Russian state-backed hackers exploited an unpatched zero-day vulnerability in Zimbra's webmail platform to steal email, contact directories, browser-saved passwords, and two-factor recovery codes from Western organisations over several months.

The attack required only opening a malicious message. Once executed, the payload accessed the last 90 days of email traffic, extracted the complete organisational email directory, harvested credentials stored in browser memory, and collected 2FA backup codes. These elements together provide attackers with persistent access and bypass mechanisms for accounts protected by multi-factor authentication.

The NSA, CISA, and partner agencies coordinated the disclosure of this vulnerability. The involvement of multiple US intelligence agencies indicates the breach's scope and severity affected government or critical infrastructure targets alongside private sector victims.

Zimbra serves as the email backend for thousands of organisations globally, from small businesses to large enterprises. The zero-day's exploitation by a Russian state-sponsored group reflects the espionage objective rather than financial gain. Intelligence services typically target mailboxes to map organisational structures, identify sensitive communications, and establish long-term surveillance capabilities.

The two-factor code theft carries particular weight. Recovery codes bypass authentication entirely if an attacker gains access before the victim discovers the breach. Combined with harvested passwords and email access, attackers gain the ability to maintain persistent control over compromised accounts even after organisations reset credentials.

Organisations running Zimbra face immediate risk. Any user who opened a suspicious message during the exploitation window should assume their mailbox was accessed. The recovery window for defenders is narrow. Attackers holding 90 days of email and full directory information can use that intelligence to craft targeted spear-phishing campaigns, identify high-value targets, and plan follow-on attacks.

Patching Zimbra immediately is non-negotiable. Organisations should also conduct forensic analysis of mail logs for the