SEV3 — ElevatedOPENCyberONGOING✓ Corroborated · 5 sources2d ago

Russian State-Sponsored Phishing Campaign Targeting Zimbra Collaboration Suite — Des Moines

Russian state-supported actors are conducting active phishing campaigns against users of Zimbra Collaboration Suite, with a companion advisory recommending isolation of vital systems. Des Moines carries meaningful knowledge-worker and back-office density (~78,000+ seats combined), where Zimbra is commonly deployed as an enterprise email and collaboration platform. Operations leaders should verify whether Zimbra is in use across any in-house or outsourced sites, enforce phishing-awareness protocols, and confirm network segmentation of critical workforce-management and telephony infrastructure. Affected regions: Des Moines, Denver

Impact Summary

Russian state-supported actors are conducting active phishing campaigns against users of Zimbra Collaboration Suite, with a companion advisory recommending isolation of vital systems. Des Moines carries meaningful knowledge-worker and back-office density (~78,000+ seats combined), where Zimbra is commonly deployed as an enterprise email and collaboration platform. Operations leaders should verify whether Zimbra is in use across any in-house or outsourced sites, enforce phishing-awareness protocols, and confirm network segmentation of critical workforce-management and telephony infrastructure.

Domain
Cyber
Opened By
watchkeeper
Jul 29, 2026, 07:30 PM UTC
Validated By
auto
Jul 29, 2026, 07:30 PM UTC
Event Cluster
3 events
OVIX Score
10.0
Community Validation

Sign in to confirm whether your operations are affected.

0 confirmed affected0 not affected

Timeline4

Incident openedby watchkeeperJul 29, 2026, 07:30 PM UTC
Declared from 2 signals. OVIX 10. News 0. BPO 1. LLM-confirmed. Flagged persistent (ongoing situation).
Severity validatedby autoJul 29, 2026, 07:30 PM UTC
Auto-validated: SEV3 per policy.
Note addedby watchkeeperJul 29, 2026, 07:30 PM UTC
External corroboration: corroborated (5 sources via Exa). unit42.paloaltonetworks.com, cyberscoop.com, cyberinsider.ca, safebreach.com, cybersecurity-review.com
Note addedby watchkeeperJul 29, 2026, 10:00 PM UTC
Merged new cluster (2 signals, OVIX 10, regions Denver) — same underlying entity. Entity identity vendor:russian+state — collapsed across regions (agents-036 Gate 3, <14d window). 1 genuinely-new material event — material clock advanced.

Evidence / Why this?

