Jessica Entwistle
July 24 2026
The NCSC, alongside the NSA, CISA and international partners, has published a joint advisory warning that a Russian state-supported threat group tracked as LAUNDRY BEAR has been exploiting a zero-day vulnerability in Zimbra Collaboration Suite to conduct targeted phishing attacks against Western organisations. The advisory explains that the group exploited the vulnerability for five months before it was patched in November 2025, and that vulnerable environments are still being actively targeted. The attack requires only that a recipient opens or previews a malicious email, making it a so-called zero-click or half-click attack. Once triggered, the payload harvests the last 90 days of email, the organisation's entire email directory, browser-saved passwords and two-factor authentication recovery codes.
For UK organisations using Zimbra Collaboration Suite, this represents a direct operational risk. The advisory makes clear that LAUNDRY BEAR has been targeting government, defence, critical infrastructure and other Western entities, and the technique bypasses many of the user awareness controls organisations rely on to reduce phishing risk. The fact that the vulnerability was exploited for months before detection, and that exploitation is continuing in unpatched environments, underscores the importance of timely patching and monitoring for unusual email or authentication activity. Organisations using Zimbra should treat this as a priority review, particularly where email systems are used to handle sensitive or operationally critical communications. The zero-click nature of the attack means that traditional user training and awareness programmes offer limited protection, and that technical controls, patching discipline and monitoring become the primary defensive measures.
Organisations using Zimbra Collaboration Suite should confirm that systems are fully patched and that monitoring is in place to detect unusual mailbox access, credential use or directory enumeration activity. It is also worth reviewing whether two-factor authentication recovery codes are stored securely, whether email access logging is sufficient to identify retrospective compromise, and whether incident response plans include procedures for investigating suspected email system compromise. Organisations should consider whether they have visibility into who has accessed mailboxes, what data has been exported, and whether authentication activity is being monitored for anomalies. Where Zimbra is used in high-risk or high-value environments, organisations may wish to review whether additional monitoring, segmentation or access controls are needed to reduce exposure.
Source: NCSC UK