SEV3 — ElevatedCLOSEDCyber✓ Corroborated · 5 sources8d ago

Russian State-Sponsored Phishing Campaign Targeting Zimbra Collaboration Suite — Denver Operations Footprint

Russian state-supported cyber actors are conducting an active phishing campaign targeting users of Zimbra Collaboration Suite, a widely deployed email and collaboration platform used across enterprise and BPO environments. Denver hosts approximately 360,000 contact-center, back-office, and knowledge-worker seats, making it a high-density target where credential compromise could disrupt communications, access controls, and service-delivery continuity. Operations leaders should verify Zimbra patch levels and MFA enforcement, issue phishing-awareness reminders to staff, and confirm whether the Panduit IntraVUE network infrastructure monitoring tool — flagged in the same signal cluster — is properly segmented and access-controlled given its network visibility scope. Affected regions: Denver, Dfw, Okc

Impact Summary

Russian state-supported cyber actors are conducting an active phishing campaign targeting users of Zimbra Collaboration Suite, a widely deployed email and collaboration platform used across enterprise and BPO environments. Denver hosts approximately 360,000 contact-center, back-office, and knowledge-worker seats, making it a high-density target where credential compromise could disrupt communications, access controls, and service-delivery continuity. Operations leaders should verify Zimbra patch levels and MFA enforcement, issue phishing-awareness reminders to staff, and confirm whether the Panduit IntraVUE network infrastructure monitoring tool — flagged in the same signal cluster — is properly segmented and access-controlled given its network visibility scope.

Domain
Cyber
Opened By
watchkeeper
Jul 24, 2026, 08:00 PM UTC
Validated By
auto
Jul 24, 2026, 08:00 PM UTC
Event Cluster
8 events
OVIX Score
10.0
Closed
watchkeeper-auto(resolved)
Jul 26, 2026, 02:00 PM UTC

Timeline10

Incident openedby watchkeeperJul 24, 2026, 08:00 PM UTC
Declared from 2 signals. OVIX 10. News 1. BPO 3. High-confidence (auto).
Severity validatedby autoJul 24, 2026, 08:00 PM UTC
Auto-validated: SEV3 per policy.
Note addedby watchkeeperJul 24, 2026, 08:00 PM UTC
External corroboration: corroborated (5 sources via Exa). cisa.gov, media.defense.gov, bleepingcomputer.com, unit42.paloaltonetworks.com, proofpoint.com
Note addedby watchkeeperJul 24, 2026, 10:00 PM UTC
Merged new cluster (1 signals, OVIX 10, regions Okc) — same underlying entity. Entity identity vendor:russian+state — collapsed across regions (agents-036 Gate 3, <14d window). Re-emission of already-tracked events only — material clock NOT advanced (agents-046 G5, quiet clock continues toward close).
Note addedby watchkeeperJul 24, 2026, 10:30 PM UTC
Merged new cluster (1 signals, OVIX 10, regions Okc) — same underlying entity. Entity identity vendor:russian+state — collapsed across regions (agents-036 Gate 3, <14d window). Re-emission of already-tracked events only — material clock NOT advanced (agents-046 G5, quiet clock continues toward close).
Note addedby watchkeeperJul 25, 2026, 01:30 AM UTC
Merged new cluster (1 signals, OVIX 10, regions Dfw) — same underlying entity. Entity identity vendor:operations+footprint — collapsed across regions (agents-036 Gate 3, <14d window). 1 genuinely-new material event — material clock advanced.
Note addedby watchkeeperJul 25, 2026, 02:01 AM UTC
Merged new cluster (1 signals, OVIX 10, regions Dfw) — same underlying entity. Entity identity vendor:operations+footprint — collapsed across regions (agents-036 Gate 3, <14d window). Re-emission of already-tracked events only — material clock NOT advanced (agents-046 G5, quiet clock continues toward close).
Note addedby watchkeeperJul 25, 2026, 01:30 PM UTC
Merged new cluster (2 signals, OVIX 10, regions Dfw) — same underlying entity. Entity identity vendor:russian+state — collapsed across regions (agents-036 Gate 3, <14d window). Re-emission of already-tracked events only — material clock NOT advanced (agents-046 G5, quiet clock continues toward close).
Note addedby watchkeeperJul 25, 2026, 02:01 PM UTC
Merged new cluster (2 signals, OVIX 10, regions Dfw) — same underlying entity. Entity identity vendor:russian+state — collapsed across regions (agents-036 Gate 3, <14d window). Re-emission of already-tracked events only — material clock NOT advanced (agents-046 G5, quiet clock continues toward close).
Incident closedby watchkeeperJul 26, 2026, 02:00 PM UTC
Auto-closed: no new material events within 36h for this incident.

