Wire · regulatory
SUPO and the FDI warn companies of Russian cyber threat actor Laundry Bear
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 24 July 2026 · Fusion42 review
Finnish and US intelligence agencies warn of Laundry Bear, a Russian state-sponsored cyber threat actor targeting email systems of NATO countries, Ukraine, and Finland, primarily in public administration, critical infrastructure, and defence. The group has exploited a zero-day vulnerability in Zimbra Collaboration Suite (patched in winter 2025/2026) and uses social engineering and stolen credentials, with espionage activity expected to continue despite the patch.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ ◆ The Wire takeaway
If you build critical infrastructure, defence systems, or email security for government or NATO-adjacent organisations in Europe, Russian state actors have you in their crosshairs and are actively trying your email front door. Patch Zimbra immediately and assume stolen credentials are in play—social engineering against your team is the real threat now.
◆ Related on Wire
◆ Topics