Cyber Resilience
← All news
Confirmed4

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

CISA reports that Russian state actors have been phishing Zimbra Collaboration Suite users in Western government and commercial orgs since at least July 2025. If you run Zimbra, review the advisory and harden now.
Sources (2)
What this means for you — CISO:If you run Zimbra Collaboration Suite, review CISA advisory AA26-204a for IoCs and TTPs from this Russian state-supported phishing campaign and hunt across mail and identity logs. Confirm MFA, external-sender warnings, and patch posture on any internet-facing Zimbra hosts.
What this means for you — Lean IT orgs:If your shop uses Zimbra for email, open CISA advisory AA26-204a and follow its checks for signs of compromise. Turn on MFA if it is available and treat unexpected login or password-reset messages as suspicious until verified.
What this means for you — MSP:Inventory which clients self-host or depend on Zimbra Collaboration Suite and push AA26-204a IoCs plus hardening steps to those tenants first. Prioritize government and commercial clients with exposed Zimbra and confirm MFA and mail-gateway controls are in place.
What this means for you — Researcher:CISA AA26-204a covers Russian state-supported phishing against Zimbra Collaboration Suite users since at least July 2025. Pull the advisory for TTPs, IoCs, and targeting notes on Western government and commercial victims.