Evidence / Why this?

Traced to source — read-onlyUpdated Jul 25, 02:01 PM UTC
Why declaredmergeDeterministic
Incident dedup / merge keys (entity, episode, network, region+title)v4
Checked in order against open same-domain incidents (never an aggregate-titled bucket): (1) ENTITY key, region-independent, incident active <14d (updated_at): shared CVE id, OR (cyber) >=2 shared distinctive vendor/product tokens (1 suffices when it carries a digit, i.e. a product model), OR (travel, agents-039) same travel operator/system key (travelSystemKey — airline/ATC/GDS/rail identity with a disruption cue), OR same network/AS key (agents-022). (2) EPISODE key (weather/environmental/disaster + travel per agents-039 + environmental air-quality per agents-040), incident active <7d: same hazard family (weather: heat/tornado/flood/cyclone/winter/wildfire/storm; travel: strike/ground_stop/airspace/it_outage/transit; environmental air-quality: air_quality/smoke — a multi-day wildfire-smoke wave, split cleanly from the weather wildfire FIRE family) AND same macro-region (eu | us/<census region> | country code) — a multi-day strike series, rolling ground stop, or smoke wave refreshes ONE incident, not dailies. (3) Legacy region-overlap + title-word dedup, active <24h (v5 unchanged). Merge unions affected_regions + related_signal_ids + material_event_keys, bumps event_count, renders the merged regions into the description ("Affected regions:" trailer), logs stage=declare decision=merge (engine deterministic), and unions the evidence projection’s signal sources. agents-046 (v4): a merge advances the material clock (last_material_event_at) ONLY when it brings GENUINELY-NEW material event keys (newMaterialKeys over the incident's material_event_keys, agents-010 Fault B) — an EVOLVING situation. Re-emission / continued press coverage of already-tracked events accumulates ids/regions/event_count but HOLDS the material clock (agents-019 §C), so a wallpaper advisory's quiet clock can finally elapse toward close. This is the evolving-vs-wallpaper discriminator the earned-rights lifecycle backstop (incident_lifecycle v1) reads.
key
vendor:russian+state
via
entity
domain
cyber
regions
["Dfw"]
signal ids
[34319,34323]
max severity
10
union regions
["Denver","Dfw","Okc"]
incident age h
0
new material keys
0
material clock advanced
no
Why SEV3SEV3score 3Deterministic
Incident severity level (SEV1–SEV4) at declarationv5
agents-043 (v4): a Gate A workforce-footprint declaration (geoExposureFloor) is scored on VALUE = magnitude × footprint via workforceFootprintSeverity, NOT the base mapSevLevel: catastrophic (sev>=9) × MAJOR hub (bpo>=3) → SEV1 (the Manila 7.0-quake worked example — this deliberately supersedes the single-event cap per ALERTING-PHILOSOPHY.md / Ted's criteria); sev>=9 × moderate hub (bpo==2) → SEV2; sev>=8 × bpo>=2 → SEV3. SEV1/SEV2 remain human-gated at declaration (validation pending). Every other path keeps the base mapSevLevel below unchanged. agents-046 (v5): the named-tropical-system active-threat arm (workforceFootprintSeverity tropicalActiveThreat, sev 7–7.99 × bpo>=2) → SEV3 — a tracked storm approaching a footprint coast is a genuine 0–72h disruption a WFM leader pre-positions for (same SEV3 honesty as the acute-severe-weather floor). The flag is a no-op for sev>=8 (those hit the higher branches), so hurricanes are unaffected. Base: SEV2 if sev>=9 AND news>=2 AND bpo>=1; else SEV3 if sev>=8 AND (news>=1 OR bpo>=1); else SEV4. Acute severe-weather (agents-028): if sev>=9 floor to SEV3 (SEV2→SEV3); minor/transient watches+advisories drop SEV2/SEV3→SEV4. Single-event cap: any SEV2 caps to SEV3 absent sustained multi-day BPO-region corroboration (SEV2 promotion is human-gated via revalidation). Systemic-travel floor (agents-039): a travelSystemicFloor declaration (multi-signal aggregate on member-relevant geography, sev 6-7 by design) floors SEV4→SEV3 — a region-level operational disruption, same honesty argument as the acute-weather SEV3 floor. It never raises anything to SEV2: SEV2 keeps its base intensity+news+human gating. Environmental air-quality floor (agents-040): an enviroAirQualityFloor declaration (multi-city cumulative air-quality/smoke aggregate on member-relevant geography, sev 6-7 by design) likewise floors SEV4→SEV3, and never raises anything to SEV2. score = numeric SEV (1=most severe … 4); SEV3/SEV4 auto-validate, SEV1/SEV2 require human validation.
domain
cyber
bpo score
3
news score
1
persistent
no
max severity
10
auto validated
yes
acute weather floor
no
travel systemic floor
no
Geo Provenance
Tierapprox
Sourcenone
Deterministic
Sources✓ Corroborated · 5 sources
[Denver] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel
[Denver] cyber 10.0 — Panduit IntraVUEsentinel
Russian State-Supported Cyber Actors Conduct Phishing ...cisa.govRussian State-Supported Cyber Actors Conduct Phishing ...media.defense.govRussian hackers exploit Zimbra zero-click flaw for email theftbleepingcomputer.comRussian Global Webmail Espionageunit42.paloaltonetworks.comTA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint USproofpoint.com
[Okc] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel
[Dfw] cyber 10.0 — MZ Automation libIEC61850sentinel
[Dfw] cyber 10.0 — MZ Automation libIEC61850sentinel
[Dfw] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel

