Russian state-backed hackers have exploited a vulnerability in widely used email software to steal messages, passwords and authentication data from Western government agencies and other organizations, U.S. and allied cyber-intelligence authorities said Thursday.
The campaign is notable because it does not require victims to click a malicious link or download an attachment. The exploit can instead activate when someone simply opens or previews an email in an unpatched version of the Zimbra Collaboration Suite — a popular alternative to major collaborative messaging platforms like Microsoft Exchange or Google Workspace — according to a joint advisory issued by the Cybersecurity and Infrastructure Security Agency, National Security Agency and FBI.
The Russian hacking group, known primarily as Laundry Bear, has successfully targeted more than 10 organizations since July 2025, the agencies said. The campaign has hit the defense industrial base, federal and local governments, law enforcement, technology companies, educational institutions, media outlets and nongovernmental organizations.
The hackers sought to steal email addresses, passwords and two-factor authentication tokens, which could allow them to retain access to compromised accounts even after obtaining a victim’s password. Their tools also attempted to collect an organization’s email directory, as much as 90 days of a victim’s communications and other sensitive information.
The Treasury Department’s Financial Crimes Enforcement Network purchased a Zimbra standard support subscription in February 2025, according to federal contracting data listed in GovTribe, a federal market intelligence platform owned by Nextgov/FCW parent company GovExec. The purchase does not indicate whether FinCEN used the vulnerable version of the software or was targeted in the campaign.
“Unlike traditional phishing that attempts to persuade a user to take an action, such as clicking a link or downloading a file, Laundry Bear’s current campaign uses a zero-click exploit that only requires a user to view a malicious email,” CISA said in a statement.
Proofpoint, which also investigated the activity, describes the technique as a “half-click” exploit because the victim must still open or preview the email. The company said no additional interaction is required once the message appears in a vulnerable Zimbra webmail client.
The emails were sent from both attacker-controlled Proton Mail accounts and addresses that had already been compromised, according to Proofpoint.
In one example released by the company, the sender claimed to represent a Belgian media-verification organization and proposed cooperation among European institutions combating disinformation. The message contained a legitimate-looking link to a European Union events calendar, but the malicious code was embedded directly in the email itself.
CISA urged organizations to update all Zimbra mail software, monitor their email systems for suspicious activity and review the technical indicators included in the advisory. Organizations that find evidence of a compromise should follow the agencies’ remediation guidance rather than relying solely on installing the available patch.
“CISA continues to see sophisticated and less sophisticated nation-state cyber groups deploy increasingly novel exploits into a highly successful capability to disrupt critical infrastructure or conduct espionage,” said Chris Butera, CISA’s acting executive assistant director for cybersecurity.
The advisory was also backed by defense, cybersecurity and intelligence agencies from Australia, Canada, New Zealand, the United Kingdom and more than a dozen European countries.


