Somewhere along the way, the ransom note stopped needing the ransomware. June 2026 was the clearest month yet of a quiet inversion years in the making: the criminals mostly stopped encrypting and simply took — because stolen data extorts just as well as locked data, without the noisy cleanup that brings journalists and incident responders running. Trackers of the month's activity called it plainly: June was dominated by data-theft extortion, not ransomware.

The centrepiece was a ShinyHunters campaign — the crew that spent two years turning Salesforce environments into a subscription business — now running a pay-or-leak operation across healthcare, insurance regulation, and entertainment, powered by a zero-day in Oracle PeopleSoft and a helping of social engineering. PeopleSoft is where organisations keep the software that runs their people: HR records, payroll, the administrative bloodstream. The target list wrote itself.

Around the campaign, the month's roll-call showed extortion's reach: Novo Nordisk — maker of the world's most in-demand drugs — investigating unauthorized access traced to an exposed high-privilege GitHub token, claimed by a group calling itself FulcrumSec; Nintendo and Eastman Kodak on incident lists; the Council of Europe and the University of Nottingham; Texas government systems; London Hydro; dental benefits administrator DentaQuest. No sector, no continent, no particular logic beyond reachability.

The Novo Nordisk detail deserves its own pause: no malware, no exploit chain — a personal access token, the kind developers mint on a Tuesday and forget by Friday, carrying enough privilege to open a pharmaceutical giant. The year's grand theme in one artifact: modern breaches are less about breaking in than about finding the key someone already left out.

Also that month · The guards got robbed

One OAuth app, half the security industry's vendors

The Klue supply-chain attack was June's neatest irony: a group dubbed Icarus abused an OAuth connection through the competitive-intelligence tool to pull Salesforce CRM data from its customers — among them HackerOne, Tanium, Huntress, Gong, and OneTrust. Companies whose business is security, breached not through their fortresses but through a sales-team app with standing permission to walk in. The borrowed-keys lesson of 2025, now taught to the faculty.

Also that month · The pattern, quantified

Extortion becomes the default business model

Step back from any single victim and June's real story was structural: encryption is friction, and the market optimised it away. Pure data-theft extortion travels lighter — no decryptors to build, no recovery to sabotage, just a leak-site countdown and a price. For defenders the shift moves the goalposts uncomfortably: backups, the great ransomware answer of the last decade, are no defense at all against a copy of your data that already left.

India desk · June 2026

Blueprints and passports: India's industrial month

June was the month India's industrial base met the leak-site economy. A group calling itself World Leaks published more than 200,000 alleged files from Tata Electronics — roughly 630 GB reportedly spanning iPhone component records, supplier details, technical drawings, and employee passport scans — prompting a MeitY investigation after the incident was reported to CERT-In. Graver still: Reliance Group confirmed a breach of a server hosted with data-centre provider Yotta, where attackers claimed 858,000 files — some 19,000 of them confidential, allegedly including Kudankulam Nuclear Power Plant blueprints and supplier records. Claims around nuclear infrastructure warrant both skepticism and alarm in equal measure — and they made June the month India's breach story graduated from stolen identities to stolen industry.

⏳ Time capsule — June 2026

  • Threat-actor naming hit peak mythology: World Leaks, FulcrumSec, Icarus — crews now brand like startups.
  • Even Nintendo turned up on the month's incident lists — nothing is too beloved to extort.
  • "Do we still need backups?" became a genuinely contested conference question — the answer is yes, but the fact it was asked is the story.
  • India's monsoon season opened alongside a season of MeitY probes and CERT-In filings.
Where it stands today — August 2026

The inversion completes

Two months on, June reads as the point where the extortion economy stopped pretending. July's supply-chain staircase — AI toolchains, consultancy keys, platform tokens — was this month's logic extended one step further, and the investigations June opened, from MeitY's probe of the Tata Electronics leak to the questions around the Kudankulam claims, remain live as we publish. The defensive agenda it set is the one our current editions now track weekly: token inventories, OAuth audits, and the uncomfortable new arithmetic in which the copy of your data you don't hold is the one that decides your month.