First published: 24 Jul 2026
Last updated: 24 Jul 2026

Content written for

Large organisations & infrastructure
Government

Today we released a joint advisory with international partners about cyber activity linked to the Russian state-sponsored group known as LAUNDRY BEAR.

The advisory explains how the group used a previously unknown flaw in Zimbra Collaboration Suite (ZCS) to access organisations' email systems.

Unlike most phishing attacks, this technique does not require a user to click a link or open a file. The attack can begin when a user simply views a malicious email in a vulnerable version of the webmail service.

The group uses this technique to steal emails, contact lists and other sensitive information. They may also try to stay inside a compromised network so they can carry out more attacks.

Organisations that use Zimbra Collaboration Suite may face increased risk. This includes organisations in the following sectors:

  • the Defence Industrial Base (DIB),
  • the federal and local government,
  • education,
  • energy,
  • law enforcement,
  • media,
  • non-governmental organizations, and
  • technology.

We strongly encourage organisations and network defenders to read the advisory. They should check whether they use vulnerable versions of ZCS and whether their networks may be affected.

Organisations can reduce risk by updating vulnerable software, applying security patches and monitoring email services for signs of compromise. The advisory also explains what to do if an organisation finds signs that its systems may have been compromised.

These recommendations can help protect against techniques used by other malicious cyber actors. Organisations should apply security updates quickly and regularly monitor internet-facing systems.

Cyber threats affect all countries.

Australia and international partners encourage responsible behaviour in cyberspace and support a secure and resilient online environment.

Read the full advisory.

Was this helpful?
Yes this was helpful
No this was not helpful

Thanks for your feedback!

We welcome additional feedback below.

Was this information easy to understand?
Will you take action after reading this?
Did you find the information you were looking for?
Did the design and layout of this page meet your expectations?