The 'Don't Click' Era Is Over: Russian Hackers Are Breaking Into Email That Victims Never Even Opened Carelessly
For twenty years, cybersecurity advice has rested on one pillar: don't click suspicious links. A newly disclosed Russian state-backed campaign against Zimbra webmail just knocked that pillar down. According to a joint international alert, victims didn't need to fall for anything — in some reported cases, simply opening or even previewing an email was enough to hand attackers the keys to their inbox.
Bottom Line
A Russian state-backed campaign against Zimbra webmail marks another step in the retirement of the 'human firewall.' The attack requires little to no victim error, targets the affordable infrastructure that under-resourced organizations depend on, and turns every compromised inbox into a launchpad against its contacts. The lesson isn't 'be more careful' — it's that email security is now a patching and configuration problem, and the organizations least equipped to handle that are the ones squarely in the crosshairs.