Somewhere along the way, the ransom note stopped needing the ransomware. June 2026 was the clearest month yet of a quiet inversion years in the making: the criminals mostly stopped encrypting and simply took — because stolen data extorts just as well as locked data, without the noisy cleanup that brings journalists and incident responders running. Trackers of the month's activity called it plainly: June was dominated by data-theft extortion, not ransomware.

The centrepiece was a ShinyHunters campaign — the crew that spent two years turning Salesforce environments into a subscription business — now running a pay-or-leak operation across healthcare, insurance regulation, and entertainment, powered by a zero-day in Oracle PeopleSoft and a helping of social engineering. PeopleSoft is where organisations keep the software that runs their people: HR records, payroll, the administrative bloodstream. The target list wrote itself.

Around the campaign, the month's roll-call showed extortion's reach: Novo Nordisk — maker of the world's most in-demand drugs — investigating unauthorized access traced to an exposed high-privilege GitHub token, claimed by a group calling itself FulcrumSec; Nintendo and Eastman Kodak on incident lists; the Council of Europe and the University of Nottingham; Texas government systems; London Hydro; dental benefits administrator DentaQuest. No sector, no continent, no particular logic beyond reachability.

The Novo Nordisk detail deserves its own pause: no malware, no exploit chain — a personal access token, the kind developers mint on a Tuesday and forget by Friday, carrying enough privilege to open a pharmaceutical giant. The year's grand theme in one artifact: modern breaches are less about breaking in than about finding the key someone already left out.

Also that month · The guards got robbed

One OAuth app, half the security industry's vendors

The Klue supply-chain attack was June's neatest irony: a group dubbed Icarus abused an OAuth connection through the competitive-intelligence tool to pull Salesforce CRM data from its customers — among them HackerOne, Tanium, Huntress, Gong, and OneTrust. Companies whose business is security, breached not through their fortresses but through a sales-team app with standing permission to walk in. The borrowed-keys lesson of 2025, now taught to the faculty.

Also that month · The pattern, quantified

Extortion becomes the default business model

Step back from any single victim and June's real story was structural: encryption is friction, and the market optimised it away. Pure data-theft extortion travels lighter — no decryptors to build, no recovery to sabotage, just a leak-site countdown and a price. For defenders the shift moves the goalposts uncomfortably: backups, the great ransomware answer of the last decade, are no defense at all against a copy of your data that already left.

India desk · June 2026

Blueprints and passports: India's industrial month

June was the month India's industrial base met the leak-site economy. A group calling itself World Leaks published more than 200,000 alleged files from Tata Electronics — roughly 630 GB reportedly spanning iPhone component records, supplier details, technical drawings, and employee passport scans — prompting a MeitY investigation after the incident was reported to CERT-In. Graver still: Reliance Group confirmed a breach of a server hosted with data-centre provider Yotta, where attackers claimed 858,000 files — some 19,000 of them confidential, allegedly including Kudankulam Nuclear Power Plant blueprints and supplier records. Claims around nuclear infrastructure warrant both skepticism and alarm in equal measure — and they made June the month India's breach story graduated from stolen identities to stolen industry.

AI Tech desk · June 2026

Eighteen days without a frontier model

Anthropic released Claude Fable 5 on 9 June 2026, the first publicly available model in a tier it calls Mythos class, alongside a restricted sibling, Mythos 5, offered to vetted researchers under a vulnerability-hunting programme, Project Glasswing, which by the company's own account had already surfaced thousands of high- and critical-severity flaws in open-source code. Three days later both models were gone. Commerce Secretary Howard Lutnick issued an export-control directive suspending access for every foreign national worldwide, including Anthropic's own overseas staff, after Amazon researchers reportedly told officials they had drawn material useful for cyberattacks out of Fable 5. Accounts diverge from there: White House adviser David Sacks said the company had refused to remediate; Anthropic disputed the severity, arguing the same capability was available from other deployed models including OpenAI's GPT-5.5, and denied refusing. Commerce lifted the controls on 30 June and the models returned the next day — but the precedent, a commercial model withdrawn worldwide on a capability finding, outlived the outage.

Digital Guard desk · June 2026

Attack tooling that coding agents helped build

On 2 June 2026 Sophos published an analysis of a ransomware toolkit it said had been developed with the help of commercial coding agents, Cursor and Claude Opus among them. The kit automated Active Directory discovery and endpoint evasion: a payload generator wrapping executables and DLLs in layers of encryption and alternative execution, Cobalt Strike profiles, Telegram command and control. Tested against Sophos's own agent, CrowdStrike's and Microsoft Defender, the modules cleared almost all of them after several iterations — though Sophos noted discrepancies between the toolkit's test output and its own reporting, and found no sign a model ran inside victim networks; the assistance stopped at development. The industry's business month sat oddly beside that. CrowdStrike reported revenue up 26 per cent on 3 June yet fell hard in late trading on billings growth of 18 per cent; on 18 June Accenture agreed to buy Dragos, runZero and NetRise for what it valued at about $4.18 billion.

⏳ Time capsule — June 2026

  • Threat-actor naming hit peak mythology: World Leaks, FulcrumSec, Icarus — crews now brand like startups.
  • Even Nintendo turned up on the month's incident lists — nothing is too beloved to extort.
  • "Do we still need backups?" became a genuinely contested conference question — the answer is yes, but the fact it was asked is the story.
  • India's monsoon season opened alongside a season of MeitY probes and CERT-In filings.
Where it stands today — August 2026

The inversion completes

Two months on, June reads as the point where the extortion economy stopped pretending. July's supply-chain staircase — AI toolchains, consultancy keys, platform tokens — was this month's logic extended one step further, and the investigations June opened, from MeitY's probe of the Tata Electronics leak to the questions around the Kudankulam claims, remain live as we publish. The defensive agenda it set is the one our current editions now track weekly: token inventories, OAuth audits, and the uncomfortable new arithmetic in which the copy of your data you don't hold is the one that decides your month.