Government Advisory

Russian State-Backed Hackers Target Zimbra Email Users in Phishing Campaign

ACSC · 23 July 2026
Key Takeaway If your business uses Zimbra or similar email platforms, enable multi-factor authentication and train staff to spot phishing attempts, as these remain the easiest way for attackers to gain access.

The Australian Cyber Security Centre (ACSC) has co-published an advisory warning of a phishing campaign linked to a Russian state-supported cyber actor known as LAUNDRY BEAR. The campaign targets organisations using Zimbra Collaboration Suite, a widely used email and collaboration platform, with the aim of compromising user accounts and gaining unauthorised access to sensitive communications.

While the advisory does not detail every technical aspect of the attack publicly, it confirms that phishing remains the primary method used to trick users into revealing credentials or granting access to their Zimbra accounts. State-linked actors often use these footholds to conduct espionage, steal data, or move laterally into connected business systems.

Organisations using Zimbra or similar collaboration platforms should treat this as a reminder that email systems remain a top target for sophisticated threat actors, including nation-state groups. Businesses are encouraged to review the full joint advisory, apply relevant security patches, and reinforce staff awareness of phishing tactics.

phishing Zimbra state-sponsored threats email security ACSC advisory

Summarised by CISO AI from ACSC. We link back to every original so you can read it yourself.