NCSC exposes Russian LAUNDRY BEAR 'zero-click' email phishing campaign targeting UK organisations
Impersonating: Zimbra Collaboration Suite (email targeting)
What is this scam?
The NCSC and 15 international partner agencies issued a formal advisory on 23 July 2026 exposing LAUNDRY BEAR, a Russian state-backed advanced persistent threat group conducting a covert zero-click phishing campaign against organisations using Zimbra Collaboration Suite (ZCS) webmail. Unlike conventional phishing, victim email accounts are compromised simply by viewing a specially crafted malicious message in a vulnerable ZCS inbox — no link click or file download is required. Since July 2025 the campaign has silently harvested sensitive communications from Western government bodies, universities, charities, and UK commercial organisations. ZCS administrators should apply the latest security patches immediately and audit all accounts for unauthorised email-forwarding rules.
Example scam message
Red flags to look out for
- The message creates urgency — threatening a fine, missed delivery, or account closure.
- Links lead to unofficial domains that don't match the real company's website.
- You weren't expecting this message and can't verify the event it references.
- It asks you to confirm payment details or personal information via a link.
- The sender's number or email address doesn't match the company's official contact.
What to do if you receive this
- Do not call any numbers or click any links in the message.
- Log in to your account directly via the official website or app to check for any real alerts.
- Forward the message to 7726 or email report@phishing.gov.uk.
- Report it to Action Fraud at actionfraud.police.uk.
Not sure if your message is a scam?
Check it instantly with our free AI-powered detector.
Check a message nowSource: NCSC