CSIS has updated its Significant Cyber Incidents timeline with a new run of June 2026 cases that spans alleged state espionage, banking disruption, and major data theft. The entries are part of the think tank’s long-running record of cyberattacks on government agencies, defense and high-tech companies, and economic crimes with losses above $1 million.
One of the most striking June incidents centers on Russia’s Federal Security Service, which said it uncovered a large-scale foreign espionage campaign targeting smartphones used by senior Russian government officials. According to the FSB, the malware enabled attackers to steal data, intercept communications, and carry out covert audio and video surveillance, though the agency did not provide technical evidence or identify the malware.
The FSB also said the operation relied on infrastructure tied to major international technology companies, but it stopped short of publicly naming a country behind the campaign. That absence of attribution leaves the incident in a familiar gray zone for cyber conflict, where governments often make serious accusations before they release technical proof.
Elsewhere in the June update, Iran’s state-owned Informatics Services Corporation said cyberattacks disrupted card-based banking services at Bank Melli, Bank Saderat, and Bank Tejarat. The disruption affected ATMs, point-of-sale terminals, and mobile applications tied to card systems, although officials said cybersecurity teams were working to restore services and that customer data had not been compromised in an earlier related incident.
CSIS also recorded a cyberattack on India’s Tata Electronics, where hackers allegedly stole and leaked thousands of confidential files. The source text says the material included sensitive information related to Apple and Tesla, and that Tata said its operations were not affected while response protocols were activated immediately.
Other June entries point to the wider reach of recent cybercrime. The National Association of Insurance Commissioners suspended assigning investment risk designations after a cyberattack compromised credit rating data from Moody’s, S&P, KBRA, Fitch, and Morningstar DBRS, while ShinyHunters claimed responsibility for access to NAIC systems.
CSIS also notes that Instructure, the company behind the Canvas learning management system, suffered a massive breach in May 2026 that was attributed to ShinyHunters. The attackers claimed to have exfiltrated 3.65 terabytes of data tied to roughly 275 million users across nearly 9,000 educational institutions, and the source says Instructure ultimately paid a ransom to prevent a catastrophic leak.
Why this matters
These incidents show how cyber risk now hits core infrastructure at once: government communications, bank payment systems, insurance regulation, and education platforms. The common thread is not just data theft, but the operational pressure that follows when attackers disrupt services, threaten leaks, or force companies and agencies into emergency response mode.
The June entries also underline how difficult attribution remains, especially in espionage-style incidents and attacks involving criminal brands such as ShinyHunters. For businesses and governments, that means response planning has to assume uncertainty: by the time a campaign is named, the operational damage is often already done.
CSIS’s timeline is likely to keep expanding as more incidents become public, and the June 2026 additions suggest the pace of disclosure is still accelerating. The broader message is simple: organizations with valuable data or essential services remain prime targets, and attackers continue to exploit the gap between technical vulnerability and public awareness.