Monthly Cyber Threat Intelligence Report: June 2026
June 2026 cyber threat intelligence from System Force IT: data-theft extortion overtook encryption as ShinyHunters ran a pay-or-leak campaign via an Oracle PeopleSoft zero-day; Microsoft shipped its largest-ever Patch Tuesday; CISA added 23 exploited vulnerabilities; and 707 ransomware victims were listed across 63 groups, with The Gentlemen ending Qilin's five-month run. Plus a UK focus: FortiBleed, the University of Nottingham breach, the Cyber Security Breaches Survey 2026 and ICO enforcement.
What's inside
- Data-theft extortion overtook file-encrypting ransomware in June. The ShinyHunters group ran a pay-or-leak campaign across healthcare, insurance and entertainment by chaining an Oracle PeopleSoft zero-day with social engineering, shifting the risk from encrypted backups to sensitive-data exposure.
- Microsoft shipped its largest-ever Patch Tuesday, fixing more than 200 vulnerabilities including three publicly disclosed zero-days. Critical remote code execution in the Remote Desktop client, Hyper-V (guest-to-host escape) and Office demands immediate patching priority.
- CISA added 23 actively exploited vulnerabilities to its catalogue, spanning internet-facing and enterprise systems including Ivanti Sentry, Cisco Catalyst SD-WAN Manager, SolarWinds Serv-U, Ubiquiti UniFi OS, Oracle PeopleSoft and the Linux kernel. Internet-facing systems should be patched first.
- Ransomware leak sites listed 707 victims across 63 active groups. For the first time in 2026 Qilin was not the busiest: The Gentlemen led with 94 victims, the previously untracked DeadLock surged to 81, and Qilin fell to 71, with healthcare, manufacturing and construction the most-targeted sectors.
- Major breaches at Novo Nordisk, Nintendo, Tata Electronics (more than 200,000 files leaked by World Leaks), One Medical and a three-week outage at Chelan County underline third-party and supply-chain exposure, and how long recovery takes without tested continuity plans.
- For UK businesses, a breach is now a regulatory as well as an operational risk. The ICO has moved to fewer but far larger fines (averaging around £3.2 million in 2026, £963,900 for South Staffordshire Water in May and £14 million for Capita, both for security failings after cyber attacks), the Cyber Security Breaches Survey 2026 found 43 per cent of UK firms attacked in the past year, and the NCSC issued an alert on 18 June about a global campaign targeting Fortinet firewalls and VPN gateways.
The June 2026 edition of the System Force IT Monthly Cyber Threat Intelligence Report covers the most significant cyber incidents, emerging threats, vulnerability disclosures and ransomware activity observed during the month. The report is intended for business owners, IT leaders and risk managers who need a concise monthly briefing without wading through fragmented vendor advisories.
June was defined by a shift away from file-encrypting ransomware towards straight data-theft extortion. The ShinyHunters group ran a pay-or-leak campaign across healthcare, insurance and entertainment, chaining an Oracle PeopleSoft zero-day with social engineering rather than deploying encryptors. High-profile organisations disclosed breaches through the month, including Novo Nordisk, Nintendo, the Council of Europe, the University of Nottingham and Tata Electronics, whose files were published by the World Leaks group after more than 200,000 were stolen. Amazon-owned One Medical confirmed a breach of a third-party file store holding senior-care records, and Chelan County in Washington spent three weeks with networks, phones and email offline after a malware attack, a reminder of how long recovery takes when continuity planning is thin.
On the technical side, Microsoft shipped its largest-ever Patch Tuesday, fixing more than 200 vulnerabilities including three publicly disclosed zero-days, with critical remote code execution flaws in the Remote Desktop client, Hyper-V (allowing guest-to-host escape) and Office. CISA added 23 flaws to its Known Exploited Vulnerabilities catalogue, spanning internet-facing and enterprise systems from Ivanti Sentry, Cisco Catalyst SD-WAN Manager and SolarWinds Serv-U to Ubiquiti UniFi OS, Oracle PeopleSoft and the Linux kernel. Ransomware leak sites listed 707 victims across 63 active groups, and for the first time in 2026 Qilin was not the busiest: The Gentlemen led with 94 victims, the previously untracked DeadLock surged to 81, and Qilin fell to 71. Healthcare, manufacturing and construction were the most-targeted sectors. Priority actions remain consistent: patch internet-facing edge devices and domain controllers urgently, treat data-theft extortion as a board-level risk rather than an IT-only one, harden identity and third-party access, and keep tested, offline backups.
For UK businesses specifically, June reinforced two points. The National Cyber Security Centre issued an alert on 18 June about a global campaign targeting Fortinet firewalls and VPN gateways, after a threat actor leaked a database of credentials gathered by credential-stuffing internet-facing FortiGate portals, and UK organisations including the University of Nottingham were among those breached. The government’s Cyber Security Breaches Survey 2026 found that 43 per cent of UK businesses had been attacked in the past year, with the revenue impact on smaller firms roughly doubling. And with the ICO now issuing fewer but much larger fines, averaging around £3.2 million in 2026 and increasingly targeting security failings after cyber attacks (it fined South Staffordshire Water £963,900 in May after a breach exposed data on more than 630,000 people, following a £14 million penalty against Capita), a slow response to a breach now carries a direct regulatory cost as well as an operational one.