# UK and Allies Uncover Russian-Backed Zero-Click Phishing Attack on Western Organizations

*Published July 24, 2026*
*Source: [https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign](https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign)*

## Executive Summary

The UK and international partners have exposed a Russian state-backed group using a zero-click exploit to target Western organizations' email systems. This campaign poses significant risks, highlighting the need for immediate security measures.

## Article

The UK’s National Cyber Security Centre, part of GCHQ, alongside cybersecurity agencies from 15 other nations, has revealed a sophisticated phishing campaign attributed to the Russian state-supported group known as LAUNDRY BEAR. This advanced persistent threat group has been exploiting a zero-click vulnerability called 'beehive' or 'Ulej' to infiltrate email systems, particularly those using the Zimbra Collaboration Suite software. Since July 2025, the group has targeted organizations in the United States across various sectors, including defense, government, education, energy, law enforcement, media, NGOs, and technology.

The zero-click nature of the 'beehive' exploit means that users do not need to interact with malicious content for their systems to be compromised. Simply viewing a specially crafted email in a vulnerable ZCS webmail interface suffices for the attack to succeed. In response to this threat, the NCSC and its partners have issued a joint advisory urging organizations to patch their systems promptly and enhance their network monitoring capabilities.

There is a significant concern that the 'beehive' exploit could be adapted to target other email systems if vulnerabilities are found. As more organizations update their ZCS software, LAUNDRY BEAR may turn its attention to other platforms used by Western entities. The NCSC encourages UK organizations to register for its free Early Warning service, which provides alerts on malicious network activity. This initiative is part of broader efforts to bolster cyber resilience across the UK.

The advisory also highlights that this campaign reflects a broader trend of Russian cyber threat groups testing their methods on Ukrainian targets before expanding to NATO members. The involvement of AI in the development of these cyber techniques further underscores the growing complexity and speed of cyber threats. The NCSC and its international partners remain committed to exposing and mitigating such state-backed cyber activities.
