You Didn't Click Anything and Were Still Hacked. How?
The advice everyone has heard about email is: do not click the link. It is good advice and it is no longer complete.
In July 2026, CISA and international partners published an advisory about a Russian state-backed group known as Laundry Bear, also called Void Blizzard. The group was breaking into email accounts using a flaw that required the victim to do nothing at all. Simply having the message open in the webmail window was enough.
Most people reading this are not running the software involved. The reason it matters anyway is that it breaks an assumption a lot of us rely on, which is that being careful is enough.
What actually happened
The flaw was in Zimbra Collaboration Suite, email software used by organisations rather than individuals. It was a stored cross-site scripting vulnerability, tracked as CVE-2025-66376, in the Classic web client.
Read next: Who calls from (609) 544-6188? Reported 14 times from New Jersey
Attackers sent an HTML email with JavaScript hidden inside it. When the victim's webmail displayed the message, that code ran automatically. No link, no attachment, no password entered.
According to CISA, the code then collected and sent back:
- The victim's last 90 days of email
- Their email address and password
- The organisation's Global Address List, meaning everyone's contact details
- Two factor authentication tokens
It also created a new Zimbra application passcode and sent that back, which gives lasting access even after the password is changed.
Laundry Bear used the flaw as a zero-day, meaning before anyone knew it existed. Zimbra patched it in November 2025. CISA reports the group is still finding organisations that have not applied the patch.
Read next: Rental Scams in 2026: $275 Million Lost and How to Spot One
Why the two factor detail is the important one
Two step login is the single strongest thing most people can do to protect an account. That has not changed and this article is not an argument against it.
What this attack shows is the shape of the exception. When code runs inside your already logged-in session, it does not need to defeat your second step, because you have already completed it. It simply takes the result.
The same principle appears in scams aimed at ordinary people. Relay phishing pages pass your one-time code to the real site in real time while you are typing it, which we cover in our guide to fake login pages. Different technique, same idea: not breaking the lock, waiting for you to open it.
What this means for you, practically
You are almost certainly not running Zimbra. But zero-click flaws are found regularly in things people do use: iPhones, Android, WhatsApp, message previews, image handling.
Read next: Is ShopVSB.com Legit? Vitamin Sea Boutique Review 2026
There is one honest conclusion to draw from that.
Against a zero-click attack, care does not help. Only updates do.
If nothing needs to be clicked, there is no moment where being sensible protects you. The flaw is closed by a patch or it stays open. That is the whole defence.
Which puts a very ordinary piece of advice in a different light: turning on automatic updates is not housekeeping. It is the only protection that works when caution cannot.
- iPhone: Settings, General, Software Update, Automatic Updates, turn everything on
- Android: Settings, System, Software update, enable automatic download
- Windows: Settings, Windows Update, leave it on
- Mac: System Settings, General, Software Update, Automatic updates
Turn on automatic app updates too, in the App Store or Play Store. Apps get the same repairs and they get postponed the same way.
Our device settings guide covers this and five other settings, each under five minutes.
If you work somewhere, this is worth passing on
Whoever runs email at your organisation, church, club or practice should know two things.
Zimbra Classic web client needs to be on the current patch. The most recent guidance points to version 10.1.19. Servers left unpatched are still being targeted.
Check for mail rules nobody created. After this kind of compromise, a forwarding rule is often left behind so the attacker keeps receiving copies long after the hole is closed. It is the step most often missed during cleanup.
The part that does not change
Zero-click attacks are rare, expensive and aimed at governments, defence, energy and similar targets. They are not what will reach you.
What will reach you is an ordinary message asking you to click something, and the ordinary defences still work on that:
- Never reach an account through a link in a message. Open the app, or type the address yourself.
- Use a passkey where one is offered. It cannot be phished, because it only works on the genuine site.
- Keep two step login on. This attack is the exception, not the rule.
- Leave automatic updates on and stop postponing them.
Sources
- CISA Cybersecurity Advisories, joint advisory on Laundry Bear, July 2026
- Zimbra Security Center, patch releases and advisories
- BleepingComputer, Russian hackers exploit Zimbra zero-click flaw for email theft
- CISA, Secure Our World: Update Software
What Do You Think?
No one has commented yet. If this happened to you as well, say so below. Knowing that other people had the same call makes it far easier for the next person to trust their instincts.
Add Your Comment
Every comment is read by a person before it appears, so it will not show up straight away. Never post your phone number, address, or bank details here.