A rare 'zero click' exploit, where opening a message is enough, ran for a year on Western targets after being tested on Ukraine, US and allies warn.
On Thursday, US and allied agencies disclosed a year-long cyber-espionage campaign in which Russian state-aligned operators quietly siphoned about three months of inbox data and full organizational directories from Western nuclear-fusion researchers, defense contractors, and government employees. The exploit runs on a single opened email, with no link click, no attachment, and nothing to hover over.
The campaign, attributed to Russian state-sponsored cyber actors in CISA advisory AA26-204A on 23 July 2026, is described as "ongoing." The joint advisory was signed by CISA, the FBI, the NSA, and more than a dozen international partners, and was corroborated by private-sector researchers at Proofpoint and Palo Alto Networks' Unit 42, according to CNN.
A "zero-click" exploit fires the moment a target opens a vulnerable message. The technique has been used against journalists and dissidents in the past. Its appearance against nuclear and defense targets is what makes Thursday's advisory unusual. Security researchers tracking the activity as "LAUNDRY BEAR" say the actors used the Zimbra flaw to steal about 90 days of email and, in some cases, two-factor authentication codes from targeted mailboxes. Two-factor codes in hand let attackers reset passwords and reach cloud accounts tied to the same identity, extending the damage well beyond the inbox.
Proofpoint researcher Greg Lesnewich told CNN the hackers were "targeting entities and users with an interest in nuclear fusion," most likely "to see what advancements [Russia's] peers in the space have made." Nuclear-fusion research shapes long-term military energy, propulsion, and weapons-stewardship work. Sherrod DeGrippo, vice president of threat intelligence at Palo Alto Networks Unit 42, said the actor "likely hoped to gain strategic insight into western military information, logistics, and policy decisions."
Before widening to NATO countries, the same hacking techniques were tested against targets in Ukraine, per the joint advisory. The pattern of running a campaign against Kyiv's networks first, then turning it on alliance members, has been a recurring feature of Russian cyber operations since 2022. The sectors listed in the advisory, federal and local governments, law enforcement, defense, education, and energy, overlap heavily with the kinds of institutions that have supported Ukraine's defense.
The advisory does not name victims. CISA declined to characterize the scale of the intrusion, and the Department of Energy, which oversees multiple national laboratories focused on nuclear energy, did not respond to a request for comment. The FBI and NSA were not immediately available, and the Russian Embassy in Washington did not respond.
The exploit targets the Zimbra Collaboration Suite, an open-source email and calendaring platform used widely by governments, universities, and mid-sized companies that run their own mail. Zimbra is not a household name, but it is the inbox of record for a meaningful slice of the public sector. A patch is available. Whether every affected organization has applied it is a separate question, and the advisory does not say.
The next concrete milestones to watch: CISA or any ally naming affected organizations, an indictment, or a publication of technical indicators of compromise that let defenders hunt the activity in their own logs. For now, the advisory's reference number is AA26-204A.