Summary
- The NCSC and international partners have warned about Russian state supported activity targeting Zimbra Collaboration Suite.
- The campaign uses a zero click exploit that can be triggered when a malicious email is viewed in vulnerable Zimbra webmail.
- The advisory places email infrastructure, patching, monitoring, and supplier assurance inside organisational resilience planning.
The National Cyber Security Centre and international partners have warned that Russian state supported actors have used a zero click exploit against Zimbra Collaboration Suite to steal email data from Western organisations.
The campaign has been attributed to the group the NCSC tracks as Laundry Bear, also known as Void Blizzard. The advisory says the activity has targeted organisations in defence, government, education, energy, law enforcement, media, non-governmental organisations, and technology, with malicious activity observed since at least July 2025.
The exploit can be triggered when a user views a maliciously crafted email in a vulnerable version of Zimbra webmail. That changes the defensive equation, because compromise does not depend on a user opening an attachment, clicking a link, or typing credentials into a fake login page. Awareness training remains useful, but it cannot compensate for an exposed system that can be compromised through viewing alone.
Email remains one of the richest targets in any organisation. Mailboxes hold internal correspondence, supplier exchanges, contract discussions, legal communications, credentials, recovery paths, calendar data, and personal information. Once attackers gain access, the breach can become a route into espionage, impersonation, lateral movement, business email compromise, or further targeting of connected organisations.
The Zimbra focus is also a reminder that cyber risk often sits in systems that receive less executive attention than newer security tooling. Collaboration platforms and mail systems still depend on asset visibility, patching, configuration management, logging, supplier assurance, and incident response planning. Where a vulnerable service is internet facing, the window between exploitation and remediation can be short.
The NCSC has urged affected organisations to patch, monitor, and review the joint advisory for indicators and mitigations. It also warned that the actors involved are likely to adapt, including by moving to other vulnerabilities and other mail systems. That makes the campaign less a single product problem than an exposure management problem across communications infrastructure.
Organisations in the affected sectors have an additional challenge because mail systems connect operational and institutional networks. A compromised education provider can hold research, visa, donor, and partner data. A media organisation can expose sources and correspondence. A technology supplier can become the path into customers. Defence, energy, and government targets bring obvious intelligence value, but the wider ecosystem around them may be easier to reach.
The warning also weakens the habit of treating phishing mainly as a user behaviour issue. Training people not to click suspicious links is only one layer. Zero click exploitation shifts more weight to patching speed, vulnerability intelligence, network monitoring, segmentation, and the boring but essential work of knowing which systems are exposed.
State linked attackers and criminal groups often exploit the same operational gaps: delayed updates, weak visibility, under-resourced IT teams, complex supplier chains, and unmanaged legacy systems. The difference is the purpose and patience of the attacker. The NCSC’s Zimbra warning places email infrastructure back where it belongs: not as a commodity office tool, but as a critical system that can determine the shape and cost of a breach.




