UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations

Source: United Kingdom National Cyber Security Centre

  • Russian state-supported actors develop new technique to target Western email platforms and gain persistent access to compromised networks 
  • Organisations provided with trusted advice and support to protect sensitive data in the face of evolving cyber threats

Russian state-supported cyber actors have targeted Western organisations with a malicious campaign which uses a zero-click exploit coined “beehive” (or “Ulej”) to steal emails, the UK has warned. 

Today, the National Cyber Security Centre – a part of GCHQ – alongside cyber security agencies in 15 countries, has exposed activities of LAUNDRY BEAR, an advanced persistent threat group who specialise in the covert acquisition of email data.

Since July 2025, LAUNDRY BEAR has successfully targeted and stolen sensitive email information from organisations that use Zimbra Collaboration Suite (ZCS) software. US organisations have been targeted in sectors including defence, government, education, energy, law enforcement, media, NGOs and technology.  

In a new joint advisory, the NCSC and partners warn LAUNDRY BEAR’s ongoing campaign is indicative of espionage and almost certainly carried out with Russian state support.  

Unlike traditional phishing campaigns, “beehive” allows the threat actors to gain extensive and sustained access to emails without requiring a user’s input. Instead of clicking a link or opening a file, the user only has to view a malicious email within a vulnerable version of the ZCS webmail service to be compromised.  

Organisations that use ZCS are urged to follow the mitigation advice, including to immediately patch vulnerabilities and improve network monitoring capabilities. 

The cyber agencies caution that it is likely “beehive” could be adapted to exploit other vulnerabilities. As more organisations update their ZCS software, it is very likely that the group will also look to target other email systems that Western organisations use. 

The NCSC recommends all UK organisations should sign up to the free Early Warning service for malicious network activity notifications.  

The government is committed to raising cyber resilience across the UK to protect businesses and safeguard growth. Earlier this month, businesses from every corner of the British economy joined a pledge publicly committing to strengthen their defences in the face of a fast-evolving threat.

Today’s action shows we’re working hand-in-hand with our allies to expose Russian state-supported hackers targeting Western organisations. It’s particularly concerning that these thugs tested their methods on victims in Ukraine, before targeting members of NATO. 

Organisations across the UK should sign up to NCSC’s Early Warning service to ensure they can quickly secure their systems against similar activity.

Security Minister, Dan Jarvis MBE

This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organisations. 

With our international partners, we strongly encourage organisations to familiarise themselves with the ‘zero-click’ techniques described in the advisory which could be used against other platforms, and act on the mitigation advice. 

We will continue to call out malicious cyber activity supported by the Russian state and urge everyone to follow NCSC guidance to raise resilience, including steps to strengthen online account security. 

Beth Hopkins CMG, NCSC Chief Operating Officer

The advisory highlights how these malicious cyber techniques were extensively trialled on Ukrainian victims before use against members of NATO, which is part of a growing trend amongst Russian cyber threat groups. 

In this case, technical analysis indicates that Artificial Intelligence (AI) played a role in the development of a simple codebase for the operation. Recently, the Five Eyes cyber security agencies called on leaders to take key actions as AI continues to accelerate the speed, scale, and sophistication of cyber threats. 

The NCSC has co-sealed this new advisory alongside agencies from Australia, Canada, the Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, Poland, Spain, Sweden, the Netherlands, New Zealand and the United States.

It can be read on the NSA website: https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF

Post-quantum cryptography (PQC) migration workshop report

Source: United Kingdom National Cyber Security Centre

There is no shortage of guidance on migration to PQC. But guidance alone is not enough. Making the PQC transition efficiently and securely requires close collaboration between experts in cryptography, cyber security and network operations, as well as those who understand the technical and business realities of the organisation undergoing change.

For this reason, the workshop was designed to connect experts across disciplines, share real-world approaches and challenges, and build momentum for action through collaboration. In doing so, the following key themes emerged from the workshop.

Arrests and searches in light of human trafficking investigation

Source: Eurojust

During the actions, four suspects were arrested in Amsterdam, including in the red-light district and two suspects were arrested in Romania simultaneously. Twelve searches took place in both countries, where information and evidence were gathered to further the investigation. The suspects are currently in custody.

