
Even before the midpoint of the summer, cyber incidents and major security efforts by both the public and private sectors have already set the tone for the second half of 2026. From continued ShinyHunters attacks and a heated ransomware rivalry to Treasury sanctions and a federal network breach ahead of the FIFA World Cup, July gave security teams plenty to work through. SWK Technologies has put together this Cybersecurity News Recap to help you keep track of the latest developments and biggest headlines from this month:
ShinyHunters Continues Targeting Healthcare, Education and More
The infamous ShinyHunters group kept up its momentum from previous months with new attacks in July 2026 against healthcare giant Abbott Laboratories, added to the group’s data leak site in mid-July after the attackers gained access through a voice phishing campaign targeting employees the prior month. The intrusion reportedly compromised a corporate Microsoft Entra single sign-on account tied to Abbott’s Cancer Diagnostics business, with the group initially setting a July 18 leak deadline before extending negotiations to July 21.
ShinyHunters has been active since 2020 and built an early reputation on large-scale data theft against consumer telecoms, retailers and cloud platforms during a series of high-profile compromises across that period, later broadening in recent years to the Salesforce ecosystem and enterprise identity infrastructure. On July 13, Microsoft’s Defender Security Research team published research mapping a year of similar activity across Salesforce environments in retail, education and manufacturing, in which the attackers abused trusted OAuth relationships and long-lived application tokens rather than exploiting the platform directly, matching the same abuse pattern behind the Abbott intrusion and giving the July advisories a shared technical fingerprint across ShinyHunters’ overlapping campaigns. Google Threat Intelligence Group and Mandiant also separately attributed a zero-day campaign against Oracle PeopleSoft to the same group and its affiliates in June 2026, and Oracle later released an out-of-band fix for the underlying flaw.
Rivalry Between Ransomware Groups Fuels More Attacks in 2026
The Qilin and Gentlemen hacker groups are both neck-and-neck for the top ransomware attacker in 2026, each overtaking the other throughout the month of July, which some experts say is fueled by a rivalry between the two cybercriminal collectives. According to multiple reports tracking Q2 2026 activity, Qilin and The Gentlemen each claimed nearly 300 victims in the financial quarter alone, and several trackers logged a June in which The Gentlemen topped Qilin’s monthly count for the first time this year. Total ransomware volume across the world rose roughly 20 percent year over year through the first half of 2026, alongside a 74 percent quarter-over-quarter jump in attacks against billion-dollar companies.
U.S.-based small and mid-sized businesses continue to absorb the largest share of incidents from both groups, though recent activity shows the same actors reaching further into larger targets. Rising SMB targeting alongside more frequent hits against larger businesses continues to shape ransomware activity in 2026 as competition among top-tier groups intensifies.
NSA Warns of Russian-Sponsored Attacks Against Routers
The National Security Agency (NSA) published an advisory alongside CISA and international partners warning that cyber actors linked to the Russian Federal Security Service (FSB) Center 16 continue to compromise poorly configured routers and networking devices tied to critical infrastructure. Nineteen agencies across thirteen countries co-signed the July 13 guidance, cataloged by CISA as AA26-194A and building on an August 2025 FBI notice that first flagged the same targeting pattern.
According to the advisory, attackers scan the internet for exposed routers still running default or common Simple Network Management Protocol community strings, pull configuration files once inside and pivot to move credentials back to attacker-controlled infrastructure. The guidance calls for changing default credentials, restricting remote management, patching firmware, disabling Cisco Smart Install where it is not needed and treating Internet-facing network equipment as a priority attack surface.
Anubis Ransomware Group Takes Down Coca Cola Dairy Firm
The Anubis ransomware group listed Coca-Cola dairy production subsidiary Fairlife on its leak website on July 20, 2026, only a few days after the parent company had notified the SEC of the initial breach. Coca-Cola disclosed the incident on July 16 in a Form 8-K filing, confirming that attackers had reached parts of Fairlife’s environment tied to production and prompting the company to temporarily suspend U.S. production while Canadian operations continued. Product safety and quality were not affected per the company’s statement, and Coca-Cola activated its incident response and business continuity plans while engaging outside cybersecurity advisors and notifying law enforcement.
