LAUNDRY BEAR: UK and Allies Expose Russian State-Supported Zero-Click Email Attack on Zimbra
The NCSC and 15 partner agencies have exposed LAUNDRY BEAR, a Russian state-supported group using a zero-click exploit called "beehive" to silently steal email from Western organisations running Zimbra Collaboration Suite. The user only needs to open a message. No click, no attachment, no warning.

Mark Fermor
Director & Co-Founder, Firevault

On 23 July 2026 the UK's National Cyber Security Centre, part of GCHQ, alongside cyber agencies in 15 partner countries, publicly attributed a long-running email theft campaign to a Russian state-supported group known as LAUNDRY BEAR. The group has been using a zero-click exploit named beehive (in Russian, Ulej) to compromise Zimbra Collaboration Suite (ZCS) webmail and quietly pull out sensitive email, according to the joint advisory.
What happened
Since July 2025, LAUNDRY BEAR has targeted Western organisations that run vulnerable versions of Zimbra Collaboration Suite. Confirmed US targets sit across defence, government, education, energy, law enforcement, media, NGOs and technology, according to the NCSC statement. The technique was trialled against Ukrainian victims first, then turned on NATO members, a pattern the agencies say is now typical of Russian state cyber activity.
Why "zero-click" matters
Traditional phishing needs the victim to do something. Click a link. Open an attachment. Enter a password. Beehive removes that step entirely. The NCSC advisory states that the user only has to view a malicious email inside a vulnerable ZCS webmail session for the exploit to fire and for the attacker to obtain persistent access to that mailbox and, in many cases, wider network access. There is no visible warning to the person on the other side of the screen.
This matters because most enterprise defences still assume the human is the last line. Security awareness training, hover-before-you-click, report-a-phish buttons, none of that helps when the payload runs on render.
Who has been named
The advisory has been co-sealed by NCSC (UK) alongside agencies from Australia, Canada, the Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, Poland, Spain, Sweden, the Netherlands, New Zealand and the United States. It is available in full on the US Department of Defense media library as Russian state-supported cyber actors conduct phishing campaign targeting users of Zimbra Collaboration Suite.
What UK officials are saying
"Today's action shows we're working hand-in-hand with our allies to expose Russian state-supported hackers targeting Western organisations. It is particularly concerning that these thugs tested their methods on victims in Ukraine, before targeting members of NATO. Organisations across the UK should sign up to NCSC's Early Warning service to ensure they can quickly secure their systems against similar activity."
Dan Jarvis MBE, Security Minister
"This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organisations. With our international partners, we strongly encourage organisations to familiarise themselves with the zero-click techniques described in the advisory, which could be used against other platforms, and act on the mitigation advice."
Beth Hopkins CMG, NCSC Chief Operating Officer
The AI angle
Technical analysis referenced in the advisory indicates that Artificial Intelligence played a role in generating parts of the codebase used in the operation. The Five Eyes agencies published a separate note earlier this month warning that AI is accelerating the speed, scale and sophistication of state-backed cyber operations. Beehive is a live example of what that looks like in practice: a small, cheap, machine-generated payload delivered against a widely deployed enterprise mail product.
The wider pattern
Beehive is not an isolated incident. It sits alongside a run of 2025 and 2026 attribution notices from NCSC and partners covering GRU Unit 26165 targeting logistics and technology firms, prolonged access campaigns against network edge devices, and repeated abuse of legitimate services for credential theft. The agencies caution that beehive is very likely to be adapted to exploit other email platforms once organisations start patching Zimbra.
What organisations should do now
- Patch Zimbra Collaboration Suite immediately to the versions specified in the joint advisory and confirm the patch level from the console, not from ticketing systems.
- Assume compromise for exposed instances that have been internet-facing without the patch since July 2025. Rotate mailbox credentials, review OAuth tokens and application passwords, and check for unauthorised mail forwarding rules.
- Improve email-plane monitoring. Look for anomalous IMAP, EWS or Zimbra API access, especially from residential proxies and cloud egress ranges.
- Sign up to the free NCSC Early Warning service for automatic notification of malicious activity on your networks.
- Segregate the crown jewels. Where email is the exfiltration path, the sensitive assets attached to it, board packs, M&A drafts, legal privileged material, HR files, should not live in the same always-on system.
The Firevault view
Zero-click is a category shift. It ends the assumption that a well-trained user is enough. It also ends the assumption that "cloud email = safe email", because the vulnerability is in the render path, not in the user's behaviour. The right response is not more training. It is less exposure.
Offline Secure Storage is designed for exactly this problem. Sensitive material, the specific files an attacker would go for once they are inside a mailbox, sits on a self-controlled, air-gapped vault that is physically disconnected outside a scheduled access window. There is no render path to exploit, no persistent session for an attacker to hijack, no OAuth token to steal. Combined with the Control Blueprints, it gives boards a defensible answer to the question regulators are now asking: where do you keep the material you cannot afford to lose, and what happens if the always-on estate is compromised tomorrow morning?
Beehive will not be the last zero-click. It is the first widely attributed one against enterprise mail. Every organisation that treats email as the vault should read the advisory in full, patch on the same day, and then have an honest conversation about which of its data ever needed to be on an always-on system in the first place.
Sources
- NCSC, "UK and partners expose Russian state-supported actors for new zero-click phishing campaign targeting Western organisations", 23 July 2026 (ncsc.gov.uk).
- Joint Cybersecurity Advisory, "Russian state-supported cyber actors conduct phishing campaign targeting users of Zimbra Collaboration Suite", 22 July 2026 (media.defense.gov).
- NCSC, "The AI shift in cyber risk: why leaders must act now", 2026 (ncsc.gov.uk).





