UK and allies warn of Russian-linked zero-click phishing against Zimbra users
THE BRIEF
The UK National Cyber Security Centre and international partners warned that Russia-linked actors had conducted a zero-click phishing campaign targeting users of Zimbra collaboration software. The advisory describes techniques designed to steal sensitive information while reducing or eliminating the need for the victim to interact with a malicious link or attachment. According to the NCSC, elements of the activity were first used against Ukrainian targets before being applied more broadly against Western organisations, including NATO members. The advisory was jointly supported by cyber agencies across Europe, North America and the Asia-Pacific region, reflecting the campaign’s international relevance and the wider reuse of these techniques across platforms.
WHY IT MATTERS
Zero-click and low-interaction phishing changes the assumptions behind many awareness programmes. Users cannot reliably defend against an attack that succeeds before they consciously click anything. The campaign therefore shifts more responsibility toward secure configuration, patching, account hardening, email telemetry and detection of anomalous sessions. It also reinforces the strategic value of collaboration-platform security: webmail systems often contain sensitive conversations, password-reset messages and identity signals that can support espionage or further compromise. Organisations using Zimbra or similar platforms should treat collaboration infrastructure as a high-value attack surface.
WHO SHOULD CARE
Government organisations, NATO-linked entities, enterprises using Zimbra, email-security teams, SOCs and identity-security leaders.
WHAT TO DO NOW
- Review the joint advisory and apply vendor-recommended Zimbra security updates.
- Harden administrator access and require strong MFA for privileged and remote accounts.
- Review webmail logs for anomalous sessions, forwarding rules and unusual access patterns.
- Restrict unnecessary internet exposure of collaboration infrastructure.
- Extend phishing defence beyond user training to session, identity and server-side detection.
VERIFICATION NOTE
Verified against the UK NCSC alert published 23 July 2026.