← Back

Wire · regulatory

SUPO and the FDI warn companies of Russian cyber threat actor Laundry Bear

Published

24 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

FinlandUnited States

Source

Read at supo.fi

Verified

Fusion42 · 24 July 2026 · Fusion42 review

Finnish and US intelligence agencies warn of Laundry Bear, a Russian state-sponsored cyber threat actor targeting email systems of NATO countries, Ukraine, and Finland, primarily in public administration, critical infrastructure, and defence. The group has exploited a zero-day vulnerability in Zimbra Collaboration Suite (patched in winter 2025/2026) and uses social engineering and stolen credentials, with espionage activity expected to continue despite the patch.

This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

If you build critical infrastructure, defence systems, or email security for government or NATO-adjacent organisations in Europe, Russian state actors have you in their crosshairs and are actively trying your email front door. Patch Zimbra immediately and assume stolen credentials are in play—social engineering against your team is the real threat now.

Related on Wire

Topics

Cybersecurityrussian-cyber-threatemail-securitycritical-infrastructurezero-day-patchnato-targeting