US and allied cyber agencies have issued a joint warning that Russian state-backed hackers are actively targeting organisations using Zimbra Collaboration Suite webmail, silently stealing emails without the user needing to click anything.
- What it is: A group tracked as LAUNDRY BEAR is exploiting a flaw in Zimbra webmail (CVE-2025-66376) using a zero-click technique - simply viewing a malicious email can trigger the attack.
- Who is affected: Organisations running Zimbra Collaboration Suite for email. This does not affect Microsoft 365 or Google Workspace mailboxes.
- The risk: Successful attacks have let the group quietly harvest up to 90 days of email history, aimed at gathering sensitive government and commercial information.
- What to do: A patch for this flaw has been available since November 2025. Businesses running Zimbra should confirm the update is installed and watch for unusual mailbox activity.
If your business uses Zimbra for email, we recommend confirming with your IT provider that the patch is applied and there is no evidence of unusual account activity.