Week 25

SecureFact – June 22, 2026

Major breaches across SaaS platforms, healthcare providers, government agencies, enterprise systems, and critical infrastructure exposed millions of records and sensitive organizational data worldwide.

Klue OAuth breach victim list grows as Icarus hackers claim attack

Klue, a market intelligence platform, confirmed a security incident on June 12 where attackers gained access through a compromised legacy credential associated with an integration service. The attackers obtained OAuth tokens used to connect Klue with third-party platforms including Salesforce, and subsequently accessed data within multiple connected customer environments. The stolen data includes business contacts, sales communications, pricing information, and competitive intelligence reports from affected organizations. The Icarus extortion group publicly claimed responsibility for the attack and began extorting affected organizations. Klue immediately revoked affected credentials and tokens, removed unauthorized code, disabled impacted integrations, launched an investigation, and notified law enforcement. The company engaged CrowdStrike to assist with the response. Multiple organizations including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity disclosed they were affected and had Salesforce data stolen.

(Source: Read full report)

Texas govt data breach exposes over 3 million driver’s licenses

The Texas Parks and Wildlife Department disclosed a data breach at its license system vendor that exposed personal information for 3,087,721 individuals. The Texas Cyber Command discovered the intrusion and launched an investigation. The threat actor may have obtained personally identifiable information including driver’s license information, passport numbers, email addresses, phone numbers, and residential addresses. Importantly, Social Security Numbers, dates of birth, and financial information such as credit cards were not impacted. The exposed data is sufficient for hackers to target impacted individuals in phishing and social engineering attacks. TPWD is working closely with the license system vendor to implement new safeguards and enhanced monitoring services. Impacted individuals are eligible for one year of free credit monitoring and are advised to monitor credit reports, place fraud alerts with major credit bureaus, and remain vigilant for phishing and impersonation scams.

(Source: Read full report)

FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices

A newly discovered data leak dubbed “FortiBleed” exposed credentials for 73,932 Fortinet and FortiGate VPN firewall URLs at organizations worldwide. The exposed data includes usernames, email addresses, and plaintext passwords for VPN and administrative interfaces. The dataset contains entries for major organizations including Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes‑Benz, and Toyota, along with government agencies and critical infrastructure operators. The exposed data also included comments listing each organization’s industry, revenue, and employee count, likely for planning attacks. A Russian‑speaking threat group allegedly conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets and 2.1 billion attempts against Microsoft SQL Server systems. CISA urged Fortinet customers to immediately rotate passwords, enable MFA, examine gateway logs for suspicious activity, and monitor for exposed employee credentials. Hudson Rock created a free FortiBleed lookup tool to check if organizations are impacted.

(Source: Read full report)

Nintendo confirms data stolen in WebMD subsidiary cyberattack

Nintendo of America confirmed that threat actors stole survey data from the third‑party TinyPulse service used internally for employee surveys. The Shadowbyt3$ extortion group claimed to have stolen approximately 1 GB of data including employee full names, email addresses, analytics and survey data, bank statements, and W‑9 forms with employee IDs and progress plans dating from 2016 to 2026. Nintendo confirmed that its systems were not compromised and no personal customer or financial data was accessed. The data involved is limited to internal survey content comprising a small subset of employees, with most information dating back several years. Nintendo is working with the TinyPulse service provider to address the issue. Shadowbyt3$ demanded a $2 million ransom and threatened to leak the information, though law enforcement strongly discourages paying ransoms as there is no guarantee the threat actor will not privately sell the information.

(Source: Read full report)

Kodak confirms data breach claimed by ShinyHunters extortion gang

Kodak confirmed it discovered unauthorized access to a limited amount of company data and promptly engaged external cybersecurity experts to investigate what data was accessed and copied. The ShinyHunters extortion group claimed responsibility on their dark web leak site, stating they stole over 2.2 million records containing customer personally identifiable information (PII) and internal corporate data. ShinyHunters threatened to leak the exfiltrated data and issued a final warning for Kodak to reach out by June 18, 2026. Kodak stated it is working with law enforcement and is confident there is no threat to its systems or operations. The company did not disclose how the threat actors gained initial access to its systems. ShinyHunters has a history of claiming attacks against hundreds of Salesforce customers, Snowflake customers, and over 100 organizations following exploitation of Oracle PeopleSoft vulnerabilities.

(Source: Read full report)

iRhythm discloses data breach, says hackers stole patient info

The Digital healthcare company iRhythm Holdings disclosed a data breach after hackers stole patients’ personal and health information stored on third‑party‑hosted business applications. The company’s cardiac monitoring service has been used to analyze more than 2 billion hours of curated heartbeat data from over 12 million patients. iRhythm discovered the incident on June 10, 2026, and confirmed that certain data was exfiltrated from third‑party applications. The threat actor reached out on June 9 demanding ransom to prevent disclosure of stolen health information online. iRhythm confirmed the incident is material in light of the volume of potentially affected data. The company has no evidence that the incident affected its products, clinical o

(Source: Read full report)

Council of Europe investigates ShinyHunters data breach claims

The Council of Europe, Europe’s oldest intergovernmental body representing 46 European member states and over 700 million people, is investigating claims of a data breach made by the ShinyHunters extortion group. ShinyHunters claimed to have stolen more than 429,000 documents containing HR and payroll data from multiple Council of Europe departments. The allegedly stolen documents include over 409,000 payslips for 10,000+ staff members (ranging from 2011 to 2026), over 3,700 in-house personnel files, more than 14,000 CVs, and other files. The stolen files contain a wide range of personal and financial information including affected individuals’ names, dates of birth, home addresses, phone numbers, employee IDs, salaries, bank account details, tax and Social Security information, and medical records. ShinyHunters threatened to leak the allegedly exfiltrated files and issued a final warning for the Council to reach out by June 16, 2026. The Council of Europe’s media department confirmed they are investigating the matter and assessing the situation but could not provide further information at the time.

(Source: Read full report)

Stay updated with SecureFact™

Get weekly cybersecurity insights delivered to your feed.

Subscribe