NCSC exposes Russian LAUNDRY BEAR 'zero-click' email phishing campaign targeting UK organisations

Impersonating: Zimbra Collaboration Suite (email targeting)

What is this scam?

The NCSC and 15 international partner agencies issued a formal advisory on 23 July 2026 exposing LAUNDRY BEAR, a Russian state-backed advanced persistent threat group conducting a covert zero-click phishing campaign against organisations using Zimbra Collaboration Suite (ZCS) webmail. Unlike conventional phishing, victim email accounts are compromised simply by viewing a specially crafted malicious message in a vulnerable ZCS inbox — no link click or file download is required. Since July 2025 the campaign has silently harvested sensitive communications from Western government bodies, universities, charities, and UK commercial organisations. ZCS administrators should apply the latest security patches immediately and audit all accounts for unauthorised email-forwarding rules.

Example scam message

[No visible phishing link or attachment is delivered — the attack exploits a Zimbra webmail vulnerability so that viewing a malicious email in a vulnerable ZCS inbox silently grants attackers sustained covert access to the account. Victims typically discover the compromise only when unusual email-forwarding rules or unexpected outbound traffic are found. Example indicator of compromise: an unauthorised mail-forwarding rule appearing in a ZCS account — 'Forward all messages to: archive-secure@protonmail.com' [This rule was not set by the account holder — apply the Zimbra security patch immediately from zimbra.com and remove any forwarding rules you did not create yourself]

Red flags to look out for

  • The message creates urgency — threatening a fine, missed delivery, or account closure.
  • Links lead to unofficial domains that don't match the real company's website.
  • You weren't expecting this message and can't verify the event it references.
  • It asks you to confirm payment details or personal information via a link.
  • The sender's number or email address doesn't match the company's official contact.

What to do if you receive this

  1. Do not call any numbers or click any links in the message.
  2. Log in to your account directly via the official website or app to check for any real alerts.
  3. Forward the message to 7726 or email report@phishing.gov.uk.
  4. Report it to Action Fraud at actionfraud.police.uk.
Received this message? Forward it to 7726 (free on all UK networks) to report it to your mobile provider. You can also report it to Action Fraud or email the NCSC at report@phishing.gov.uk.

Not sure if your message is a scam?

Check it instantly with our free AI-powered detector.

Check a message now
← Back to all latest scams

Source: NCSC