Authorities are working together during the investigation through a joint investigation team set up at Eurojust. Eurojust and Europol have supported the investigation since the start and will continue to do so following yesterday’s actions.

The actions were carried out by the following authorities:

  • Netherlands: Public Prosecution Office Amsterdam; Police Coordination Centre for Cross-Unit Human Trafficking Interventions; Police Amsterdam – Human Trafficking Unit; Amsterdam Regional Criminal Investigation Department; Amsterdam Burgwallen Neighbourhood Police Team
  • Romania: Prosecution Office of the High Court of Cassation and Justice; Directorate for Investigation of Organized Crime and Terrorism, Dâmbovița Territorial Office; Romanian Police – Directorate for Combating Organized Crime, Dâmbovița Service for Combating Organized Crime; Buzau Service for Combating Organized Crime; Constanta Brigade for Combating Organized Crime; Ilfov Country Police Inspectorate; Buzau County Police Inspectorate; Constanta Mobile Gendarmerie Brigade; Special Intervention Gendarmerie Brigade; Buzau County Gendarmerie Inspectorate

Helping small businesses with free, hands-on cyber consultancy

Source: United Kingdom National Cyber Security Centre

Cyber Advisors can also help you with other free tools from the NCSC. The Early Warning service, for example, warns you about potential viruses and vulnerabilities on your network, so you can act on them before they become bigger problems. If you employ a Cyber Advisor, they will also be able to help set up Early Warning, and use the alerts you’ll receive to improve your cyber security.

The NCSC’s Cyber Action Toolkit gives you a practical starting point for building cyber resilience and a pathway towards Cyber Essentials certification.

Another tool, the NCSC’s free Cyber Action Toolkit, is a new way of providing advice in a way that engages small businesses, and more importantly, encourages you to take action. As you work through the toolkit, you’ll build layers of protection around your organisation which defends against common cyber threats such as email hacking, data breaches and ransomware.

Ultimately, initiatives like these demonstrate that cyber security is within reach for organisations of all sizes, working across all sectors. With the right support, small businesses don’t need to tackle cyber security alone. You can confidently take practical steps to protect your operations, customers, and data with the support and expertise that’s perfectly tailored to you.

Emma W, Head of Cyber Essentials

Interregional Training on Joint Investigation Teams for EU and Latin American prosecutors

Source: Eurojust

On 2-3 July 2026, the EJOCN in cooperation with the JITs Network Secretariat and with the support of EL PACCTO 2.0, organised an interregional training on Joint Investigation Teams (JITs), held at Eurojust. The training was addressed to specialised organised crime prosecutors from the EU and Latin America to provide capacity building on the use of JITs with a focus on their practical implementation in complex organised crime and drug trafficking investigations between these two regions. The training placed particular emphasis on the interregional dimension of cooperation and the judicial advantages of cooperation in a JIT as a strategic added value in combating and disrupting contemporary transnational criminal networks and drug trafficking operations. 

During the two-day event, practitioners from 17 European and 5 Latin American jurisdictions collaborated in teams on a fictional cross-border case developed specifically for the training. Through simulations and group exercises, participants addressed key operational elements encountered in JITS; including the drafting of JIT agreements, preparation and participation in coordination meetings, and the organisation and dynamic responses encountered during a joint action day.

The programme brought together extensive expertise on JITs, particularly from the JITs Network Secretariat, alongside diverse national experiences on organised crime and drug trafficking cases from the practitioners. It also provided practitioners from the EU and Latin America an opportunity to build professional relationships and mutual trust; essential to establishing and operating successful JITs. The training further strengthened mutual understanding and operational links between the two regions, highlighting the value of JITs in tackling cross-border criminal networks.

UK and Allies urge critical sectors to improve defences against Russian intelligence targeting

Source: United Kingdom National Cyber Security Centre

  • The UK and international allies strongly urge action to better defend against the threat from Russian state intelligence actors
  • Advice follows the opportunistic exploitation of inadequately configured routers and network devices by Centre 16 of Russia’s Federal Security Service (FSB)
  • Warning comes as the UK sanctions Russian state and criminal networks for cyber and hybrid operations and calls out the FSB for a reckless attack on Poland’s energy grid.