Anubis surfaced in late 2024 and operates as a financially motivated ransomware-as-a-service crew that leans heavily on public leak site pressure, following a pattern similar to prior manufacturing sector attacks where downtime and reputational cost push victims toward negotiation. The group claims to have exfiltrated one terabyte of confidential Fairlife data and set a leak deadline within the week, applying the same double-extortion pressure model that has defined much of the ransomware activity across 2026.
Report Says Ohio County May Have Paid Ransom for Files
A report by a cyber intelligence investigator published on July 3 claims that they uncovered that a U.S. government agency paid a ransom to obtain access to files stolen by a threat actor, evidenced by chat transcripts between both parties published online. The case study traces a roughly $1 million bitcoin payment — around 9.44 BTC at the time — to a group calling itself Kairos, which never encrypted the victim’s systems and relied only on data-theft extortion. Several news outlets covering the story have speculated that Union County, Ohio is the most likely victim based on file names appearing in proof-of-theft samples shared during negotiations, though neither the county nor Kairos has confirmed the connection.
Initial access reportedly came through password guessing against infrastructure that lacked multi-factor authentication, after which more than two terabytes of data — including Social Security numbers, financial records and fingerprint files — were exfiltrated. Even where a victim pays, proof of deletion rests on the attacker’s word, and the FBI has consistently advised against ransom payments because there is no way to verify that stolen data has actually been destroyed.
US Treasury Sanctions Ukrainian VPN for Supporting Ransomware
First VPN Service (1VPNS), a virtual private network ostensibly favored by ransomware operators, was sanctioned by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) on July 13, 2026. The action also designated the VPN’s Ukrainian administrator, Dmytro Rashevskyi, and Belarusian national, Yegeniy Vladimirovich Silayev, both on the basis of providing services to known ransomware groups. The Treasury said 1VPNS advertised on cybercriminal forums since 2014, promoted a no-logs policy and refused to cooperate with law enforcement, while Silayev sold cryptors used to disguise ransomware as safe software.
The Treasury’s sanction designations prohibit any U.S. person from transacting with the named parties and expose downstream providers to compliance risk. The sanctions follow Operation Saffron, a May 2026 European law enforcement action supported by the FBI’s Boston Field Office that seized 33 servers across 27 countries and dismantled the 1VPNS website, and mark the first time OFAC has ever designated a VPN provider for facilitating ransomware.
DHS Ignored Signs of Network Breach Before FIFA World Cup
Nextgov/FCW reported in mid-July that the Department of Homeland Security dismissed two separate alerts as false positives before confirming an active intrusion into its Homeland Security Information Network. The publication first disclosed the breach in late June, and DHS confirmed the incident on July 1, describing it as an event affecting a legacy unclassified information-sharing environment and asserting that no classified networks were compromised. Attackers are believed to have entered the network between late May and early June, remaining undetected long enough to steal credential files, run malicious code and delete logs.
Senator Mark Warner, vice chair of the Senate Select Committee on Intelligence, called for a Department of Justice investigation and warned that even the unclassified data hosted on HSIN carries national security weight. Warner noted the platform is currently supporting security operations for the FIFA World Cup games hosted across the United States. The intrusion joins other recent federal breaches, including the November 2025 compromise of the Congressional Budget Office attributed to a suspected foreign nation-state actor.
Cybersecurity News Continues to Develop in 2026
The summer of 2026 has been quite busy for cybersecurity news, as has the entire year at this point, and there are few signs that this trend may stop any time soon. Staying informed on how threats are evolving remains one of the more valuable habits your business can build in a year defined by ransomware activity, nation-state campaigns and federal breaches.
Contact SWK here to learn more about how our team can help your business stay informed on the latest cybersecurity news.
