Key Developments
On 23 July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) warned Zimbra users about Russian state-supported malicious activity. On the same date, HM Government told the OSCE that Russia’s conduct in Ukraine had caused civilian harm and required accountability.
Key Statistics
- More than 10 organizations were successfully targeted by LAUNDRY BEAR, according to CISA.
- 1 zero-click exploit was used against Zimbra Collaboration Suite users, according to CISA.
- 125 drones were launched in attacks cited by HM Government.
- 41 missiles were launched in attacks cited by HM Government.
- 20 civilian casualties were cited in the UK statement to the OSCE, according to HM Government.
- 24 individuals and entities were targeted in a historical UK-EU cyber sanctions package, according to HM Government.
Main Body
On 23 July 2026, CISA, the NSA, the FBI and partner agencies warned Zimbra Collaboration Suite users that the Russian state-supported group LAUNDRY BEAR had carried out ongoing malicious activity. On the same date, HM Government told the OSCE that Russia’s attacks in Ukraine and conduct in occupied areas showed continuing disregard for international humanitarian obligations.
The CISA advisory said LAUNDRY BEAR had used phishing and a zero-click exploit against Western organizations and provided mitigation and remediation steps for exposed users. The UK statement cited large-scale Russian strikes involving drones and missiles, civilian casualties, arbitrary detention and efforts to suppress Ukrainian identity in occupied territories.
The announcements followed earlier allied action against Russian-linked cyber operations. On 13 July 2026, France’s Ministry for Europe and Foreign Affairs attributed espionage-related cyber activity against French interests to the FSB’s 16th Center. Also on 13 July 2026, HM Government said the UK and EU had sanctioned Russian cyber networks, including individuals and entities tied to cyber operations and disinformation.
The development mattered for security and diplomacy because the CISA warning gave organizations concrete defensive steps, while the UK OSCE statement placed civilian harm and detention allegations in an accountability forum. Together, the French, UK and US statements showed a continued allied response using public attribution, cyber defence guidance and sanctions.