Traced to source — read-onlyUpdated Jul 29, 10:00 PM UTC
Why declaredmergeDeterministic
Incident dedup / merge keys (entity, episode, network, region+title)v4
Checked in order against open same-domain incidents (never an aggregate-titled bucket): (1) ENTITY key, region-independent, incident active <14d (updated_at): shared CVE id, OR (cyber) >=2 shared distinctive vendor/product tokens (1 suffices when it carries a digit, i.e. a product model), OR (travel, agents-039) same travel operator/system key (travelSystemKey — airline/ATC/GDS/rail identity with a disruption cue), OR same network/AS key (agents-022). (2) EPISODE key (weather/environmental/disaster + travel per agents-039 + environmental air-quality per agents-040), incident active <7d: same hazard family (weather: heat/tornado/flood/cyclone/winter/wildfire/storm; travel: strike/ground_stop/airspace/it_outage/transit; environmental air-quality: air_quality/smoke — a multi-day wildfire-smoke wave, split cleanly from the weather wildfire FIRE family) AND same macro-region (eu | us/<census region> | country code) — a multi-day strike series, rolling ground stop, or smoke wave refreshes ONE incident, not dailies. (3) Legacy region-overlap + title-word dedup, active <24h (v5 unchanged). Merge unions affected_regions + related_signal_ids + material_event_keys, bumps event_count, renders the merged regions into the description ("Affected regions:" trailer), logs stage=declare decision=merge (engine deterministic), and unions the evidence projection’s signal sources. agents-046 (v4): a merge advances the material clock (last_material_event_at) ONLY when it brings GENUINELY-NEW material event keys (newMaterialKeys over the incident's material_event_keys, agents-010 Fault B) — an EVOLVING situation. Re-emission / continued press coverage of already-tracked events accumulates ids/regions/event_count but HOLDS the material clock (agents-019 §C), so a wallpaper advisory's quiet clock can finally elapse toward close. This is the evolving-vs-wallpaper discriminator the earned-rights lifecycle backstop (incident_lifecycle v1) reads.
key
vendor:russian+state
via
entity
domain
cyber
regions
["Denver"]
signal ids
[35752,35779]
max severity
10
union regions
["Des Moines","Denver"]
incident age h
0
new material keys
1
material clock advanced
yes
Why SEV3SEV3score 3Deterministic
Incident severity level (SEV1–SEV4) at declarationv5
agents-043 (v4): a Gate A workforce-footprint declaration (geoExposureFloor) is scored on VALUE = magnitude × footprint via workforceFootprintSeverity, NOT the base mapSevLevel: catastrophic (sev>=9) × MAJOR hub (bpo>=3) → SEV1 (the Manila 7.0-quake worked example — this deliberately supersedes the single-event cap per ALERTING-PHILOSOPHY.md / Ted's criteria); sev>=9 × moderate hub (bpo==2) → SEV2; sev>=8 × bpo>=2 → SEV3. SEV1/SEV2 remain human-gated at declaration (validation pending). Every other path keeps the base mapSevLevel below unchanged. agents-046 (v5): the named-tropical-system active-threat arm (workforceFootprintSeverity tropicalActiveThreat, sev 7–7.99 × bpo>=2) → SEV3 — a tracked storm approaching a footprint coast is a genuine 0–72h disruption a WFM leader pre-positions for (same SEV3 honesty as the acute-severe-weather floor). The flag is a no-op for sev>=8 (those hit the higher branches), so hurricanes are unaffected. Base: SEV2 if sev>=9 AND news>=2 AND bpo>=1; else SEV3 if sev>=8 AND (news>=1 OR bpo>=1); else SEV4. Acute severe-weather (agents-028): if sev>=9 floor to SEV3 (SEV2→SEV3); minor/transient watches+advisories drop SEV2/SEV3→SEV4. Single-event cap: any SEV2 caps to SEV3 absent sustained multi-day BPO-region corroboration (SEV2 promotion is human-gated via revalidation). Systemic-travel floor (agents-039): a travelSystemicFloor declaration (multi-signal aggregate on member-relevant geography, sev 6-7 by design) floors SEV4→SEV3 — a region-level operational disruption, same honesty argument as the acute-weather SEV3 floor. It never raises anything to SEV2: SEV2 keeps its base intensity+news+human gating. Environmental air-quality floor (agents-040): an enviroAirQualityFloor declaration (multi-city cumulative air-quality/smoke aggregate on member-relevant geography, sev 6-7 by design) likewise floors SEV4→SEV3, and never raises anything to SEV2. score = numeric SEV (1=most severe … 4); SEV3/SEV4 auto-validate, SEV1/SEV2 require human validation.
domain
cyber
bpo score
1
news score
0
persistent
yes
max severity
10
auto validated
yes
acute weather floor
no
travel systemic floor
no
Geo Provenance
Tierapprox
Sourcenone
Deterministic
Sources✓ Corroborated · 5 sources
[Des Moines] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel
[Des Moines] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel
Russian Global Webmail Espionageunit42.paloaltonetworks.comRussian espionage group using novel Zimbra exploit to steal sensitive data from Western countries | CyberScoopcyberscoop.comRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite | Cyber Insidercyberinsider.caCISA AA26-204A: Russian Zimbra Phishing | SafeBreach Coveragesafebreach.comRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite - Cyber Security Reviewcybersecurity-review.com
[Denver] cyber 10.0 — MZ Automation libIEC61850sentinel
[Denver] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel

Related Signals19

[Denver] cyber 10.0 — igloohome Smart Lock Mobile Applicationsentinel2d ago[Des Moines] cyber 10.0 — igloohome Smart Lock Mobile Applicationsentinel2d ago[Denver] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel2d ago[Des Moines] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel2d ago[Denver] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel2d ago[Denver] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel2d ago[Des Moines] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel2d ago[Denver] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel2d ago[Denver] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel2d ago[Des Moines] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel2d ago[Des Moines] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel2d ago[Denver] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel2d ago[Denver] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel2d ago[Des Moines] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel2d ago[Des Moines] cyber 10.0 — MZ Automation libIEC61850sentinel2d ago[Denver] cyber 10.0 — MZ Automation libIEC61850sentinel2d ago[Des Moines] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel2d ago[Des Moines] cyber 10.0 — CI Fortify – Advice for isolating vital systemssentinel3d ago[Des Moines] cyber 10.0 — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitesentinel3d ago

External Corroboration

✓ Corroborated · 5 sourcesChecked Jul 29, 2026, 07:30 PM UTC
Russian Global Webmail Espionageunit42.paloaltonetworks.comJul 23, 2026, 12:00 AM UTCRussian espionage group using novel Zimbra exploit to steal sensitive data from Western countries | CyberScoopcyberscoop.comJul 23, 2026, 05:33 PM UTCRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite | Cyber Insidercyberinsider.caJul 21, 2026, 12:00 AM UTCCISA AA26-204A: Russian Zimbra Phishing | SafeBreach Coveragesafebreach.comJul 23, 2026, 12:00 AM UTCRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite - Cyber Security Reviewcybersecurity-review.comJul 23, 2026, 12:00 AM UTC

Affected Regions

DenverDes Moines