Organisations in critical infrastructure sectors are being supported to better understand and defend against malicious activity, as the UK and international partners today call out techniques used by Russian Intelligence Services

Alongside 18 agencies from 12 countries, the National Cyber Security Centre (NCSC) – a part of GCHQ – has published a new advisory highlighting the methods of Federal Security Service (FSB) Centre 16 cyber actors, who are exploiting vulnerable routers and opportunistically targeting networks belonging to critical national infrastructure (CNI) globally.

Sectors most at risk from this global targeting, including communications, defence, energy, financial services, government and healthcare, are subsequently being urged to take action. This includes recommendations to use SNMPv3 and disable legacy SNMP versions, implement strong and unique passwords for network devices, and restrict access to management protocols through appropriate access controls.

Centre 16, also known as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra, has been seen hunting for vulnerable routers by scanning the internet for devices that still use default or weak Simple Network Management Protocol (SNMP) passwords and community strings.

Whilst the actor primarily uses SNMP scans to locate and compromise vulnerable routers, they have also exploited well-known vulnerabilities relating to Cisco devices, Cisco’s Smart Install (SMI) feature and web-portal flaws to gain control of network devices.

Jonathon Ellison, NCSC Director of National Resilience said:

The NCSC, alongside our international partners, have repeatedly exposed the advanced tools and coordinated campaigns of Russian cyber actors who persistently seek to exploit any vulnerability they encounter.

“Today’s joint advisory provides decisive, actionable directions from the global security community that network defenders should implement to protect against Russian Intelligence operations and secure the UK’s critical infrastructure.

“I’d strongly encourage all organisations, especially those entrusted with UK critical networks, to adopt these recommended measures immediately, thereby reducing the risk of compromise.

Organisations are also encouraged to obtain Cyber Essentials certification, the government-backed scheme for all organisations to show they meet the recognised UK minimum standard for cyber security, and make use of the updated Cyber Assessment Framework, enabling them to assess their security maturity, address vulnerabilities and build their resilience against increasing threats.

The advisory has been published on the same day as the UK government has sanctioned 24 individuals and entities behind destructive cyber and hybrid operations including cyber criminals involved in proxy networks linked to the Russian Intelligence Services.

The UK together with EU member states has also today formally attributed the December 2025 attack on Poland’s energy grid to Russia’s FSB Centre 16 – an attack that if it had been successful could have caused 500,000 civilians to lose electricity.

The NCSC has co-sealed this new advisory alongside agencies from Australia, Canada, Czech Republic, Denmark, Estonia, Finland, France, Italy, New Zealand, Poland, Sweden and the United States. 

It can be read on the NSA website: https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF 
 

Western Balkans and EU prosecutors strengthen cooperation against migrant smuggling in Vienna

Source: Eurojust

Hosted by the Austrian Ministry of Justice and chaired by the Chair of Eurojust’s Focus Group on Migrant Smuggling, the meeting was organised by the Western Balkan Criminal Justice project at Eurojust, with contributions from the EU4FAST project.

Participants exchanged views on recent developments and practical challenges, including judicial cooperation issues, evolving criminal trends and innovative investigative approaches. Discussions focused on the prosecution of cross-border smuggling networks, cooperation through EMPACT, the use of drones for evidence gathering and the growing use of Hawala systems by criminal groups.

The programme also included a visit to the Austrian Joint Operational Office, providing an opportunity to discuss closer cooperation between judicial and law enforcement authorities. The support available through the Western Balkan Criminal Justice project, including operational funding, and through EU4FAST, including advisory support, was also presented.

By bringing together practitioners from different jurisdictions, the meeting helped reinforce mutual trust, facilitate the exchange of expertise and promote closer operational cooperation across the Western Balkans and the European Union.

