Weekly Cybersecurity Report | Week 25, 2026

As your dedicated cybersecurity services provider, CyberOne equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape.

Weekly Cybersecurity Report | Week 25, 2026

Information security updates and events from the past week

1. The Qilin ransomware group has announced that it is behind a cyberattack on Q Link Wireless, a US mobile service provider. The group is threatening to release sensitive information if negotiations are not initiated.

Q Link Wireless is best known as a provider of subsidized phone services to low-income populations in the US, as part of government programs This means that the company holds personal information of customers from vulnerable populations, exactly the kind of information that is designed to be exploited in scams

2. ShinyHunters group claims to have hacked the Council of Europe: 297GB of data, including employee salary data and medical records

The ShinyHunters attack group claims to have hacked the Council of Europe and stolen almost 300GB of data. The group added the organization to its Tor leak site, and gave it until June 16, which is tomorrow, to get in touch before the information is published.

What does the group claim to have stolen?

  • Over 429,000 files from various departments, including human resources, the secretariat, the parliamentary assembly and the European Agency for the Quality of Medicines and Healthcare
  • Salary data of over 10,000 employees from 2011 to 2026
  • Over 14,000 CVs, contracts, purchase orders, absence and sickness reports and performance evaluations
  • Sensitive personal information: names, ID numbers, addresses, telephone numbers, dates of birth, tax and social security details, bank account details and medical records

The Council of Europe has not yet publicly responded to the incident

3. Anubis ransomware attacks a port authority in the Adriatic Sea region, paralyzing its operations and demanding $10 million

Research firm Resecurity has published an analysis of a serious ransomware attack carried out by the Anubis group against a port authority in the Adriatic Sea region (an area that overlaps Italy, Croatia and Slovenia). The attack paralyzed port operations and disrupted maritime trade in the entire region, a clear example of how a cyberattack on a port can cause damage equivalent to a physical attack.

How the attack Happened?

  • First entry: According to Resecurity, the attackers infiltrated via a spear-phishing email with a malicious attachment sent to employees
  • After the intrusion, they escalated privileges and spread across the network (lateral movement), exploiting vulnerabilities that had not been updated in the IT infrastructure
  • In the final stage, they encrypted thousands of files, which paralyzed cargo tracking, sailing schedules and customs processing, and stole sensitive information such as contracts and employee records
  • Ransom demand: $10 million in Bitcoin within seven days, with a threat to publish the stolen information on the Darknet

The port was unable to handle incoming and outgoing shipments, and vessels were forced to dock at alternative ports

The shutdown caused millions of dollars in damage and delays in the supply chains of businesses that depend on the port

The incident damaged confidence in the port authority’s ability to secure its infrastructure.

The entire attack was carried out by exploiting vulnerabilities only, such as unsecured accounts running Office 365 and Azure, and yet the result was a real-world hit that paralyzed an entire port.

This shows that you no longer need to attack the control systems to disrupt critical infrastructure, it is enough to damage the office systems

https://www.resecurity.com/blog/article/the-anubis-ransomware-attack-on-the-adriatic-port-authority

4. Researchers remotely took control of 6 million Mercedes cars:

  • In an academic study published in the journal Sensors, researchers analyzed the in-vehicle multimedia (IVI) systems of seven manufacturers, including Mercedes, Tesla, and VW
  • They built an exploit chain that reached the point of remotely controlling about 6 million Mercedes vehicles, and verified it on six real vehicles
  • A total of 23 vulnerabilities were found, of which 7 received a CVE identifier. The root of the problem: Hardcoded Credentials and Exposure of Internal Services

https://www.businesstoday.in/auto/story/can-your-car-be-tracked-without-you-knowing-it-heres-how-it-happened-to-the-british-prime-minister-536157-2026-06-10

5. Chinese tracking device found in British Prime Minister’s car:

  • Former diplomat Charles Parton testified in Parliament that the Prime Minister’s car in 2022 transmitted data to China via a cellular module
  • The device was hidden inside a sealed component imported from China and installed in the car by the manufacturer
  • It is unclear whether it was Johnson, Truss or Sunak. China has denied it, and Britain has declined to comment

https://www.lbc.co.uk/article/chinese-tracking-device-found-government-vehicle-2022-5HjdbQd_2/

6. Handela hacks California water company via exposed GPS tool:

  • The Handela group claims to have hacked California Water Service (Cal Water), one of the largest private water companies in the US, and has released a 5GB dump as proof
  • According to an analysis by Dataminr, the group accessed two systems: a billing database with customer information (names, addresses, phone numbers, payment history), and an internal RTKBase system, which is an open-source platform for precise GPS corrections used by field teams
  • The surprising entry point was the GPS: the RTKBase system, which is usually installed on cheap hardware like a Raspberry Pi, was exposed via HTTP on port 10000 and served as a jumping-off point to the billing system
  • Most problematic: the admin passwords were published in plaintext, and these two systems were not supposed to be able to reach each other at all
  • The group made it clear that it could have disrupted the water supply but chose not to “according to hour”, defining the attack as revenge for American actions in Iran

7. Four Iranian banks have suffered a cyberattack:

  • Iranian media are reporting an attack that began this morning and disrupted the operations of four banks: Melli, Tejarat, Saderat and Export Development
  • The disruptions were felt in banking applications, ATMs, payment terminals and money transfers – The Coordination Council of State Banks in Iran issued an official statement stating that this was a limited cyberattack, and that there was no unauthorized access to customer information and no information was leaked

8. iRhythm Technologies, the developer of the Zio smart heart monitoring patches, reported a cyber incident during which personal and medical information of patients was stolen.

According to the company, the attackers managed to gain access to several business applications managed by third-party providers using social engineering techniques.

After the intrusion, data including personally identifiable information (PII), health information (PHI) and other internal company information was stolen.

The company emphasized that the medical devices themselves, clinical systems and manufacturing processes were not compromised, and that there was no risk to patient safety.

The incident focused on business systems and not on the heart monitoring technology itself. iRhythm is considered one of the leading companies in the field of remote heart rate monitoring and analyzes billions of hours of pulse data using artificial intelligence-based technologies.

9. American Tower faces cyberattack

American Tower, one of the largest telecommunications infrastructure and cell tower companies, reports a cyberattack after the ShinyHunters group took responsibility for the incident.

According to reports, over 5.2 million records were exposed including personally identifiable information (PII), internal company data, as well as communication tower asset details including GPS coordinates and website access codes. The information is expected to be offered or disclosed by June 15, raising concerns about the impact on critical communications infrastructure and physical site security.

10. Pharmaceutical company Novo Nordisk, (the world’s largest manufacturer of insulin), reports a data leak.

The company announces that attackers accessed internal systems and stole data related to clinical trials.

The information includes sensitive details such as gender, year of birth, health information and more, but the company claims that the information does not allow the identification of patient names.

In addition to the clinical trial information, additional information about staff members was also stolen and the company has informed those affected and warned against phishing attempts.

The company indicates that business operations continue as usual.

The cybersecurity attacks highlighted in this report aren’t just incidents, they’re blueprints of the adversary’s arsenal. To protect your business you need the right partner. CyberOne is here to help! Check out our services.