07/20/2026 | Press release | Archived content
The FDI, SUPO and their international partners are warning of a Russian state-sponsored cyber threat actor that specifically targets email systems of organisations.
For the second time this July, the FDI and SUPO are taking part in a joint Cybersecurity Advisory (CSA) that the National Security Agency (NSA) of the United States have published together with several Western intelligence services about Russia's malicious cyber activity. This time, the Finnish intelligence authorities want to make companies and organisations aware of a lesser-known Russian cyber threat actor, Laundry Bear, that is assessed to pose a serious cyber espionage threat especially to organisations working in the public administration, critical infrastructure or the defence industry.
Laundry Bear has targeted a wide range of victims, including military industry operators, state administration and other authorities, technology companies, and third sector operators. The main targets have been NATO countries and Ukraine. Finland is also targeted. The Finnish authorities have responded to the activity and helped to protect against it.
Laundry Bear has primarily attempted to break into the email systems of the targeted organisation, often using simple but effective methods such as social manipulation (e.g. impersonation) and stolen user IDs. As of 2025, Laundry Bear has exploited a so-called zero-day vulnerability in the Zimbra Collaboration Suite (ZCS). The vulnerability has been addressed by the release of a software update in winter 2025/2026.
The FDI and SUPO assess that Laundry Bear will likely continue to attempt to infiltrate the email systems of sensitive industries, even though a patch for the ZCS vulnerability exists and the potential to exploit the vulnerability is diminishing. The intelligence authorities are encouraging organisations to be aware of the threat posed to email systems by state actors and to ensure regular updates of their systems and the security monitoring of email systems.
The operational conditions of Russian human intelligence in the West have been weakened following the expulsions of Russian intelligence officers as a result of the war of aggression in Ukraine, forcing the country to increasingly resort to cyber methods in its espionage activity. Russia's need for information has also been exacerbated by Western sanctions.
Cyber security professionals can find more detailed technical guidance in the NSA's CSA published on 23 July 2026: