Government Advisory

Russian State-Sponsored Hackers Targeting Zimbra Email Servers to Steal Data

ACSC · 24 July 2026
Key Takeaway If your business uses Zimbra Collaboration Suite or similar email platforms, patch immediately, enable multi-factor authentication, and monitor for unusual account activity.

A joint cybersecurity advisory has revealed an ongoing campaign by Russian state-sponsored cyber actors targeting organisations that use Zimbra Collaboration Suite, a popular email and collaboration platform. The attackers are exploiting vulnerabilities in the software to gain unauthorised access to email accounts, steal sensitive correspondence, and establish long-term footholds within compromised networks.

While Zimbra is more commonly used by larger enterprises and government bodies, small and medium businesses that rely on it—or on similar self-hosted email and collaboration tools—should take note. State-sponsored actors often use compromised systems as stepping stones to reach partner organisations, supply chains, or clients, meaning even smaller players in a network can become valuable targets or unwitting conduits for further attacks.

Organisations running Zimbra should urgently check they are on the latest supported version and have applied all available security patches. Reviewing account activity logs for unusual login patterns, enforcing multi-factor authentication, and restricting administrative access are also strongly recommended steps to reduce exposure to this ongoing threat.

Zimbra state-sponsored email security patching advisory

Summarised by CISO AI from ACSC. We link back to every original so you can read it yourself.