Around June 18–19, 2025, researchers at Cybernews described a compilation of roughly 16 billion login credentials, assembled from about 30 datasets that had each been briefly exposed on the open internet. The number did what large numbers do: it stampeded. "Largest breach in history" ran the headlines, and millions of people reset passwords they'd been ignoring for years. The headlines were also wrong — and the truth was, in its own way, worse.

Here is the nuance most coverage skipped. This was not a new breach of any single company. It was an aggregation — years of credentials scooped up by infostealer malware from infected PCs, blended with recycled material from old leaks and credential-stuffing lists. Heavy duplication across the datasets meant the count of genuinely unique, at-risk accounts was far below sixteen billion. So the scary headline oversold the event. But the underlying reality undersold it: there really is a permanent, industrial-scale malware economy quietly draining credentials off ordinary machines, and fresh infostealer logs don't just carry passwords — they carry the session cookies and tokens that let an attacker skip the password entirely. The 16-billion number was a bad measurement of a real and growing problem, which is why the sober response — passkeys, MFA, and killing password reuse — was the right one even though the headline was hype.

Setting the mega-compilation aside, June was a busy month on its own terms: by one monthly tally, newly disclosed attacks compromised more than 23 million records across 33 incidents. But the credential story set the tone — the sense of a threat that was everywhere and nowhere, measured in numbers too big to feel.

Also that month · The $90 million bonfire

Predatory Sparrow burns an Iranian exchange

Some attackers steal money; this one destroyed it on purpose. On June 17, amid the June 13–24 Iran–Israel war, the pro-Israel hacktivist group Predatory Sparrow (Gonjeshke Darande) claimed a destructive strike on Iran's state-linked Bank Sepah, disrupting ATMs and card payments. The next day it hit Nobitex, Iran's largest crypto exchange, draining over $90 million — and provably burning it, by sending the funds to unspendable "vanity" addresses no one holds the keys to. It then released what it claimed was Nobitex's source code. This was not theft; it was arson as statecraft, a demonstration that in a shooting war, a nation's financial rails are just another target set.

Also that month · Scattered Spider's insurance season

One sector at a time

Google's threat teams warned in mid-June that Scattered Spider had turned its signature playbook — help-desk social engineering, not software exploits — onto US insurers. Aflac identified an intrusion on June 12 (disclosed June 20), warning that Social Security numbers, health records, and claims data may have been exposed; Philadelphia Insurance Companies and Erie Insurance suffered week-plus outages that researchers, not the companies, attributed to the group. By month's end the crew was already pivoting to aviation — the prelude to July's Qantas breach. The method never changed; only the industry on the letterhead did.

India desk · June 2025

Two Delhi hospitals, one dark night

On the night of June 10–11, 2025, two private Delhi hospitals — Sant Parmanand in Civil Lines and NKS Super Speciality in Gulabi Bagh — reported server hacks that crippled their IT systems. Patient records, financial data, and administrative files were reportedly accessed, and NKS had to fall back to manual OPD and IPD workflows. Delhi Police registered an FIR under the IT Act and brought in cyber experts; the method of access, and whether any ransom was demanded at all, were never established in public reporting. The twin intrusions were a pointed reminder that Indian healthcare — data-rich, budget-poor, and unable to simply close when the computers stop — sits squarely in the ransomware crosshairs, in a year when Check Point counted Indian organisations facing an average of over 2,000 cyberattacks per week.

⏳ Time capsule — June 2025

  • Nintendo's Switch 2 launched June 5 and sold over 3.5 million units in four days — the fastest Nintendo hardware debut ever.
  • At WWDC on June 9, Apple unveiled its "Liquid Glass" redesign and re-versioned all its operating systems to "26."
  • Nvidia closed at record highs late in the month, reclaiming its title as the world's most valuable company at roughly $3.75 trillion.
  • The 12-day Iran–Israel war (June 13–24), capped by US strikes and a June 24 ceasefire, spilled visibly into cyberspace.
Where it stands today — 2026

The number was never the point

The 16-billion scare faded from the headlines within a week, but its real lesson hardened into 2026 doctrine: the password is a dying credential, and the session token that replaces it is the thing attackers now actually want — the exact logic behind the OAuth-token campaigns that came to define the following year. Predatory Sparrow's Nobitex bonfire, meanwhile, kept its place as the reference case for destructive financial attacks in wartime, cited every time a regional conflict raised fears for banking infrastructure. June 2025 was a month of numbers too big to feel — and its durable warning was that the scariest threats are often the quiet, ambient ones the headline number can't capture.