Russian state-supported cyber actors conduct phishing campaign targeting users of Zimbra Collaboration Suite

This section contains time sensitive announcements about specific cyber threats, vulnerabilities and scams. Each alert has information you need to be aware of, and what actions to take to mitigate any risk to you or your organisation.

Subscribe to our updates to be notified as soon as we publish an alert.

12:30PM, 24 July 2026

TLP Rating: Clear

Russian state-supported cyber actors conduct phishing campaign targeting users of Zimbra Suite

A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organisations using the Zimbra Collaboration Suite software since at least July 2025.

This cyber security advisory urges any organisations using Zimbra Collaboration Suite to implement the recommendations listed within the ‘Mitigations’ section of this advisory, to reduce the risk associated with this activity. This advisory also includes specific remediations for organisations to implement if they discover the presence of the listed Indicators of compromise.

This advisory is being released by the following authoring and co-sealing agencies: 

  • United States National Security Agency (NSA)
  • United States Federal Bureau of Investigation (FBI)
  • Netherlands Defence Intelligence and Security Service (MIVD)
  • Netherlands General Intelligence and Security Service (AIVD)
  • United States Cybersecurity and Infrastructure Security Agency (CISA)
  • United States Defense Counterintelligence and Security Agency (DCSA)
  • United States Department of Defense Cyber Crime Center (DC3)
  • United States Department of the Treasury
  • United States Naval Criminal Investigative Service (NCIS)
  • Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)
  • Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)
  • New Zealand National Cyber Security Centre (NCSC-NZ)
  • United Kingdom National Cyber Security Centre (NCSC-UK)
  • Czech Republic National Cyber and Information Security Agency (NÚKIB)
  • Danish Defence Intelligence Service (DDIS)
  • Estonian Foreign Intelligence Service (EFIS)
  • Finnish Defence Intelligence (FDI)
  • Finnish Security and Intelligence Service (SUPO)
  • French General Directorate for Internal Security (DGSI)
  • French National Cybersecurity Agency (ANSSI)
  • Italian External Intelligence and Security Agency (AISE)
  • Italian Internal Intelligence and Security Agency (AISI)
  • Security and Intelligence Service of the Republic of Moldova (SIS RM)
  • Polish Foreign Intelligence Agency (AW)
  • The Military Counterintelligence Service of Poland (SKW)
  • Spain National Intelligence Centre (CNI)
  • Sweden National Cyber Security Centre (NCSC-SE)

What's happening

Systems affected

A Russian state supported advanced persistent threat (APT) group, known as LAUNDRY BEAR, has targeted and compromised users in various organisations, including those associated with:

  • the Defense Industrial Base (DIB),
  • the federal and local government,
  • education,
  • energy,
  • law enforcement,
  • media,
  • non-governmental organisations, and
  • technology.

What to look for

How to tell if you're at risk

Your organisation uses Zimbra Collaboration Suite.

What to do

Mitigation

Read the Mitigations section in the advisory for full details on how to mitigate.

More information

Download the advisory [PDF, 1.2 MB]

If you require more information or further support, submit a report on our website:

Report an incident External Lin.External Link.

If you need assistance using the tool, call us on 0800 114 115. Calling us is free within New Zealand. We’re open 7am to 7pm, Monday to Friday, and we’re closed on public holidays.