The mail server is patched. The incident is not necessarily scoped.
A July 2026 government advisory describes Russian state-supported actors using a viewed message in vulnerable Zimbra webmail to attempt months of email and address-directory collection. The clever part is the browser-side entry. The operationally durable part is that mail reads, persistent credentials, and exfiltration evidence can fall across different teams and logs.
Our forecast is deliberately narrower than “someone will phish an inbox.” It asks whether another *distinct*, state-backed campaign will be publicly attributed by June 2027 with automated mailbox or directory collection at its center. That disclosure standard creates real uncertainty even if operations continue.
The immediate move is more modest: test whether messaging, IAM, the SOC, and IR can reconstruct one account’s collection path from the logs they actually keep. The dashboard may be green; the evidence join still has a job to do.