UK NCSC and Partners Publish International Alert on Russian State-Supported Zero-Click Zimbra Zero-Day Campaign

A year-long Russian state-supported zero-click Zimbra campaign, exposed this week by NCSC UK and partners across some 16 nations — a defender review for any organization still running unpatched Zimbra.

Share
Flat white line-art of a large envelope linked to a shield and a webmail window, on a cobalt-blue background — the NCSC-led Russian Zimbra zero-click alert.

Key Takeaways

  • On July 23, 2026 the UK's National Cyber Security Centre (NCSC UK) and partners across roughly 16 nations published a joint international alert exposing a Russian state-supported "zero-click" phishing campaign that targeted Western organizations through unpatched Zimbra webmail servers, attributing the activity to a cluster the advisory calls LAUNDRY BEAR (also tracked as Void Blizzard).
  • The campaign reportedly ran for about a year before disclosure and used a Zimbra Collaboration Suite flaw, CVE-2025-66376, to read mailbox contents and harvest 2FA codes; reported targets span US sectors including defense, government, education, energy, law enforcement, media, non-governmental organizations and technology, alongside Ukraine and other NATO-aligned organizations.
  • For defenders the takeaway is operational rather than exotic: Zimbra patched the flaw on November 6, 2025 and CISA added it to its Known Exploited Vulnerabilities catalog in March 2026, so the defender-relevant actions are to verify Zimbra is on a fixed version, review the published indicators of compromise, and treat internet-facing webmail as a priority attack surface — not to reconstruct the technique.

A year-long Russian state-supported zero-click Zimbra campaign, named and attributed by NCSC UK and partners across some 16 nations — the defender story is patch-and-verify, not the exploit itself.

LONDON — The UK's National Cyber Security Centre (NCSC UK) and partners across roughly 16 nations on July 23, 2026 published a joint international alert exposing a Russian state-supported "zero-click" phishing campaign that reportedly ran for about a year against Western organizations running unpatched Zimbra webmail servers. The advisory attributes the activity to a Russian state-supported cluster it calls LAUNDRY BEAR — also tracked in industry reporting as Void Blizzard — and says the actors reportedly harvested mailbox contents and two-factor-authentication (2FA) codes.

The alert was coordinated among government cyber agencies, with US signatories including CISA, the NSA and the FBI joining the NCSC and more than a dozen other national partners. As reported by Dark Reading and The Register, the campaign leaned on a flaw in Zimbra Collaboration Suite rather than on a link or attachment a user had to click. This piece summarizes what the joint alert documents and what it asks defenders to do — patch, verify, and review indicators — without reconstructing how the technique works.

At a Glance
FieldDetails
WhatJoint international alert on a Russian state-supported "zero-click" Zimbra campaign
Who publishedNCSC UK and partners across ~16 nations; US signatories include CISA, NSA and FBI
Attributed actorLAUNDRY BEAR, per the advisory (also tracked as Void Blizzard)
VulnerabilityCVE-2025-66376 in Zimbra Collaboration Suite webmail
Reported durationAbout a year before disclosure
Reported data takenMailbox contents and 2FA codes, per reporting
Reported targetsUS defense, government, education, energy, media, NGOs, tech; Ukraine and NATO-aligned orgs
Patch statusZimbra fixed the flaw on November 6, 2025; added to CISA KEV in March 2026
Disclosure dateJuly 23, 2026

What the Joint Alert Documented

According to the NCSC UK advisory and coordinated partner statements, a Russian state-supported cluster the alert names LAUNDRY BEAR conducted a phishing campaign against organizations running Zimbra Collaboration Suite, the open-source webmail and collaboration platform. The through-line the agencies emphasize is that the operation reportedly required no click on a malicious link or attachment — the reason multiple governments and outlets have described it as "zero-click." The campaign reportedly ran for roughly a year before this week's disclosure.

