• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
  • X
  • Facebook
  • YouTube
  • LinkedIn
Screen Connect
Support
Customer Portal
Pay Online
SWK logo.

SWK Technologies

Software Solutions & Services

  • Accounting & ERP Software
      • Acumatica Cloud ERP
        • Overview
        • Construction
        • Distribution
        • Field Service
        • Financial Management
        • Manufacturing
        • Professional Services
        • Project Accounting
        • Retail-Commerce
      • Sage Intacct
        • Overview
        • Construction and Real Estate (CRE)
        • Distribution Operations for Sage Intacct
        • Financial Services
        • Healthcare
        • Manufacturing Operations for Sage Intacct
        • Nonprofits
        • Professional Services
        • Sage Intacct Payroll powered by ADP
      • Sage 100
        • Overview
        • Business Intelligence
        • Core Accounting & Financials
        • Distribution
        • Manufacturing
        • Payroll
        • Sage 100 Contractor
      • More Accounting Products
        • QuickBooks
        • Sage 50
        • Sage 300
        • Sage 500
        • Sage BusinessWorks
      • ERP Add-ons
        • ADP Workforce Now
        • Avalara
        • AvidXchange
        • BILL
        • BigCommerce
        • CIMCloud
        • Cloud Hosting
        • DataSelf
        • DocLink
        • Endpoint Automation Solutions
        • Fortis
        • FreightPOP
        • Lumber
        • Microsoft 365
        • Netstock
        • Quadient
        • Sage Fixed Assets
        • Sage HCM
        • Sage Intacct Payroll powered by ADP
        • Sage Supply Chain Intelligence
        • Savant WMS
        • ScanForce
        • Solver
        • SPS Commerce
        • Velixo
        • Workforce Go!
      • More ERP Add-ons
        • Crystal Reports
        • KnowledgeSync
        • Nuvei
        • Nectari
        • Ottimate
        • Pacejet
        • Planning Maestro
        • Sage CRM
        • Sage HRMS
        • Sage Intelligence
        • Service Pro
        • ShipStation
        • Shopify
        • Starship
        • Sugar CRM
        • Traild
      • Industries
        • Construction
        • Distribution
        • Financial Services
        • Healthcare
        • Manufacturing
        • Nonprofit
        • Professional Services
        • Retail
  • Managed Cloud Services
      • Managed IT Services
        • Managed Cloud Services
        • Network Assurance Core
        • Co-Managed IT
        • Email Hosting
        • IT Support
        • Microsoft 365 Services
        • Server Monitoring
        • Virtualization
      • Cybersecurity
          • CyberAssurance CORE™
          • Cybersecurity Solutions
          • Backup & Continuity
          • Compliance
          • Dark Web Monitoring
          • EDR
          • Encryption
          • MDR
          • MFA
          • Penetration Testing
          • Security Training
          • SOC
          • Spam & Virus Filtering
          • vCIO
          • Vulnerability Assessment
      • Cloud Services
        • Secure Cloud Hosting
        • Infrastructure-as-a-Service
        • Acumatica IaaS
      • Industries
        • Financial Services
        • Healthcare
        • Construction
      • Locations
          • Nationwide
          • Austin
          • California
          • Chicago
          • Minneapolis
          • New Jersey
          • New York
          • North Carolina
          • Philadelphia
          • Phoenix
          • San Diego
          • Seattle
  • Consulting & Implementation
    • Business Technology Consulting
    • eCommerce
    • Financing
    • Human Capital Management
    • Managed Cloud & IT Services
    • Partner Program
    • Software Development
    • Software Implementation
  • Resources
    • Help Desk
    • Blog Posts
    • Payments Portal
    • Webinars
    • YouTube Channels
    • Acumatica Resources
    • Sage Intacct Resources
    • Sage 100 Resources
    • IT Resource Pages
  • About
    • About SWK
    • Awards & Recognition
    • Life@SWK
    • Careers
    • Success Stories
    • SWK Gives
  • Contact
    • Contact Us
    • Support
    • Our Locations

SWK Cybersecurity News Recap July 2026

July 23, 2026 by Hector Bonilla

Home » Cybersecurity » SWK Cybersecurity News Recap July 2026

Flat lay of a paper July calendar on a yellow and coral background surrounded by rainbow-tinted sunglasses, a coral leather bag, orange drop earrings, assorted seashells, a watermelon wedge on a white plate, grapefruit slices on a gray plate and shell bracelets.

Even before the midpoint of the summer, cyber incidents and major security efforts by both the public and private sectors have already set the tone for the second half of 2026. From continued ShinyHunters attacks and a heated ransomware rivalry to Treasury sanctions and a federal network breach ahead of the FIFA World Cup, July gave security teams plenty to work through. SWK Technologies has put together this Cybersecurity News Recap to help you keep track of the latest developments and biggest headlines from this month:

ShinyHunters Continues Targeting Healthcare, Education and More

The infamous ShinyHunters group kept up its momentum from previous months with new attacks in July 2026 against healthcare giant Abbott Laboratories, added to the group’s data leak site in mid-July after the attackers gained access through a voice phishing campaign targeting employees the prior month. The intrusion reportedly compromised a corporate Microsoft Entra single sign-on account tied to Abbott’s Cancer Diagnostics business, with the group initially setting a July 18 leak deadline before extending negotiations to July 21.