Related Signals20

[Denver] cyber 10.0 — MZ Automation libIEC61850sentinel6d ago[Dfw] cyber 10.0 — MZ Automation libIEC61850sentinel6d ago[Dfw] cyber 10.0 — MZ Automation libIEC61850sentinel6d ago[Denver] cyber 10.0 — MZ Automation libIEC61850sentinel6d ago[Okc] cyber 10.0 — MZ Automation libIEC61850sentinel6d ago[Dfw] cyber 10.0 — MZ Automation libIEC61850sentinel7d ago[Denver] cyber 10.0 — MZ Automation libIEC61850sentinel7d ago[Denver] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel7d ago[Dfw] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel7d ago[Denver] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel7d ago[Dfw] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel7d ago[Dfw] cyber 10.0 — MZ Automation libIEC61850sentinel7d ago[Denver] cyber 10.0 — MZ Automation libIEC61850sentinel7d ago[Denver] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel7d ago[Dfw] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel7d ago[Denver] cyber 10.0 — MZ Automation libIEC61850sentinel7d ago[Dfw] cyber 10.0 — MZ Automation libIEC61850sentinel7d ago[Denver] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel7d ago[Dfw] cyber 10.0 — MZ Automation libIEC61850sentinel7d ago[Denver] cyber 10.0 — MZ Automation libIEC61850sentinel7d ago

External Corroboration

✓ Corroborated · 5 sourcesChecked Jul 24, 2026, 08:00 PM UTC
Russian State-Supported Cyber Actors Conduct Phishing ...cisa.govJul 23, 2026, 08:00 PM UTCRussian State-Supported Cyber Actors Conduct Phishing ...media.defense.govJul 21, 2026, 08:00 PM UTCRussian hackers exploit Zimbra zero-click flaw for email theftbleepingcomputer.comJul 23, 2026, 08:00 PM UTCRussian Global Webmail Espionageunit42.paloaltonetworks.comJul 23, 2026, 12:00 AM UTCTA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint USproofpoint.comJul 23, 2026, 12:00 AM UTC

Affected Regions

DenverDfwOkc