The phishing email that needs no click

· Carl Heaton · Security

Ask most business owners what their defence against phishing is, and the answer comes back the same: we train our staff not to click. It is sound advice, and for years it has done real work. A warning the UK's National Cyber Security Centre issued this week, alongside its Five Eyes partners and agencies across Europe, quietly moves the goalposts. The attack it describes needs no click at all. Viewing the email is enough to be compromised.

What "zero-click" means

The NCSC named the operation Laundry Bear and the technique beehive, and attributes it with confidence to the Russian state. It has already stolen data from organisations in defence, education, energy, government, law enforcement, and media.

In an ordinary phishing attack, the email is bait. It only works if the recipient does something: clicks a link, opens an attachment, types a password into a fake page. Every step of your staff training targets that moment of action. A zero-click attack removes the moment. As Computer Weekly reported, the victim only has to view the malicious email in a vulnerable webmail system for the attacker to gain quiet, lasting access to their mailbox. No link, no attachment, no mistake by the user.

The specific flaw it exploits, tracked as CVE-2025-66376, sits in Zimbra Collaboration Suite, an email platform Zimbra patched back in November 2025. Most UK small businesses do not run Zimbra, so the immediate instruction, patch it now if you do, is narrow. The reason this is worth your attention is broader, and the NCSC said so plainly: the technique can be adapted to other email software, and as organisations patch Zimbra the attackers will very likely turn to the next platform. The method is the story, not the one product.

Why staff training is no longer the whole answer

The uncomfortable part is what this does to the "we train our staff not to click" defence. That defence assumes there is a click to avoid. When there is not, an alert, well-trained employee is compromised exactly as fast as a careless one. Training remains worth doing, but it can no longer be the only layer you rely on.

Dray Agha of security firm Huntress put it directly: a zero-click attack "completely bypasses traditional employee security training and gives state-backed hackers a silent, invisible backdoor into sensitive communications without the victim ever making a mistake." His conclusion is the one to take away: "Organisations shouldn't just rely on their staff acting as a human firewall. Rapid software patching, coupled with layered technical defences, is the only reliable safety net."

There is a second detail worth noting. The NCSC's analysis suggests the attackers used AI tools to help write the code behind this technique. That is the practical face of a trend we keep returning to: the effort required to build a novel attack is falling, which means more novel attacks, faster, against everyone rather than just the largest targets.

What to do this quarter

You cannot train your way out of an attack that needs no click. You can build the layers that catch it anyway.

Patch email and browsers promptly, not eventually. Zero-click attacks live or die on unpatched software, because the flaw is doing the work the user would otherwise have to. If you run your own mail server, updates to it belong at the top of the list, not the bottom. For most firms on Microsoft 365 or Google Workspace, the provider patches the platform, but the browsers and mail apps your staff read email in are yours to keep current. Turn on automatic updates and check they are actually applying.

Assume one layer will fail and add another. If simply viewing an email can hand over a mailbox, the mailbox itself needs a second lock. Sign-in that a stolen password alone cannot satisfy, ideally passkeys, means a compromised session is far harder to turn into ongoing access. Alerting on unusual mailbox behaviour, a login from a new country, a rule that quietly forwards mail elsewhere, gives you a chance to notice.

Ask your IT provider two questions. First: how quickly are the systems that read our email actually patched, and how would we know if one fell behind? Second: if an attacker got into one mailbox without anyone clicking anything, what would stop them, and what would tell us? If the answers lean entirely on staff not clicking, that is the gap this warning is about.

How Steelwise can help

Working out where a single failure would let an attacker in, and adding the layers that catch what training cannot, is the kind of review we do. Get in touch.

Further reading

← All filings