UK and allies warn of Russian-backed ‘zero-click’ attacks on Western email systems

The UK’s National Cyber Security Centre (NCSC) and cybersecurity agencies from 15 partner countries have warned that a Russian state-supported threat group is using a “zero-click” phishing technique t...

The UK’s National Cyber Security Centre (NCSC) and cybersecurity agencies from 15 partner countries have warned that a Russian state-supported threat group is using a “zero-click” phishing technique to steal email data from Western organisations.

The campaign has been attributed to LAUNDRY BEAR, an advanced persistent threat group associated with covert email collection. According to the joint advisory, the activity began in July 2025 and has involved the compromise of organisations using Zimbra Collaboration Suite (ZCS), a widely used email and collaboration platform.

Victims in the United States have included organisations in defence, government, education, energy, law enforcement, media, technology and the non-profit sector. The agencies said the campaign is consistent with espionage and is almost certainly being conducted with Russian state support.

A different phishing model

The technique, referred to as “beehive” or “Ulej”, does not require a victim to click a link, open an attachment or otherwise interact with a message. Instead, viewing a malicious email through a vulnerable version of the ZCS webmail service can be sufficient to trigger the compromise.

Once access is obtained, the attackers can maintain broad and persistent access to email accounts and collect sensitive information. The advisory warns that the method could be adapted to exploit other vulnerabilities and email platforms as organisations patch affected ZCS deployments.

Mitigation advice

Organisations using ZCS are urged to apply available security updates immediately, review the advisory’s technical indicators and strengthen monitoring for unusual network and account activity. The NCSC also recommends that UK organisations enrol in its free Early Warning service, which provides notifications about potentially malicious activity affecting their networks.

International partners said technical analysis suggests the attackers tested the techniques extensively against Ukrainian targets before using them against organisations in NATO countries. Analysts also found indications that artificial intelligence may have assisted in developing parts of the operation’s relatively simple codebase.

The advisory was issued jointly by agencies in the UK, Australia, Canada, the Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, Poland, Spain, Sweden, the Netherlands, New Zealand and the United States. The agencies encouraged organisations to treat the incident as a warning that hostile groups are adapting phishing methods to exploit trusted business software and reduce the need for user interaction.