This week the NCSC — part of GCHQ — joined cyber agencies from 15 other countries to formally expose a group known as LAUNDRY BEAR, attributing a year-long email espionage campaign to Russian state support. What makes it worth every UK business owner’s attention, even outside the specific organisations targeted, is the method: victims didn’t need to click a link, open an attachment, or make any mistake at all. Simply viewing the email in a vulnerable webmail platform was enough to trigger malicious code that quietly exfiltrated up to 90 days of email history and the organisation’s internal address book. It’s the clearest sign yet that “don’t click suspicious links” — the advice every business has drilled into staff for a decade — is no longer the whole story.
What actually happened
LAUNDRY BEAR exploited a cross-site scripting flaw in Zimbra Collaboration Suite, a webmail platform, embedding JavaScript directly inside emails that executed the moment the message was opened. NCSC’s technical analysis suggests AI tools were used to help generate the exploit’s codebase — a detail that matters beyond this specific campaign, because it points to attackers using AI the same way defenders do: to build and iterate faster. The targets were largely government, defence, energy, and technology organisations across the US and allied countries, but the technique itself isn’t tied to one platform or one target list. Zero-click, view-only exploits have been growing across messaging and email platforms for two years, and this is the most detailed public confirmation yet that the trend is accelerating rather than fading.
Why “don’t click the link” isn’t enough anymore
Most SME security training still centres entirely on spotting a bad link or a dodgy attachment, and that training is still worth doing — most attacks still rely on it. But a business whose entire defence is “train staff to be suspicious” has no answer to an exploit that fires before anyone’s judgement gets involved. The practical response isn’t complicated: keep webmail and email-adjacent software patched on a short cycle rather than a quarterly one, because these vulnerabilities get exploited fast once public; make sure whatever platform you use for email is one still receiving active security updates, since older or unsupported webmail software is exactly where flaws like this survive longest; and treat “we patched it eventually” as no longer good enough when the gap between disclosure and exploitation keeps shrinking.
For businesses without the internal capacity to track which of their platforms and vendors carry this kind of exposure, KeepSafe monitors for exactly this — incidents and vulnerabilities affecting the tools a business actually relies on — so you’re not finding out about a zero-click flaw in your email platform from a news story after the fact.
It’s not just about Zimbra
Most UK SMEs don’t run Zimbra — Microsoft 365 and Google Workspace cover the large majority of the market — and it would be a mistake to read this as “not my platform, not my problem.” The same class of vulnerability has surfaced repeatedly across email and messaging software over the past two years, precisely because webmail clients render a huge amount of untrusted content (HTML, embedded scripts, images) automatically, by design, so that emails display properly. That’s a large attack surface sitting behind every inbox, regardless of vendor. The specific flaw here belonged to one platform; the pattern it represents belongs to all of them, and the next one exploited this way is unlikely to announce itself in advance.
The takeaway
You can’t train someone to avoid clicking something they never had to click. Check what webmail or collaboration platform your business runs on, confirm it’s still receiving security patches, and get those patches applied on a cycle measured in days, not months — because the next zero-click campaign won’t wait for you to notice.