SecureFact – June 29, 2026
Major cyber incidents impacted telecommunications, healthcare, manufacturing, cryptocurrency platforms, SaaS providers, and enterprise systems, exposing millions of records and sensitive business data worldwide.
Data breach exposes up to 14.2 million email logins at six ISPs
Japanese telecommunications operator KDDI Corporation disclosed a major data breach affecting up to 14.2 million customer accounts across six ISP operators. Threat actors exploited a vulnerability in unnamed third-party software to gain access to KDDI’s email system used by five other internet service providers. The compromised data includes email addresses and passwords for current and former customers, as well as inactive accounts. Some passwords were stored in hashed or encrypted form, limiting immediate abuse potential, though the company did not specify encryption types or the percentage of plaintext passwords exposed. KDDI discovered the compromise on June 17 and immediately blocked the attacker and implemented defense measures. The company notified affected ISPs, Japan’s Personal Information Protection Commission, and the Ministry of Internal Affairs and Communications. Customers are advised to reset email passwords immediately and enable two-factor authentication where available. KDDI is working with affected ISPs to implement additional security measures to mitigate risks from the exposure.
(Source: Read full report)
Polymarket customers lose $3 million in supply-chain attack
Polymarket, a $9 billion cryptocurrency-based prediction market platform, suffered a supply-chain attack resulting in approximately $3 million in financial losses for customers. Hackers injected malicious JavaScript into Polymarket’s frontend after breaching a third-party vendor dependency, tricking unsuspecting users into approving fraudulent transactions. The attack impacted less than 15 customer accounts according to blockchain analytics. Attackers stole approximately $3 million worth of PartyonUSD from affected users and subsequently swapped the stolen funds for approximately 1,893 Ether, bridging the assets from Polygon to Ethereum blockchain. Polymarket’s own servers and backend infrastructure were not compromised, limiting the scope of the incident. The company committed to fully reimbursing all affected customers for their losses. Independent blockchain intelligence firms including PeckShield and Bubblemaps tracked the stolen funds and identified the attacker’s wallets. Polymarket is working to identify the compromised vendor and implement enhanced security measures to prevent similar supply-chain attacks in the future.
(Source: Read full report)
Tata Electronics confirms cyberattack as hackers leak data
Tata Electronics, a major Apple iPhone and component manufacturer under the Tata Group conglomerate, confirmed a cyberattack targeting parts of its IT infrastructure. The company emphasized that operations continued normally and were not affected by the incident. World Leaks threat group, a rebrand of the Hunters International ransomware group, claimed responsibility and leaked data allegedly stolen from Tata. The leaked information includes multiple directories and documents containing sensitive manufacturing data for Apple products, including internal component schematics, PCB designs, material specifications, and SDK files. World Leaks operates as a data extortion group, stealing files and threatening to leak them online rather than using data encryptors. The incident was discovered a few weeks before public disclosure, with response protocols deployed immediately. Tata Electronics has not disclosed the specific volume of data compromised or the exact nature of all stolen materials. The company is investigating the incident and working to secure its systems. Apple was contacted regarding potential exposure of proprietary data but had not responded at the time of reporting.
(Source: Read full report)
LastPass confirms data breach in Klue supply chain attack
LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company’s OAuth tokens in the Klue supply chain attack. The incident occurred at Klue, a third-party market intelligence platform integrated with LastPass’s Salesforce and Gong systems. On June 12, 2026, LastPass became aware that an unauthorized actor obtained OAuth tokens that Klue held for many of its customers, including LastPass. The threat actor used these credentials to access LastPass customer data within the Salesforce environment. Exposed data includes customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM-related data. The investigation found no evidence that Gong-related data (customer calls and emails) was accessed. LastPass products, services, and infrastructure were not affected, and customer vaults remained secure. The Klue breach was claimed by the Icarus extortion group, which compromised Klue’s infrastructure using legacy credentials for an integration service. LastPass disabled employee access to Klue, rotated exposed API/OAuth tokens, and notified law enforcement. The company warned about threat actors using sender domains baccarat.com.au, robinskitchen.com.au, and house.com.au for phishing campaigns.
(Source: Read full report)