NCSC Alert: State Hackers Stealing Email Without Any Clicks
What has happened
On 23 July 2026, the UK’s National Cyber Security Centre (NCSC) published an urgent joint advisory alongside CISA, the NSA, and security agencies from partner nations across 15 countries in total. The subject: a sustained campaign by a Russian state-backed hacking group called LAUNDRY BEAR, which has been systematically stealing sensitive email data from organisations across the West.
The attack exploits a vulnerability in Zimbra Collaboration Suite (ZCS), an email and groupware platform used by some businesses, government bodies, and organisations as an alternative to Microsoft 365 or on-premises Exchange. The security flaw, tracked as CVE-2025-66376, is a stored cross-site scripting (XSS) bug. In plain terms: attackers hide malicious code inside a specially crafted email, and that code runs automatically in the recipient’s browser when the email is viewed in Zimbra’s classic webmail interface.
What makes this particularly alarming is that it is a zero-click attack. The victim does not need to click a link, open an attachment, or approve anything. Simply viewing the malicious email in a vulnerable version of Zimbra webmail is enough to trigger the code. Once it runs, it begins silently copying and exfiltrating the victim’s emails to the attackers’ infrastructure. The NCSC assesses that LAUNDRY BEAR may have used artificial intelligence tools to help develop its attack toolkit.
A patch for CVE-2025-66376 was released by Zimbra in November 2025 as part of ZCS versions 10.1.13 and 10.0.18. Wherever Zimbra has not been updated to those versions, organisations remain exposed right now.
Why this matters to your business
If your business uses Zimbra and has not yet applied the November 2025 patch, your email is currently at risk from a state-level espionage campaign. A single malicious email landing in an unpatched Zimbra inbox is all it takes. There is no warning, no antivirus prompt, no obvious sign of compromise. The attack is designed to be quiet and sustained, with LAUNDRY BEAR having run the campaign successfully since at least July 2025.
If your business uses Microsoft 365 or on-premises Exchange, this specific attack does not target your platform. That said, the NCSC advisory is a useful signal for all businesses: nation-state actors are actively investing in tools that can compromise business email silently and at scale. Email remains the most sensitive communication channel most organisations have, and the security configuration around it matters.
There is also a data protection angle. A successful email compromise could expose years of confidential correspondence, client data, and any personal information processed via email. Under UK GDPR, a breach caused by knowingly running unpatched software is difficult to defend if the ICO investigates.
What to check and do
If you use Zimbra Collaboration Suite:
- Update to ZCS version 10.1.13 or 10.0.18 immediately. These versions contain the fix for CVE-2025-66376.
- If you cannot patch straight away, advise staff to stop using the classic Zimbra webmail browser interface and access email via an alternative client until the update is applied.
- Review your server logs for any unusual outbound data transfers that might indicate exfiltration has already occurred.
- If you suspect a compromise has taken place, treat this as a security incident and seek specialist support.
For all businesses, regardless of which email platform you use:
- Ensure multi-factor authentication (MFA) is enabled across all email accounts. MFA means that even if an attacker steals your password, they still need a second verification step, such as a code sent to your phone, to get in.
- Keep your email platform up to date. Whether you use Microsoft 365, Exchange, or any other system, regular patching closes the doors that attackers are actively looking for.
- Consider whether you have advanced threat protection in place for email, such as Microsoft Defender for Office 365, which adds an additional layer of inspection and defence against sophisticated attacks.
How we can help
For businesses on our managed IT service, we maintain your Microsoft 365 environment to security best practice, including MFA enforcement, Defender for Office 365 configuration, and regular patching. Your email security is part of what we actively manage.
If you have any concerns about your email security posture, or would like a review of how your business is protected against this class of threat, our IT security team is ready to help. If you use Zimbra and need urgent support with patching or incident response, please contact us today.
This attack is also a reminder of why Cyber Essentials certification matters. The scheme requires businesses to demonstrate that software is kept patched and up to date, and organisations that do this consistently are significantly harder targets for exactly this kind of campaign.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


