The United States and more than a dozen allied countries have accused Russian hackers of stealing emails from users of the Zimbra email platform through a method that did not depend on classic social engineering tactics. According to the warning, the attackers were able to access messages without needing victims to click a malicious link or open an infected attachment.

That detail makes the campaign especially notable because many email intrusions begin with phishing. In this case, officials said the hackers used a different technique to obtain emails directly, highlighting a threat that can bypass the kinds of user-awareness defenses many organizations rely on most heavily.

The disclosure underscores growing concern among Western governments about state-linked cyber activity aimed at communications systems and sensitive data. Zimbra, which is used by a range of organizations, can become a high-value target when attackers are seeking access to inboxes and internal correspondence.

The joint statement from the US and its partners reflects a broader push to publicly attribute major cyber campaigns and warn potential targets about evolving tactics. For organizations using email platforms such as Zimbra, the alert is a reminder that security risks are not limited to suspicious attachments and fraudulent messages.