US and Allies Blame Russian Hackers for Email Theft Without Tricking Users

The United States and more than a dozen allied nations announced Thursday that Russian hackers successfully stole emails from users of the Zimbra email platform — without ever needing to trick those users into clicking a link or opening a suspicious attachment.

The attack method, which cybersecurity company Proofpoint described as a “half-click exploit,” took advantage of a vulnerability — now fixed — in Zimbra software. The flaw allowed hackers to access an account simply after a user opened an email, with no further action required on the victim’s part.

“No social engineering required,” Proofpoint wrote in a blog post detailing the hacking operation.

A 31-page alert issued by police and intelligence agencies from the U.S., the Netherlands, Canada, Britain, Australia, New Zealand, Denmark, the Czech Republic, and several other European countries attributed the spy campaign to a Russian government-backed hacking group called Laundry Bear. According to the alert, the group initially focused heavily on targets in Ukraine before shifting its attention to users in the U.S. and other NATO alliance members.

British Security Minister Dan Jarvis responded sharply to the findings. “It’s particularly concerning that these thugs tested their methods on victims in Ukraine, before targeting members of NATO,” he said in a statement.

Laundry Bear is one of several hacking groups the U.S. alleges are operating on behalf of Russian security services. A U.S. indictment filed this month connected the group to a Russian cybersecurity firm called Yutek-NN. The company’s deputy director, Denis Obrezko, is facing hacking-related charges in Boston after being arrested in Thailand last year. He has entered a not guilty plea.

The Russian embassy in Washington did not respond to a request for comment. Yutek-NN has also not answered repeated requests for comment. Russia has historically denied any involvement in hacking operations.

Zimbra and its parent company, Synacor, which is headquartered in Buffalo, New York, could not be reached for comment.

Russian cyber operatives have long made email services a prime target for intelligence gathering. In April, it was reported that Russian hackers had broken into dozens of email accounts belonging to prosecutors and investigators across Ukraine.