International alert spotlights Russia-linked attacks on Zimbra webmail

2026-07-24T14:51:56Zf3b9303318dd2b032ebea4f2a6c636fbaad63f4168adce1614b2c76f0d2d259a
CISA 2015EverestLaundry BearNDAAOrigin EnergyRussiaStadler RailState DepartmentU.S. policyZimbracyber scamsdata breachinformation sharingnation-stateransom demandransomwarevisa restrictionswebmail compromisezero-click phishing

What happened

Multiple security and policy developments: an international alert says Kremlin-linked group Laundry Bear is using a zero‑click phishing technique to compromise Zimbra webmail accounts worldwide; the U.S. State Department announced visa restrictions targeting individuals tied to transnational cyber‑scam operations; Australian energy supplier Origin Energy confirmed a customer data compromise and is investigating impact; Stadler Rail refused a $12.3M ransom demand from the Everest group after technical data was stolen from a supplier file‑sharing platform; and the House included a 10‑year re‑lic

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
f3b9303318dd2b032ebea4f2a6c636fbaad63f4168adce1614b2c76f0d2d259a
Enrichment time
2026-07-24T14:51:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · International alert spotlights Russia-linked attacks on Zimbra webmail · Baitaphish