July 24, 2026

Russian Zero-Click Email Campaign: What US Organizations Should Review

Russian Zero-Click Email Campaign: What US Organizations Should Review

US and allied cyber agencies have warned that Russian state-supported actors used a zero-click technique to compromise email systems belonging to government and commercial organizations.

The joint advisory attributes the campaign to an advanced persistent threat group known as LAUNDRY BEAR. According to the agencies, the group has targeted organizations using Zimbra Collaboration Suite since at least July 2025.

Unlike conventional phishing, the technique did not require the recipient to follow a link, open an attachment or enter login credentials. The malicious content could operate when an email was rendered through a vulnerable version of Zimbra webmail.

US organizations reportedly targeted by the campaign operated across defense, government, education, energy, law enforcement, media, nonprofit and technology sectors. The activity has been assessed as consistent with espionage and almost certainly conducted with Russian state support.

The warning demonstrates why email security cannot depend solely on teaching employees not to click suspicious links. Organizations must also address software vulnerabilities, monitor unusual access and prepare for incidents in which users have done nothing wrong.

What the joint advisory says

The advisory was issued by US and international cyber agencies, including the Cybersecurity and Infrastructure Security Agency, the FBI, the National Security Agency and the United Kingdom’s National Cyber Security Centre.

The agencies say LAUNDRY BEAR used a technique known as “beehive” to target vulnerable Zimbra installations.

The campaign exploited CVE-2025-66376, a vulnerability that was reportedly being used before a security update became available. Zimbra issued a patch in November 2025, but agencies warned that vulnerable systems continued to be exploited afterward.

The activity allowed the threat actors to obtain extensive and sustained access to email information without requiring conventional user interaction.

Organizations using affected systems have been urged to:

  • Install available security updates.
  • Assess whether compromise may already have occurred.
  • Improve network and email monitoring.
  • Review relevant indicators of compromise.
  • Investigate suspicious access to accounts and servers.
  • Strengthen their ability to detect continuing activity.

Applying a patch closes a known vulnerability, but it does not automatically remove access established before the update was installed.

What “zero-click” means in this case

Most employees understand phishing as a message that asks them to click a link, download a file or disclose a password.

A zero-click attack operates differently.

In this campaign, the malicious content was designed to exploit the email platform when the message was rendered in a vulnerable webmail environment. The user did not need to knowingly interact with the message beyond viewing it.

This distinction matters because traditional employee-awareness advice would not, by itself, have prevented the compromise.

The attack did not necessarily depend on:

  • Convincing the recipient to trust the sender.
  • Persuading the user to open an attachment.
  • Directing the user to a false login page.
  • Obtaining the password through social engineering.
  • Waiting for the recipient to approve a download.

The risk arose from a technical weakness in the software responsible for displaying the message.

Organizations still need phishing training, but training must sit alongside secure configuration, vulnerability management and active threat detection.

Why email systems are valuable espionage targets

Corporate and government email accounts contain far more than routine correspondence.

Depending on the organization, email may expose:

  • Executive and board discussions.
  • Government and regulatory communications.
  • Customer and supplier information.
  • Research and development plans.
  • Legal advice and litigation strategy.
  • Commercial negotiations.
  • Employee and applicant information.
  • Travel and security arrangements.
  • Credentials and password-reset messages.
  • Attachments containing sensitive business records.

Access to an email account can also help an attacker understand how an organization operates.

The threat actor may learn who approves payments, which suppliers are trusted, when senior executives are traveling and how employees communicate with external advisers.

That intelligence can support further espionage, impersonation or social-engineering activity even where the original technical access is later removed.

The NCSC warned that the actors gained persistent access to compromised email environments and that similar techniques could potentially be adapted to target other email platforms.

Installing the patch may not be enough

Organizations using vulnerable Zimbra versions should install the relevant updates without delay.

However, a system that was exposed before patching may already have been compromised.

A complete response should consider whether the organization needs to:

  1. Determine when the vulnerable software was in use.
  2. Review server, authentication and access logs.
  3. Identify unusual forwarding rules or mailbox changes.
  4. Examine unexpected administrative activity.
  5. Check for unauthorized sessions and authentication tokens.
  6. Review connections from unfamiliar locations or infrastructure.
  7. Assess whether sensitive emails or attachments were accessed.
  8. Reset relevant credentials and invalidate active sessions.
  9. Preserve evidence before logs or systems are altered.
  10. Monitor for renewed access or related targeting.

