersecurity, and intelligence agencies from Australia, Canada, New Zealand, the United Kingdom, and more than a dozen European countries.
Source
Government Executive - All ContentWestern
Part of this Story
Russian Hackers Steal Government Emails Without Victims Clicking a Link, Cyber Agencies Warn