Eurojust supports increased cooperation on Sky ECC investigations among France and Western Balkans

Source: Eurojust

A major operation to decrypt Sky ECC in March 2021 by Belgian, French and Dutch authorities, coordinated by Eurojust and Europol, unlocked hundreds of million of messages exchanged between criminals. Since then, judicial authorities and law enforcement have started hundreds of investigations around the world using Sky ECC evidence and were able to successfully take action against some of the world’s most dangerous criminal networks. The French National Desk at Eurojust have supported the execution of many judicial requests for Sky ECC data. To coordinate the judicial requests from the Western Balkans to France and strengthen cooperation on cross-border investigations using Sky ECC data within the region, Operation Flying Bride was started by Eurojust through its French National Desk and Western Balkans Criminal Justice Project.

To kickstart the initiative, a first meeting was organised at Eurojust in April 2026 where prosecutors from the Western Balkans, Slovenia, Croatia and representatives from the French National Public Prosecution Office against Organised Crime (PNACO) came together to discuss how cross-border investigations will be coordinated and how prosecutors could obtain Sky ECC data from France. 

To continue the cooperation, representatives from the six prosecution offices of the Western Balkans region, Croatia and Slovenia were invited on 7 and 8 July in Paris to the PNACO to identify cooperation needs and facilitate the judicial requests to France. More than 18 bilateral meetings took place to discuss ongoing and potential new cases linked to Sky ECC evidence.

Cyber Essentials Pathways: from proof of concept to cyber confidence

Source: United Kingdom National Cyber Security Centre

Large organisations often tell us the same thing. “We want to achieve Cyber Essentials Plus, but the way we operate does not align with the technical controls that Cyber Essentials Plus requires.” 

Complex architectures, legacy systems, and layered security requirements mean that a purely prescriptive approach can sometimes feel more like a constraint than something that enables better security outcomes.

Pathways was designed to respond to this challenge, providing a way for organisations to demonstrate that their controls deliver equivalent (or better) protection, even where they differ from the standard Cyber Essentials model.

Essentially, Pathways introduces flexibility without weakening trust.

It’s all about giving organisations more than one way to demonstrate that they are achieving the same overall outcome, rather than implementing the individual security controls. It effectively provides an ‘alternative pathway’ to achieving Cyber Essentials Plus certification, without compromising the integrity of the scheme. 

Over the last 18 months, we’ve been running the Cyber Essentials Pathways Proof of Concept (PoC) to see if organisations can demonstrate that their alternate controls manage the risks covered by Cyber Essentials. This culminated in one of the PoC organisations demonstrating that they could achieve Cyber Essentials plus using the Pathways approach.

In this blog we’ll explain what worked with the PoC, what didn’t, what needs to change, and what happens next.

Over 5,800 arrests, USD 293 million intercepted in global fraud bust

Source: Interpol (news and events)

LYON, France – A global anti-fraud operation involving 97 countries and territories has led to the arrest of 5,811 individuals and the interception of USD 293 million in illicit assets.

Operation First Light 2026 (15 Jan 2026 – 30 April 2026), coordinated by INTERPOL, focused on combatting social engineering scams and associated money laundering activities.

Social engineering is a broad term that refers to techniques that exploit a person’s trust to obtain money or confidential information. This type of fraud can include business email compromise, sextortion, as well as romance, impersonation or investment scams.

After an initial period of intelligence collection and exchange, participating countries took part in more than three months of operational activities. This included pro-active action against high-value targets, raiding identified premises, blocking or freezing bank accounts and virtual wallets, requesting INTERPOL Notices and Diffusions and proactively utilizing INTERPOL’s Global Rapid Intervention of Payments (I-GRIP), a stop-payment mechanism that facilitates the swift blocking of illicit financial flows of both fiat and virtual assets.

Over 142,000 victims globally were identified during Operation First Light 2026, highlighting the extent to which social engineering scams and fraud have escalated into a major transnational threat, affecting individuals, businesses and governments. Other significant results include:

– 152,808 cases analyzed
– 31,014 bank accounts blocked
– 23,715 cases solved
– 15,606 suspects identified
– 99 Notices and Diffusions issued

In Eswatini, police dismantled a criminal network running illegal online gambling, money laundering and elaborate impersonation scams.

Authorities in Eswatini seized 240 electronic devices, foreign currency and a realistic replica of a Brazilian police station, complete with fake uniforms, signage and equipment.

