
Zero-Click Phishing: When Viewing an Email Is Enough
Most phishing advice comes down to a single instruction: do not click. It is simple, it is memorable, and for years it has stopped a great deal of harm. A campaign exposed by the UK and fifteen partner countries in July 2026 breaks that rule completely. The victims did not click a link or open an attachment. They only had to view an email, and their mailbox was already being copied.
The National Cyber Security Centre, part of GCHQ, and cyber agencies across sixteen countries have named the group behind it as LAUNDRY BEAR, a Russian state-supported outfit that specialises in quietly stealing email. Their method is a zero-click exploit, and it deserves attention well beyond the organisations that were directly hit, because the technique is very likely to spread.
What the LAUNDRY BEAR campaign actually did
Since at least July 2025, LAUNDRY BEAR has targeted organisations running Zimbra Collaboration Suite (ZCS), a widely used email and calendar platform. The group built an exploit it calls 'beehive' (or 'Ulej' in Russian) and used it to read the contents of victims' inboxes without ever alerting them. According to the joint advisory published on 22 July 2026, US organisations were targeted across defence, government, education, energy, law enforcement, media, NGOs and technology.
The stolen data was not trivial. CISA reports that the exploit automatically collected each victim's last 90 days of emails, their email address, their account password, the organisation's Global Address List, and their two-factor authentication tokens. In other words, one silent action handed the attacker the mailbox, the credentials and the second factor that was supposed to protect it. The advisory also notes the techniques were trialled extensively on Ukrainian victims before being turned on NATO members, a pattern seen repeatedly with Russian cyber groups.
How an email can attack you without a single click
The flaw at the centre of this is CVE-2025-66376, a stored cross-site scripting weakness in the classic Zimbra web interface. In plain terms, a stored scripting flaw lets an attacker plant code that runs later inside someone else's session. LAUNDRY BEAR hid that code inside the styling of an HTML email, abusing the way the webmail client handled CSS import rules. When a victim opened the message in a vulnerable version of Zimbra, the hidden script ran on its own, inside their logged-in session, and simply inherited their access to the mailbox.
That is what zero-click means here. There was no fake login page to spot, no attachment to think twice about, no suspicious button to hover over. The act of reading the email was the whole attack. Zimbra fixed the flaw in November 2025 with version 10.1.13, but LAUNDRY BEAR had already been using it as a zero-day before the patch existed, and the group continues to hunt for servers that have not been updated. As one detail worth noting, technical analysis suggests AI was used to help build the simple codebase behind the operation, a small sign of how these groups are speeding up their own work.

The part that still involves people
It would be easy to read all this and conclude that awareness training is pointless if a message can attack without a click. That is the wrong lesson. The malicious emails did not arrive from obvious strangers. They were sent from accounts LAUNDRY BEAR had already compromised, so to the recipient they looked like mail from a known, trusted sender. That trusted-sender trick is the oldest move in phishing, and it is exactly why a healthy dose of scepticism about unexpected messages, even from familiar names, still matters.
The realistic view is that people are one layer of defence and the systems behind them are another. When the trigger for an attack is simply viewing a message, the heavy lifting moves to patching, monitoring and account controls. But staff who notice that a colleague's emails suddenly read oddly, or that their own mailbox is behaving strangely, are often the first to raise the alarm. Equipping people to report those small signals quickly is far more useful than blaming them for a threat that was designed to need no mistake on their part.
Why this matters even if you do not run Zimbra
Most organisations are not a target for a state-supported espionage group, and most do not run Zimbra. The reason to pay attention is the method. The agencies behind the advisory warn that beehive could be adapted to exploit other vulnerabilities, and that as Zimbra servers get patched, the group is very likely to turn the same zero-click approach against other email platforms. Techniques that start life in targeted espionage have a habit of filtering down to ordinary cyber crime within a year or two. The defensive habits that blunt this attack are the same ones that protect against a great deal else.
Practical steps to reduce the risk
- Patch email and webmail systems quickly. This attack worked on servers that had not applied Zimbra's November 2025 fix. Prioritising updates for anything internet-facing closes the door that beehive relies on.
- Do not treat MFA as untouchable. The exploit lifted 2FA tokens along with the password. Move towards phishing-resistant methods such as passkeys or hardware keys where you can, and watch for sign-ins that reuse a stolen session.
- Monitor mailboxes for unusual behaviour. Sudden bulk access to old mail, new forwarding rules, or logins from unexpected locations are the kind of signals that reveal a silent compromise.
- Keep scepticism about trusted senders. A message from a known contact is not automatically safe if that contact's account has been taken over. Encourage staff to verify anything unexpected through a separate channel.
- Make reporting easy and blame-free. The faster a strange message or account behaviour reaches your security team, the smaller the eventual damage. UK organisations can also use the NCSC's free Early Warning service for alerts about malicious activity on their networks.
The bottom line
The LAUNDRY BEAR campaign is a reminder that do not click was always one control among many, not a complete defence. When simply reading an email can be enough, the answer is not to give up on people but to surround them with technical controls that catch what they cannot see, and to make it easy for them to flag the things they can. Zero-click attacks are rare and expensive to build today. They will not stay that way, and the organisations that treat patching, monitoring and a strong reporting culture as everyday habits are the ones that will barely notice when the next one arrives.
Sources: NCSC, the joint cybersecurity advisory (NSA-hosted), Help Net Security and The Hacker News.
Phishing Tackle offers the tools businesses need to strengthen their human risk strategies, with multi-platform testing, real-time behavioural insights, and actionable data to keep your organisation ahead of modern cyber threats.
Contact us today to learn how Phishing Tackle can help safeguard your organisation from the growing array of cyber risks.