Changing an employee’s password may be necessary, but it should not be treated as a complete solution where access was obtained through the underlying email infrastructure.

Which organizations should pay particular attention

The campaign specifically affected organizations using Zimbra Collaboration Suite, but the wider lesson is relevant to any organization that depends on email for sensitive work.

Particular attention may be justified where an organization:

  • Operates in defense, energy, technology or government contracting.
  • Conducts commercially sensitive research.
  • Handles protected legal, financial or personal information.
  • Works with public authorities or critical infrastructure.
  • Maintains valuable intellectual property.
  • Supports political, media or nonprofit activity.
  • Uses self-hosted or externally managed email infrastructure.
  • Has not recently assessed its email-security configuration.

The advisory also warns that the technique may be adapted to exploit other vulnerabilities as organizations update their Zimbra systems.

Businesses should therefore avoid treating this as a problem relevant only to one software product.

What organizations should review now

Senior management and technical teams should establish whether email security is being managed as a continuing business risk rather than a one-time configuration exercise.

Questions to consider include:

  1. Which email platforms and versions are currently in use?
  2. Who is responsible for monitoring relevant security advisories?
  3. How quickly are critical updates assessed and installed?
  4. Can the organization identify suspicious mailbox or administrator activity?
  5. How long are email and authentication logs retained?
  6. Are privileged accounts protected by strong authentication controls?
  7. Can active sessions and tokens be invalidated rapidly?
  8. Has the organization tested its response to a compromised email server?
  9. Who decides whether clients, regulators or law enforcement must be notified?
  10. Can relevant evidence be preserved before remediation begins?

Unclear answers may indicate weaknesses that should be addressed before an incident occurs.

Evidence to preserve after suspected compromise

When suspicious activity is identified, organizations may need to move quickly to contain access.

Containment should be coordinated with evidence preservation.

Relevant material may include:

  • Email-server and application logs.
  • Authentication and session records.
  • Administrative-account activity.
  • Mailbox forwarding and delegation rules.
  • Firewall, proxy and network logs.
  • Endpoint alerts and security-tool records.
  • Copies of suspicious emails.
  • Dates of software updates.
  • Lists of affected accounts.
  • Internal incident communications.
  • A detailed chronology of detection and response.

Where possible, preserve original records and document every action taken during containment.

Removing malicious access without retaining the available evidence may make it more difficult to establish how the compromise occurred, what information was exposed and whether the threat actor retained another route into the environment.

Cyber security requires preparation before an incident

The campaign illustrates why cyber security must combine prevention, monitoring and response.

A proportionate program may include:

  • Vulnerability assessments.
  • Penetration testing.
  • Email and identity-security reviews.
  • Patch-management procedures.
  • Privileged-access controls.
  • Continuous threat monitoring.
  • Incident-response planning.
  • Employee awareness training.
  • Post-incident review and remediation.

Conflict International USA’s Cyber Security Services support organizations through vulnerability assessments, penetration testing, cyber-threat monitoring, employee training and incident-response planning.

No technical control can guarantee that every attack will be prevented. The objective is to reduce avoidable exposure, identify suspicious activity earlier and ensure that the organization can respond through an established process.

How Conflict International USA can assist

Conflict International USA supports businesses, professional firms and other organizations reviewing their exposure to cyber threats and sensitive information loss.

Depending on the organization’s requirements, support may include:

  • Cyber-risk and vulnerability assessments.
  • Penetration testing.
  • Email and access-control reviews.
  • Threat monitoring and intelligence.
  • Incident-response planning.
  • Evidence-preservation guidance.
  • Employee cyber-awareness training.
  • Coordination with legal and technical advisers.

The correct response to suspected compromise depends on the systems affected, the available evidence and the sensitivity of the information involved.

If your organization uses Zimbra or is concerned about unauthorized access to sensitive email, contact Conflict International USA in confidence to discuss its cyber-security exposure and appropriate next steps.

Get a quote today!

Can we help you? Contact us in confidence. We are always happy to help and give you an indication of how we may be able to assist.

Please provide a brief background to your case and the reasons for initiating an investigation.

What is your required outcome? (e.g. Asset Identification, Litigation Support, Due Diligence, or Risk Mitigation).

Please define your relationship to the person or entity of interest (e.g. Legal Counsel, Business Partner, Family Member, or Victim of Fraud).

Please list any specific details you currently possess, such as names, addresses, or any other known details which may assist.

Need our help?
Get a free consultation today.

Get started
© 2026 Conflict International · Privacy Policy · Cookie Policy · Website by ghostwhite