Every era of security has a favourite door. In July 2026 the doors of choice were, overwhelmingly, other people's: the tools developers install, the consultants who hold the keys, the platforms where customer data already lives. Reading the month's incident list is like descending a staircase where every step is somebody you trusted.

Start at the newest step: the AI toolchain. Hugging Face — the registry where the world's machine-learning teams fetch models and libraries the way web developers fetch npm packages — spent July responding to a supply-chain compromise targeting AI development tools. The industry had spent two years warning that model hubs would inherit every disease package registries ever caught; July was the month the warning stopped being hypothetical. Poisoned developer tooling is an old trick, but pointing it at the AI build pipeline — the fastest-growing, least-audited dependency surface in software — made it new again.

One step down: the keyholders. A threat actor going by "888" claimed to have taken 35 GB from Accenture — source code, SSH keys, RSA keys, Azure credentials, the working inventory of a firm whose business is running other companies' transformations. EY, meanwhile, investigated an incident affecting internal systems of its own. The claims around both remained just that — claims, of the kind that sometimes deflate under investigation — but the targeting logic needed no verification: a consultancy's keyring opens hundreds of doors that were never yours to guard.

And one step further: the platforms. ShinyHunters — whose Salesforce-adjacent harvesting defined 2025 — carried the franchise into its second year, with test-and-measurement firm Fluke among July's victims: over 21 million Salesforce records reported compromised. Fifteen months of the same lesson, taught to a new class each term: the fortress model died quietly, and what replaced it is a web of standing grants and tokens that nobody's dashboard fully shows.

Also that month · Critical infrastructure

Water and dial tones

The month's infrastructure entries came from opposite ends of the scale: community water utilities in Minnesota faced operational disruption — small systems, thin IT, the soft underbelly American security agencies have warned about for years — while in Japan, telecom giant KDDI dealt with disruption of its own. One victim serves towns of thousands, the other tens of millions; what they share is the lesson of the decade's infrastructure attacks: criticality and defensibility are set by different budgets.

Also that month · Ransomware's odd jobs

The dairy and the ice rink

Ransomware's July itinerary read like a surrealist travel diary: Coca-Cola's Fairlife dairy operations disrupted; the Netherlands' famous Thialf ice-skating stadium hit by a crew styling themselves "the Gentlemen"; alongside incidents touching Chick-fil-A, Origin Energy, and others. The breadth is the point — a decade of professionalisation has left ransomware with the economics of a volume business, where a speed-skating rink and a milk plant are simply Tuesday's accounts receivable.

India desk · July 2026

A terabyte with a bank's name on it

India's story of the month was on the dark web: a database bearing Bank of Baroda's name, listed by an actor claiming nearly 1 TB of sensitive data, as the bank dealt with customer-facing incidents. The claim's full contours remained under investigation — but it landed in a very different India than it would have two years ago: one where banks reported over 17,000 fraud cases exceeding ₹36,000 crore in just the first nine months of FY 2025-26, where CERT-In's six-hour clock and the DPDP Act's breach duties now run simultaneously, and where a bank's disclosure obligations are no longer a matter of discretion. The era of quiet incidents is ending on a statutory schedule.

⏳ Time capsule — July 2026

  • Mid-year "worst breaches of 2026 so far" listicles arrived on schedule — the industry's grim solstice tradition.
  • Threat-actor branding reached peak theatre: a thief named "888", a ransomware crew called "the Gentlemen". Marketing departments everywhere took notes.
  • "Secure your AI supply chain" completed its journey from conference title to procurement questionnaire in under a year.
  • In India, monsoon season and digital-payment fraud advisories arrived together, as they now reliably do.
Where it stands today — August 2026

The month before this magazine

July 2026 is where The Vault meets the present — these events were the news while our relaunch issue was being laid out, and several are still unfolding as we publish: investigations open, claims unverified, consequences unbilled. That thinness of hindsight is worth being honest about; this edition will be revisited as the record settles. What needed no waiting was the pattern. The staircase of borrowed trust — toolchains, keyholders, platforms — is the world our current editions now cover in real time, one week ahead of it becoming history.