Sri Lankan authorities carried out multiple raids and enforcement actions as part of Operation First Light.

During the three-month operation, hundreds of suspects were arrested in Sri Lanka for their involvement in cyber scam centres.

An INTERPOL Operational Support Team is deployed to support authorities in Eswatini.

Tomonobu Kaya, Director of the INTERPOL Financial Crime and Anti-Corruption Centre, said:

“Social engineering scams continue to pose a significant threat to our society. Criminal syndicates exploit human psychology to manipulate their targets, and no nation can stay safe unless all countries are equipped and committed to jointly fighting back. INTERPOL is dedicated to supporting member countries in building a comprehensive, coordinated strategy to tackle cyber-enabled financial crimes, organized criminal networks and the money laundering that fuels them.”

From scam centres to money laundering: key cases reveal full spectrum of financial fraud

• In Eswatini, police arrested 82 people and dismantled a criminal network running illegal online gambling, money laundering and elaborate impersonation scams. Authorities seized 240 electronic devices, foreign currency and a realistic replica of a Brazilian police station, complete with fake uniforms, signage and equipment. Posing as Brazil’s Federal Police via video call, the scammers deceived their targets into believing they were victims of a crime, tricking them into transferring funds for “safekeeping,” which were then stolen.

Due to the scale and complexity of the digital evidence, an INTERPOL Operational Support Team was deployed at the request of authorities in Eswatini to provide forensic analysis of the seized devices.

• In Thailand, police made two arrests and uncovered a money laundering scheme that funneled illicit funds from romance scams into various cryptocurrencies, utilizing cross-chain token swaps to obscure the financial trail. Investigations showed that the digital wallet of one of the suspects, aged 20, had processed more than USD 122.5 million in just 10 months.

• Authorities in Singapore and Oman utilized I-GRIP to block a USD 6.6 million illicit transfer linked to a Business Email Compromise scam. In this case, a Singapore-based commodity trading firm was targeted by criminals impersonating a supplier.

• Police in Macao, China carried out anti-fraud community outreach as part of Operation First Light 2026. During the initiative, police discovered that one of the public participants was actively being manipulated by a criminal syndicate.  Impersonating public officials, the perpetrators had convinced the victim to transfer money under the guise of a fraud investigation. Thanks to the public campaign, police were able to intervene before the victim sent close to USD 372,000 to the fraudsters.

• Authorities in Palau deported 22 individuals for their role in two connected scam centres being conducted from hotels. The suspects utilized cryptocurrency and illegal gambling websites to target victims in foreign countries, operating a range of online fraud schemes.

Notes to editors

Operation First Light is funded by China’s Ministry of Public Security and supported by the participation of three regional policing bodies: ASEANAPOL, GCCPOL, and Europol.
Participating countries: Albania, Anguilla (UK), Antigua and Barbuda, Argentina, Armenia, Australia, Austria, Bahrain, Bangladesh, Belize, Bhutan, Bosnia and Herzegovina, Botswana, Brazil, Brunei, Bulgaria, Burkina Faso, Cambodia, Cameroon, Canada, Chile, China, Colombia, Democratic Republic of the Congo , Costa Rica, Czechia, Denmark, Ecuador, Eswatini, France, Gambia, Ghana, Gibraltar (UK), Greece, Honduras, Hong Kong (China), Hungary, India, Indonesia, Iraq, Ireland, Jamaica, Japan, Kazakhstan, Kuwait, Lao PDR, Latvia, Lebanon, Lesotho, Libya, Liechtenstein, Lithuania, Macao (China), Malawi, Malaysia, Maldives, Mongolia, Montenegro, Morocco, Myanmar, Namibia, Niger, Nigeria, North Macedonia, Norway, Oman, Pakistan, Palau, Palestine, Paraguay, Philippines, Poland, Portugal, Qatar, Republic of Korea, Romania, Russia, Rwanda, Seychelles, Singapore, Slovakia, South Africa, South Sudan, Spain, Sri Lanka, Sudan, Sweden, Tanzania, Thailand, Türkiye, United Arab Emirates, United Kingdom, United States, Uruguay, Viet Nam, Zambia, Zimbabwe.