N

News

How Viewing One Email Could Hand Hackers Your Inbox

How much can an attacker steal if someone only views an email? In a recent incident, the answer includes 90 days of messages, account credentials, two-factor authentication tokens and an organisation's contact directory.

On 24 July 2026, the Australian Signals Directorate joined international partners in warning organisations about a phishing campaign targeting vulnerable versions of Zimbra Collaboration Suite. The campaign has been active since at least July 2025 and has targeted government, education, energy, law enforcement, media, technology, non-government organisations and the defence supply chain.

What makes it different is the trigger. The recipient may not need to click a link, open an attachment or enter credentials. Viewing the malicious email in a vulnerable version of Zimbra webmail may be enough to begin the compromise.

Viewing the Email Can Trigger the Attack

The campaign exploits CVE-2025-66376, a vulnerability in how affected versions of Zimbra webmail process email content. The malicious message contains code that runs when the email is viewed.

According to the joint international advisory, the exploit attempts to steal:

  • The victim's last 90 days of emails

  • The user's email address and password

  • The organisation's Global Address List

  • Two-factor authentication tokens

  • A newly created application passcode

The attackers also attempt to maintain access to the compromised account. That gives them current conversations, trusted contacts and account information they can use for further targeting.

Some malicious emails have been sent from previously compromised accounts. A message from a legitimate account is harder for the recipient to recognise as suspicious and may be less obvious to controls looking for conventional phishing.


“Don't Click” Isn't Enough

Security awareness training still matters. People should check senders, question unexpected requests and report suspicious messages. Those behaviours cannot stop an exploit triggered by viewing an email in a vulnerable service.

Most phishing attacks rely on persuasion. The attacker needs someone to click, download, approve or disclose something. This campaign removes that step. The person can use the platform normally and still be compromised.

This issue applies specifically to vulnerable versions of Zimbra webmail. It does not mean viewing any email on any platform will expose an inbox. The broader lesson is that user awareness cannot compensate for vulnerable software, and it cannot detect everything that happens after an attacker gains access.


The Patch Has Been Available Since November

CVE-2025-66376 was patched in November 2025. Eight months later, agencies warned that it was still being successfully exploited.

A released patch does not protect a system until it is deployed. Updates may be delayed, older instances may sit outside normal maintenance, or an organisation may not have a complete record of its internet-facing services. Any unpatched instance remains an entry point.

Email platforms hold valuable information: current conversations, internal relationships, account notifications and the context needed to make later attacks more convincing. That makes patching an exposed mail service a security priority, not a routine maintenance task.

Patching also does not show whether the service was compromised before the update. That requires logs, published indicators of compromise and enough monitoring capacity to investigate what happened.


What You Need to Check

The ASD's Australian Cyber Security Centre guidance recommends updating Zimbra, enabling multi-factor authentication and monitoring accounts and network activity for unauthorised access or credential theft.

A complete response includes:

  • Confirming exposure. Security teams know whether Zimbra is in use, which versions are deployed and which instances are accessible from the internet.

  • Applying current updates. Vulnerable systems are patched using the latest vendor guidance, and deployment is verified.

  • Enabling multi-factor authentication. MFA adds protection to Zimbra accounts, but it supports patching rather than replacing it.

  • Reviewing relevant activity. Email, identity, authentication and network logs are checked against the indicators of compromise in the advisory.

  • Removing persistent access. A suspected compromise is treated as more than a password reset. Active sessions, authentication tokens, application passcodes and account changes are also reviewed.

These are the controls our SecOps team looks for when helping organisations protect trusted, internet-facing services that hold sensitive information.


Security Must Cover the Service and the Account

When viewing an email may be enough, phishing defence cannot begin and end with the click.

The focus shifts from whether every person can recognise every threat to whether the organisation can maintain its services, monitor account activity and investigate quickly. Email, identity and network signals need to be available and reviewed together before one compromised account becomes a wider incident.

Through Lumara, our SecOps team brings continuous monitoring, investigation and 24/7 Australian security operations into one operating picture. We help connect email, identity and network signals, identify suspicious activity and determine what happened after an initial compromise.

Can your team see the signs of compromise, identify where the gaps are and respond before one account becomes a wider incident? Let's look at how Lumara can strengthen monitoring and response around the critical services your organisation relies on.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.