The alert ties the activity to CVE-2025-66376, a vulnerability in Zimbra's webmail interface. In defender terms, the salient facts are that the flaw is in an internet-facing mail product, that Zimbra shipped a fix on November 6, 2025, and that CISA later added the vulnerability to its Known Exploited Vulnerabilities catalog in March 2026. Reporting from The Hacker News indicates the actors used the access to read mailbox contents and to harvest 2FA codes; the advisory describes a custom aggregation-and-exfiltration capability the actors used against affected servers. The CyberSignal is deliberately not reproducing the mechanics — the defender-relevant facts are the affected product, the fixed version, and the published indicators.

Reported targets, per partner statements, span US organizations across defense, government, education, energy, media, NGOs and technology, alongside Ukraine and other NATO-aligned bodies. The consistent characterization across signatories is espionage: covert collection of email data rather than disruption or extortion.

The "Zero-Click" and Year-Long Framing in Defender Terms

Two phrases from the alert will travel fastest — "zero-click" and "year-long" — and both are worth translating for a defender team rather than taking at face value. "Zero-click" means the campaign did not depend on the usual human step of clicking a link or opening an attachment; the exposure sat in how a vulnerable Zimbra webmail instance handled certain messages. Some researchers have noted the interaction is closer to "half-click" in that a message still had to be rendered, but the defender-relevant point is the same: user-awareness training is not the primary control here. Patching and hardening the mail server is.

"Year-long" is the detail that should reframe incident scoping. If exploitation reportedly predates the fix and stretched across many months, then for an organization that ran an unpatched Zimbra instance during that window, the relevant question is not only "are we patched now" but "what happened while we were exposed." That shifts effort toward retrospective review — mailbox access, 2FA-code exposure, and the published indicators — rather than treating the patch as the end of the matter. Neither framing requires understanding the exploit; both point at the same workflow: confirm the fixed version is deployed, assume webmail was reachable during the exposure window, and look backward using the agencies' indicators.

Where This Fits in the Russian Espionage Pattern

The alert lands in a run of coordinated Western attribution of Russian state-supported cyber activity that The CyberSignal has tracked closely. The naming of Void Blizzard is itself a thread: US prosecutors have already moved against an individual charged in connection with Void Blizzard activity, so this week's alert extends a cluster already on Western radar rather than introducing a new one. It also fits the NCSC's own framing of the threat environment, set out when the agency warned that hostile states threaten a large share of UK critical infrastructure.

The espionage character rhymes with other Russian state-supported operations the site has covered — from a Russian nation-state botnet built around Signal Desktop to a WinRAR flaw exploited by Russia-aligned groups against Ukraine. What is distinctive here is the breadth of the coalition: a joint alert spanning roughly 16 nations, with US, UK, Dutch, Australian and Canadian agencies among the signatories, aimed less at surprising the actor than at pushing exposed organizations to close a specific, already-patched hole.

Defender Posture for Organizations Running Zimbra

For any organization operating Zimbra, the alert converts into a short, concrete checklist. First, confirm the deployment is on a version that includes the November 6, 2025 fix for CVE-2025-66376; the flaw's presence in CISA's KEV catalog makes patching a baseline expectation for US federal agencies and a strong signal for everyone else. Second, treat internet-facing webmail as a priority attack surface: minimize its exposure, restrict administrative interfaces, and verify that logging is enabled and retained long enough to support a look-back across the reported exposure window.

Third, assume the possibility of prior access rather than only preventing future access. Because the campaign reportedly ran for about a year and reportedly reached mailbox contents and 2FA codes, organizations that ran unpatched Zimbra should consider credential and 2FA-secret rotation for potentially affected accounts, and review whether any harvested session material could still be valid. None of this requires knowing how the flaw was triggered; all of it follows from the alert's own facts.

Detection-Engineering Review per Published Indicators

The joint alert and its partner publications include indicators of compromise and detection guidance, and the defender move is to route those into monitoring rather than to characterize the actor's tooling. Reporting from Help Net Security and CyberScoop notes the actors relied on custom aggregation-and-exfiltration capability, which is the kind of detail worth translating into host- and network-level detections against the published artifacts.

Practically, that means loading the advisory's indicators into SIEM and EDR content, hunting historically across the reported exposure window rather than only forward from the patch date, and prioritizing telemetry around Zimbra hosts and the identity systems that issue and validate 2FA. The goal is not to model the campaign but to answer a narrow question with the agencies' own artifacts: did anything matching these indicators touch our environment while it was exposed?