ShinyHunters has been active since 2020 and built an early reputation on large-scale data theft against consumer telecoms, retailers and cloud platforms during a series of high-profile compromises across that period, later broadening in recent years to the Salesforce ecosystem and enterprise identity infrastructure. On July 13, Microsoft’s Defender Security Research team published research mapping a year of similar activity across Salesforce environments in retail, education and manufacturing, in which the attackers abused trusted OAuth relationships and long-lived application tokens rather than exploiting the platform directly, matching the same abuse pattern behind the Abbott intrusion and giving the July advisories a shared technical fingerprint across ShinyHunters’ overlapping campaigns. Google Threat Intelligence Group and Mandiant also separately attributed a zero-day campaign against Oracle PeopleSoft to the same group and its affiliates in June 2026, and Oracle later released an out-of-band fix for the underlying flaw.

Rivalry Between Ransomware Groups Fuels More Attacks in 2026

The Qilin and Gentlemen hacker groups are both neck-and-neck for the top ransomware attacker in 2026, each overtaking the other throughout the month of July, which some experts say is fueled by a rivalry between the two cybercriminal collectives. According to multiple reports tracking Q2 2026 activity, Qilin and The Gentlemen each claimed nearly 300 victims in the financial quarter alone, and several trackers logged a June in which The Gentlemen topped Qilin’s monthly count for the first time this year. Total ransomware volume across the world rose roughly 20 percent year over year through the first half of 2026, alongside a 74 percent quarter-over-quarter jump in attacks against billion-dollar companies.

U.S.-based small and mid-sized businesses continue to absorb the largest share of incidents from both groups, though recent activity shows the same actors reaching further into larger targets. Rising SMB targeting alongside more frequent hits against larger businesses continues to shape ransomware activity in 2026 as competition among top-tier groups intensifies.

NSA Warns of Russian-Sponsored Attacks Against Routers

The National Security Agency (NSA) published an advisory alongside CISA and international partners warning that cyber actors linked to the Russian Federal Security Service (FSB) Center 16 continue to compromise poorly configured routers and networking devices tied to critical infrastructure. Nineteen agencies across thirteen countries co-signed the July 13 guidance, cataloged by CISA as AA26-194A and building on an August 2025 FBI notice that first flagged the same targeting pattern.

According to the advisory, attackers scan the internet for exposed routers still running default or common Simple Network Management Protocol community strings, pull configuration files once inside and pivot to move credentials back to attacker-controlled infrastructure. The guidance calls for changing default credentials, restricting remote management, patching firmware, disabling Cisco Smart Install where it is not needed and treating Internet-facing network equipment as a priority attack surface.

Anubis Ransomware Group Takes Down Coca Cola Dairy Firm

The Anubis ransomware group listed Coca-Cola dairy production subsidiary Fairlife on its leak website on July 20, 2026, only a few days after the parent company had notified the SEC of the initial breach. Coca-Cola disclosed the incident on July 16 in a Form 8-K filing, confirming that attackers had reached parts of Fairlife’s environment tied to production and prompting the company to temporarily suspend U.S. production while Canadian operations continued. Product safety and quality were not affected per the company’s statement, and Coca-Cola activated its incident response and business continuity plans while engaging outside cybersecurity advisors and notifying law enforcement.

Anubis surfaced in late 2024 and operates as a financially motivated ransomware-as-a-service crew that leans heavily on public leak site pressure, following a pattern similar to prior manufacturing sector attacks where downtime and reputational cost push victims toward negotiation. The group claims to have exfiltrated one terabyte of confidential Fairlife data and set a leak deadline within the week, applying the same double-extortion pressure model that has defined much of the ransomware activity across 2026.

Report Says Ohio County May Have Paid Ransom for Files

A report by a cyber intelligence investigator published on July 3 claims that they uncovered that a U.S. government agency paid a ransom to obtain access to files stolen by a threat actor, evidenced by chat transcripts between both parties published online. The case study traces a roughly $1 million bitcoin payment — around 9.44 BTC at the time — to a group calling itself Kairos, which never encrypted the victim’s systems and relied only on data-theft extortion. Several news outlets covering the story have speculated that Union County, Ohio is the most likely victim based on file names appearing in proof-of-theft samples shared during negotiations, though neither the county nor Kairos has confirmed the connection.

Initial access reportedly came through password guessing against infrastructure that lacked multi-factor authentication, after which more than two terabytes of data — including Social Security numbers, financial records and fingerprint files — were exfiltrated. Even where a victim pays, proof of deletion rests on the attacker’s word, and the FBI has consistently advised against ransom payments because there is no way to verify that stolen data has actually been destroyed.

