🚀 Startups / /via csis.org / updated -117m ago

Wave of Major Cyberattacks Underscores Expanding Global Digital Risk

A new tranche of incidents logged by CSIS highlights how espionage, ransomware, and data theft are converging across governments, banks, and tech firms. From Russia’s FSB alleging a massive smartphone spying campaign to ShinyHunters-linked breaches at NAIC and Instructure, the activity spans critical infrastructure and core digital platforms. The pattern points to a widening attack surface where education, finance, healthcare, and gaming services are all in play.

#CenterforStrategicandInternationalStudies#FSB#TataElectronics#Apple#Tesla#InformaticsServicesCorporation#NationalAssociationofInsuranceCommissioners#Instructure#NVIDIA#ChipSoft
~/ Startups/ Wave of Major Cyberattacks Underscores Expandin...

The latest entries in the Center for Strategic and International Studies’ Significant Cyber Incidents timeline paint a picture of a threat landscape that is both widening and deepening across sectors. Since April and May 2026, attackers have struck educational platforms, insurance regulators, crypto infrastructure, banks, and cloud gaming services, while state security agencies in Russia and Iran have disclosed disruptive operations with geopolitical overtones. The incidents range from claimed foreign espionage campaigns against senior officials to massive data breaches affecting hundreds of millions of users.

In June 2026, Russia’s Federal Security Service (FSB) said it uncovered a large-scale foreign espionage operation using malware to infect the smartphones of senior Russian government officials. According to the agency, the malware allowed attackers to steal data, intercept communications, and conduct covert audio and video surveillance, allegedly leveraging the infrastructure of major international technology companies. The FSB opened a criminal investigation and pledged to identify those responsible, but did not provide technical evidence, name the malware, or publicly attribute the campaign to a specific country, leaving key details opaque even as it amplified concerns about mobile device security at the highest levels of government.

Corporate espionage and extortion featured prominently in India, where Tata Electronics reported a cyberattack in June that resulted in hackers allegedly stealing and leaking thousands of confidential files. Those files reportedly included sensitive information related to Apple and Tesla, underscoring how supply chain partners have become high-value targets for data thieves. Tata said its operations were not affected and that response protocols were activated immediately, yet the company reportedly received a ransom demand, and Apple launched an investigation, highlighting the ripples such incidents can create across global manufacturing ecosystems.

Financial systems were not spared. Iran’s state-owned Informatics Services Corporation announced in June that cyberattacks disrupted card-based banking services at Bank Melli, Bank Saderat, and Bank Tejarat. Card-related operations at these major banks were suspended, affecting ATMs, point-of-sale terminals, and mobile applications tied to card systems, while Iranian officials said cybersecurity teams were working to restore services and stressed that an earlier related incident had not compromised customer data. In the United States, the National Association of Insurance Commissioners (NAIC) suspended assigning investment risk designations after a cyberattack compromised credit rating data from agencies including Moody’s, S&P, KBRA, Fitch, and Morningstar DBRS, prompting those agencies to pause data sharing with NAIC and temporarily clouding the calculations that help determine how much capital insurers must hold to meet policyholder obligations.

ShinyHunters, a well-known cybercriminal group, emerged as a recurring actor across several of the most consequential breaches. In May 2026, Instructure, provider of the Canvas learning management system, suffered what was described as a massive data breach orchestrated by ShinyHunters, who compromised the platform’s cloud infrastructure. The attackers claimed to have exfiltrated 3.65 terabytes of data belonging to roughly 275 million users across nearly 9,000 global educational institutions, exposing student names, IDs, and private communications and ultimately compelling Instructure to pay a ransom to avert a catastrophic data leak. The same group claimed responsibility for accessing NAIC systems in June, and an unidentified threat actor later impersonated ShinyHunters while compromising the GeForce NOW cloud gaming platform’s Armenian alliance partner, GFN.am, then attempting to extort $100,000 by leaking names, phone numbers, and email addresses from local users.

Critical infrastructure and decentralized finance also came under coordinated pressure. U.S. officials disclosed in May that suspected Iranian hackers successfully breached systems monitoring fuel storage tanks at multiple gas stations across several states by exploiting automatic tank gauge systems left exposed to the public internet without proper password protection. The attackers did not physically alter fuel quantities but manipulated digital display readings, raising serious safety concerns that such vulnerabilities could be abused to conceal dangerous gas leaks. In April, a hacker group suspected of links to North Korea exploited a major cryptocurrency exchange platform, with costs estimated at roughly $293 million by LayerZero Labs, which provides infrastructure for KelpDAO’s RsETH configuration; LayerZero characterized the attack as isolated, yet the incident nonetheless represented the largest decentralized finance attack of 2026.

Europe faced its own data security shocks. France’s National Agency for Secure Credentials (ANTS) announced in April that its database had been breached, identifying between 11 and 18 million accounts and exposing personally identifiable information such as names, user IDs, phone numbers, and addresses, and urged citizens to remain broadly vigilant for increased targeted scams. French authorities said the culprit was a 15-year-old citizen, a detail that underscores how serious breaches of national credential systems no longer require sophisticated state capabilities. Around the same time, ChipSoft, an online service provider for roughly 70 percent of Dutch hospitals, was breached by a hacker group called Embargo; while no direct healthcare services were reportedly disrupted, ChipSoft temporarily disabled connections to compromised clients to prevent further damage, leading to operational disruptions and portal shutdowns as the company deleted compromised data and worked to restore normal operations.

Why this matters

Taken together, these incidents show how cyber risk has moved beyond isolated hacks toward systemic exposure across education, finance, healthcare, gaming, and state institutions. The ShinyHunters-linked breaches at Instructure, NAIC, and the GeForce NOW partner illustrate how criminal groups can simultaneously threaten the confidentiality of student records, the integrity of insurance regulation, and the trust in consumer cloud services. Meanwhile, the fuel gauge manipulation in U.S. gas stations and the large-scale espionage campaign alleged by Russia’s FSB reveal that operational technology and mobile endpoints at the core of everyday and governmental functions are now squarely in attackers’ sights, raising both safety and national security stakes even when technical details and attribution remain contested or incomplete.

Looking ahead, the CSIS timeline suggests that organizations will need to assume that their data, interfaces, and partners are part of a global attack surface that is constantly probed by both nation-state operators and opportunistic cybercriminals. Large platforms like Canvas and crypto exchanges face the dual challenge of shoring up complex cloud infrastructures while managing the fallout when attackers claim to hold terabytes of sensitive information. Regulators and banks, from NAIC to Iranian institutions, are being forced to weigh how to keep essential services running while halting processes such as risk designations or card operations after compromises, a tension that is unlikely to ease as threat actors refine both their technical tactics and their extortion strategies.

source csis.org →
share
𝕏 FB
← cd ../news