Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 29th June and 5th July 2026.30th June
India tops Asia-Pacific (APAC) ransomware target list
29th June
2.7 Million Sysco Emails Leaked Following ShinyHunters Data Breach
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
A Data Breach Rarely Ends with the Breach Itself - Leaked Data Is Used in Travel and Ticket Scams During the Summer
Agentic AI Has an Identity Problem and Attackers Know It
AI Will Test Identity Infrastructure, Organizations Need More Prep
AI-Driven Identity Attacks Are Surging
Apple supplier Tata tightens internal controls post-data breach
ATM Jackpotting Gang Members Sentenced for Ploutus Malware Attacks
Australia: NSW Rural Fire Service admits security incident
Bluekit Phishing Kit Uses Browser-in-the-Middle Attacks to Evade Detection
Cambridge University Hospitals (CUH) Trust refers itself to regulator over data breach
Canadian hacker sentenced for Texas Republican Party website defacement
Companies keep bolting AI onto their products, and the security bill is coming due
Copying the wrong person on an email could be considered a data breach in South Africa
Couple jailed over ‘worst ever’ Transport for London (TfL) data breach and £650k fraud
Critical SimpleHelp flaw exploited to deploy new stealer malware
Cyber insurance is delivering meaningful financial protection, with a majority of data breach and first-party losses covered according to Willis’ latest report
Cybersecurity for Food Companies: How to Prepare for Ransomware, AI Threats, and Supply Chain Disruptions
Danish official warns data stored on US cloud is shared with American spies
DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto Fraud and WhatsApp Phishing
DCloud Uni-App Templates Help Fraudsters Scale Crypto, Mobility, and Messaging Phishing Scams
Dell Wyse Management Suite Flaws Let Remote Attackers Execute Code
DentaQuest data breach class action filed over ShinyHunters cyberattack
Don’t pay the ransom: Warning to organisations to protect themselves from ransomware attacks as more than 320 businesses affected last year
EvilTokens Phishing Breaches Finance Firms Using “Ghost” Code Across U.S. and European Businesses
ExtraHop report finds nearly half of ransomware victims suffer data theft before detection
FBI Sounds Alarm Over Russian Intelligence Signal Phishing
FBI warns of Russian Intelligence phishing campaign abusing Signal support services to target VIPs and high-value government and military targets - this is how to secure your account
FoxTrot Data Breach Compromises Social Security Numbers
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Germany discloses data over “silent SMS” use for surveillance
Ghostwriter Hackers Use Real-Time WebSocket Relay to Bypass SMS and OTP MFA
Ghostwriter Phishing Infrastructure Targets Gmail and Ukrainian Email Portal Users
GIFTEDCROOK Payload Targets Chrome, Firefox, KeePass, OpenVPN, and Sensitive Documents
Global Cybersecurity Firms Warn of Rising AI-Powered Phishing Attacks
Government Website in India Taken Offline After Defacement Attack
Hackers claim 110 Million Notion records exposed, but the company’s AI assistant is not concerned
Hackers claiming leak of 310 million Temu accounts: here's what we know
Hackers now exploit critical Oracle E-Business flaw in attacks
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
In major privacy win, Supreme Court rules geofence warrants are protected by privacy rights
India: Pune Property Tax Data Breach Sparks Alarm
India’s Meerut Development Authority Website Defaced With Pro-Pakistan Messages
Indian auto giant Bajaj targeted in ransomware attack
Iran cyberattacks on Israel surged in 2026, Israeli cyber chief says
Japan Hit By Major Data Breach: Up to 14.22 Million Email Login Credentials Potentially Exposed
Japanese AI police chief takes on $2 billion scam epidemic
JSP webshells being dropped on unpatched PTC Windchill instances
KDDI Breach Exposes Up to 14.2 Million Email Logins at Six ISPs
KDDI Data Breach Exposes 14 Million Emails in Japan
KDDI Data Breach Exposes 14.2 Million Logins: Shared Infrastructure Flaw Hits Six ISPs
KDDI discloses data breach affecting up to 14.2 million customers
London Hydro offers credit monitoring after data breach
MCBS Data Breach Compromises PII and PHI Data
Microsoft 365 Apps Security Update Fixes High-Severity Excel RCE Vulnerability
Microsoft extends Windows Server 2022 hotpatching until October 2027
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Microsoft Removes Over 100 StegoAd Edge Extensions Hiding Malware via Steganography
Microsoft reveals phishing campaign targeting hotels in Europe and Asia
Millenium RAT Malware-as-a-Service (MaaS) Uses Telegram Bot API to Control Infected Windows Machines
Most teams accept higher risk for faster AI database work
Mozilla warns of indirect prompt injection risk in AI coding agents
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
North Korea-Linked macOS Malware Uses Prompt Injection to Evade AI Analysis
Northern Technologies International Corporation (NTIC) Data Breach: Social Security Numbers Exposed
Nova ransomware group takes responsibility for NSW Rural Fire Service (RFS) hack
OpenAI Reveals GPT-5.6 Sol Cybersecurity Model, Restricts Early Access
Operation Endgame Disrupts SocGholish, StealC Malware Networks
Over 14 million login credentials leaked from six ISPs in major data breach - here’s what we know
Phishing and ransomware - 10 ways to stop phishing-based ransomware attacks
Photo-themed phishing campaign targets European and Asian hotels with Node.js implant
Polymarket Users Lose $3.1 Million in Phishing Attack as 1,891 ETH Moves to Fresh Wallets
Public Proof-of-Concept (PoC) Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
Ransom should not be paid say Law Enforcement Agencies
Ransomware groups are coming for law firms
Ransomware hits European suppliers as attacks surge 55%
Rokarolla Uses Fallback C2 Domains to Maintain Control Over Infected Android Devices
Russian Hackers Accused of Destructive Cyber-Attack on Jaguar Land Rover
Russian spies are targeting Signal accounts linked to Ukraine with new phishing tactic
Russian state hackers stealing new Signal accounts with old backup keys, FBI warns
Sender Policy Framework (SPF) checker guide: How to protect your domain from phishing attacks
South Korea: Golfzon Data Breach Victims Launch Class-Action Lawsuit
Texas data breach hits 3 Million license customers
The Hacker’s 2026 Playbook from the Dark Web
Tower Administrative Services discloses data breach exposing SSNs and financial information
Trump White House Dips Toes Into AI Cybersecurity Regulation by Executive Order
Taiwan digital ministry admits failures over cyber institute data breach
Telegram-Based Millenium RAT Campaign Infects 60,000 Devices
The Gentlemen are knocking: сustom backdoors and evolving tactics
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
UAE Cybersecurity Council Calls for Stronger Digital Footprint Protection
UK businesses fear stigma of ransomware
UK data watchdog fines consultancy firm £300K for flooding people with millions of illegal texts
Ukraine to use seized crypto from cybercrime group to buy war bonds
UNC1151 Ghostwriter Hackers Target Belarusian Politician in Gmail Phishing Campaign
Update Chrome Now: Google Fixes 18 Security Flaws, Including Critical Bugs
US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw
US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp
Website owners report surge in malicious bots impersonating Googlebot, sparking call to check IPs
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private
Why Insider Threats Deserve a Spot at the Top of Your Risk List
Women's Center for Radiology Data Breach Compromises Personal and Health Information
Women's Wellness of Delaware Data Breach Impacts Aesthetic and Clinical Service Patients
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 15th June and 21st June 2026, kindly assisted by our partners.