Open Questions

Several specifics remain unresolved at publication, and The CyberSignal is not filling them in. Public totals of confirmed victims are not established in the material reviewed, and the full membership and exact count of the coalition behind the alert are reported with some variation across outlets. The precise attribution of LAUNDRY BEAR to a specific Russian intelligence service, as opposed to a named actor cluster, is likewise something the agencies frame carefully; this piece follows the advisory's own naming and does not assert a sponsoring service.

Other questions are about impact rather than mechanics: how many exposed organizations were actually accessed, and how completely the published indicators capture the activity. These will sharpen as agencies, Zimbra and independent researchers publish more. The reporting frames this as a defender-oriented disclosure of an already-patched flaw under active exploitation — which is why the guidance above centers on patching, verification and indicator-driven review.


The CyberSignal Analysis

The reported facts above come from the joint alert and its reporting; what follows is The CyberSignal's editorial reading. None of the judgments below are new reported facts.

Signal 01 — The Story Is Patch Latency, Not the Zero-Click Label

The "zero-click" framing is what will carry the headline, but our reading is that the load-bearing detail is time. The flaw was fixed on November 6, 2025 and added to CISA's KEV catalog in March 2026, yet the campaign reportedly ran for about a year and this coordinated alert only arrived in July. The exposure that mattered lived in the gap between a fix being available and organizations actually deploying it on an internet-facing mail server.

That reframes the defender lesson away from the exotic and toward the familiar: the organizations most at risk were not those who failed to understand a novel technique, but those whose webmail patch cadence lagged. Seen that way, this alert is less a new-capability warning than a reminder that unpatched, internet-facing collaboration software remains a first-choice target for state-supported espionage.

Signal 02 — Coalition Attribution Is Doing Deliberate Work

A joint alert spanning roughly 16 nations, naming a specific Russian state-supported cluster, is not primarily an intelligence surprise — the actor was already tracked as Void Blizzard, already the subject of US prosecution. Our assessment is that the coordination itself is the message: a broad Western coalition publicly aligning on attribution and on a single remediation ask raises the diplomatic and operational cost of the activity while giving exposed organizations unambiguous cover to prioritize the fix.

For defenders, the practical value of that coalition is consolidation: instead of parsing several vendor accounts, an organization gets one government-backed set of indicators and one clear directive. The useful posture is to treat the joint attribution as a prioritization signal and act on the shared indicators quickly.

Signal 03 — Webmail Is Identity Infrastructure Now

The detail we find most durable is what the actors reportedly went after: not just email, but 2FA codes. Our view is that this reframes a mailbox from a store of messages into a piece of identity infrastructure — a place where authentication material accumulates and can be turned into wider access. That is why a mail-server flaw warrants credential and 2FA-secret rotation, not just a patch.

The organizations best positioned to absorb this are those that already treat their mail platform as a tier-zero identity asset — monitored, tightly patched, and wired into the same rotation and detection discipline as directory services. We would treat this alert as a prompt to ask a blunt internal question: if our webmail were reachable and unpatched for months, what authentication secrets would have been sitting inside it — and have we rotated them yet?


Sources

TypeSource
PrimaryNCSC UK — Russia zero-click Zimbra alert
AnalysisUnit 42 — Russian global webmail espionage
ReportingDark Reading — Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
ReportingThe Hacker News — Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
ReportingThe Register — Year-long Russian Zimbra zero-click campaign
ReportingThe Record — International alert on Russia's Zimbra campaign
ReportingCyberScoop — Russian espionage group using novel Zimbra exploit
ReportingHelp Net Security — Russian hackers exploit unpatched Zimbra servers
RelatedThe CyberSignal — Russian National Charged in Void Blizzard Case
RelatedThe CyberSignal — NCSC UK: Hostile States and 75% of Critical Infrastructure
RelatedThe CyberSignal — Kazuar / Secret Blizzard Russian Nation-State Botnet
RelatedThe CyberSignal — WinRAR Flaw Exploited by Russia-Aligned Groups Against Ukraine