Russian hackers, identified as the Laundry Bear group, have compromised more than 10 Western organizations since July 2025, according to U.S. and allied cyber-intelligence authorities. The group has targeted defense contractors, nuclear scientists, and government employees, focusing on entities involved in nuclear fusion technology.
The hackers exploited a vulnerability in the Zimbra Collaboration Suite email software, allowing them to steal messages, passwords, and authentication data without requiring victims to click a link. The exploit activates when a victim opens or previews a malicious email in an unpatched version of the software.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and FBI issued a joint advisory regarding the cyber-espionage campaign. The advisory included support from defense, cybersecurity, and intelligence agencies from Australia, Canada, New Zealand, the United Kingdom, and over a dozen European countries.
The hackers aimed to collect up to 90 days of a victim’s communications and an organization’s email directory. Brett Leatherman, assistant director of the FBI’s cyber division, noted an uptick in Russian cyber targeting of the United States over the past year.
Proofpoint described the technique used by the hackers as a “half-click” exploit, as it requires victims to open or preview the email. The emails were sent from both attacker-controlled Proton Mail accounts and previously compromised addresses.
The Treasury Department’s Financial Crimes Enforcement Network purchased a Zimbra standard support subscription in February 2025, but it is unclear if this version was targeted in the campaign. CISA urged organizations to update all Zimbra mail software and monitor their email systems for suspicious activity.
UK Security Minister Dan Jarvis expressed concern that the hackers tested their methods on victims in Ukraine before targeting NATO members. In November 2025, Thai authorities arrested an alleged member of the hacking group, a Russian man in his 30s.
“CISA continues to see sophisticated and less sophisticated nation-state cyber groups deploy increasingly novel exploits into a highly successful capability to disrupt critical infrastructure or conduct espionage,” said Chris Butera, CISA’s acting executive assistant director for cybersecurity.