US Treasury Sanctions Ukrainian VPN for Supporting Ransomware

First VPN Service (1VPNS), a virtual private network ostensibly favored by ransomware operators, was sanctioned by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) on July 13, 2026. The action also designated the VPN’s Ukrainian administrator, Dmytro Rashevskyi, and Belarusian national, Yegeniy Vladimirovich Silayev, both on the basis of providing services to known ransomware groups. The Treasury said 1VPNS advertised on cybercriminal forums since 2014, promoted a no-logs policy and refused to cooperate with law enforcement, while Silayev sold cryptors used to disguise ransomware as safe software.

The Treasury’s sanction designations prohibit any U.S. person from transacting with the named parties and expose downstream providers to compliance risk. The sanctions follow Operation Saffron, a May 2026 European law enforcement action supported by the FBI’s Boston Field Office that seized 33 servers across 27 countries and dismantled the 1VPNS website, and mark the first time OFAC has ever designated a VPN provider for facilitating ransomware.

DHS Ignored Signs of Network Breach Before FIFA World Cup

Nextgov/FCW reported in mid-July that the Department of Homeland Security dismissed two separate alerts as false positives before confirming an active intrusion into its Homeland Security Information Network. The publication first disclosed the breach in late June, and DHS confirmed the incident on July 1, describing it as an event affecting a legacy unclassified information-sharing environment and asserting that no classified networks were compromised. Attackers are believed to have entered the network between late May and early June, remaining undetected long enough to steal credential files, run malicious code and delete logs.

Senator Mark Warner, vice chair of the Senate Select Committee on Intelligence, called for a Department of Justice investigation and warned that even the unclassified data hosted on HSIN carries national security weight. Warner noted the platform is currently supporting security operations for the FIFA World Cup games hosted across the United States. The intrusion joins other recent federal breaches, including the November 2025 compromise of the Congressional Budget Office attributed to a suspected foreign nation-state actor.

Cybersecurity News Continues to Develop in 2026

The summer of 2026 has been quite busy for cybersecurity news, as has the entire year at this point, and there are few signs that this trend may stop any time soon. Staying informed on how threats are evolving remains one of the more valuable habits your business can build in a year defined by ransomware activity, nation-state campaigns and federal breaches.

Contact SWK here to learn more about how our team can help your business stay informed on the latest cybersecurity news.

Sign Up for More

Category: Cybersecurity, Blog, News and Events

Sidebar

Recent Posts

  • SWK Cybersecurity News Recap July 2026
  • How to Set Up Microsoft 365 Copilot for Your Business
  • Data Center Construction Cash Forecasting and Risk Mitigation
  • How Much Weak Cybersecurity Costs Your Business
  • SWK Technologies Ranks on Accounting Today VAR 100 for 2026
  • Sage 100 2026 64-Bit Transition: What CFOs and Controllers Should Review Before Upgrading
  • SWK Helps Dillon Precision Modernize Ammunition Reloading Manufacturing with Acumatica

Categories

Ready to take the next step?

Contact SWK today to get in touch with one of our experts. We’ll go over your business challenges and unique needs, and see where you can unlock new value from your technology and make your operations run easier.

Get in touch!

Our Latest Posts

Flat lay of a paper July calendar on a yellow and coral background surrounded by rainbow-tinted sunglasses, a coral leather bag, orange drop earrings, assorted seashells, a watermelon wedge on a white plate, grapefruit slices on a gray plate and shell bracelets.

SWK Cybersecurity News Recap July 2026

Read moreSWK Cybersecurity News Recap July 2026
Microsoft Surface Studio all-in-one desktop displaying a Windows setup screen — a large Windows logo above the text "Getting ready" and a small circular loading indicator — with a Surface Pen resting on the base of the stand, a Surface keyboard and Surface Mouse arranged on the white desk in front and a softly blurred office in the background.

How to Set Up Microsoft 365 Copilot for Your Business

Read moreHow to Set Up Microsoft 365 Copilot for Your Business
Data center construction cash forecasting for grid interconnection delays

Data Center Construction Cash Forecasting and Risk Mitigation

Read moreData Center Construction Cash Forecasting and Risk Mitigation

Awards and Accreditations

Top work places in NJ 2020.
Acumatica the Cloud ERP gold certified partner.
The Gold Microsoft partner logo on a black background.
Sage business partner diamond logo.
Dell Technologies Gold Partner
Sage tech partner logo.

Stay in the know!

Subscribe for exclusive ERP, process automation, IT and cybersecurity news.

Twitter
  • Facebook
  • YouTube
  • LinkedIn

Home
About
Contact

Support
Screen Connect
Pay Online
Downloads

SWK logo.

Headquarters:
120 Eagle Rock Ave, Suite 330
East Hanover, NJ 07936

Contact:
info@swktech.com
(877) 979-5462

Copyright © 2026 · SWK Technologies, Inc. · All Rights Reserved · Terms of Use · Privacy Policy

This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. By continuing to browse this site you agree to the use of cookies. Visit our privacy policy to learn more.