June 2026 was defined less by classic ransomware than by data-theft extortion, according to PKWARE’s latest breach roundup. Across the month’s worst incidents, attackers appeared focused on stealing usable data and threatening to publish it if victims did not pay.
That shift showed up in a wide range of organizations. One Medical confirmed unauthorized access to a third-party file storage system containing legacy patient records, while the National Association of Insurance Commissioners disclosed a breach tied to its PeopleSoft environment. Madison Square Garden Entertainment also faced publication of millions of records after declining to pay, and DentaQuest saw data on millions of people leaked.
PKWARE’s account says ShinyHunters was the month’s central actor, operating more like a durable cybercrime brand than a single crew. In the cases described, the group used an Oracle PeopleSoft zero-day and social engineering, while a separate pharmaceutical incident turned on an exposed developer credential rather than perimeter compromise.
The common thread was not that networks were broadly encrypted or destroyed. Instead, attackers often logged in with valid or inherited access, then removed data that remained valuable the moment it left the environment. PKWARE says that in these cases, whether the stolen information could be used was decided long before the incident by how well it had been protected at the data layer.
Why this matters
The report’s core warning is that traditional defenses do not solve a breach once the data has already been exfiltrated. Backups, rapid containment, and recovery planning can limit operational damage, but they do not make stolen records unreadable after the fact.
That has direct implications for organizations that rely on archives, acquired systems, and third-party repositories. PKWARE argues that many of June’s worst exposures sat in places teams had stopped actively watching, which means discovery and retention discipline matter as much as perimeter security.
Healthcare, insurance, entertainment, and pharmaceuticals all appear in the month’s examples because each sector holds sensitive data with long-lived value. Once records, credentials, or research material are taken, the damage can extend far beyond the initial intrusion and into fraud, compliance, and reputational fallout.
PKWARE’s broader lesson is that companies need to know where sensitive data lives before attackers do. The report points to automated discovery, minimizing retained data, and persistent encryption as the controls most likely to reduce the impact of the next breach wave.
June’s incidents suggest the industry is still adjusting to a threat model built around theft rather than disruption. If attackers can reach data through old systems, vendor platforms, or a single credential, then the decisive security question is no longer whether the perimeter holds, but whether the data itself remains protected when it does not.