Join our Upcoming Free Webinar · Continuous Pentesting in DevSecOps using AI Agents  on July 9 at 8 PM IST / 10:30 AM EST · Seats are LimitedRegister Now
Strobesstrobes
Platform
Solutions
Resources
Customers
Company
Pricing
Book a Demo
Strobesstrobes

Strobes connects every exposure signal to autonomous action, so security teams fix what matters, prove what works, and stop chasing noise.

Book a DemoTalk to an expert
ISO 27001SOC 2CREST
  • Platform
  • Platform Overview
  • Agentic Exposure Management
  • AI Agents
  • Integrations
  • API & Developers
  • Workflows & Automation
  • Analytics & Reporting
  • Solutions
  • Exposure Assessment (EAP)
  • Attack Surface Management
  • Application Security Posture
  • Risk-Based Vulnerability Management
  • Adversarial Exposure Validation (AEV)
  • AI Pentesting
  • Pentesting as a Service
  • CTEM Framework
  • By Industry
  • Financial Institutions
  • Technology
  • Retail
  • Healthcare
  • Manufacturing
  • By Roles
  • CISOs
  • Security Directors
  • Cloud Security Leaders
  • App Sec Leaders
  • Resources
  • Quick Agentic Pentest
  • Blog
  • Customer Stories
  • eBooks
  • Datasheets
  • Videos & Demos
  • Exposure Management Academy
  • CTEM Maturity Assessment
  • Pentest Health Check
  • Security Tool ROI Calculator
  • Company
  • About Strobes
  • Meet the Team
  • Trust & Security
  • Contact Us
  • Careers
  • Become a Partner
  • Technology Partner
  • Partner Deal Registration
  • Press Release

Weekly insight for security leaders

CTEM research, agentic AI trends, and what's actually moving the needle.

© 2026 Strobes Security Inc. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyAccessibilitySitemap
Back to Blog
Top 8 Data Breaches and Exposures of June 2026
Data BreachesSupply Chain Security

Top 8 Data Breaches and Exposures of June 2026

Shubham JhaJune 30, 202613 min read

Table of Contents

  • June 2026 breaches at a glance
  • 1. The 24-billion-record credential dump
  • 2. The Oracle PeopleSoft campaign across US universities
  • 3. The Klue OAuth supply chain attack
  • 4. Texas Parks and Wildlife: 3M+ exposed through a license vendor
  • 5. Xsolis: one phishing email, 1.4M healthcare records
  • 6. Tata Electronics: the APAC manufacturing hit
  • 7. University of Nottingham: the clearest PeopleSoft victim
  • 8. Eastman Kodak: confirmed access, claimed 2.2M count
  • What June 2026 actually tells security teams
  • Sources
  • Related Reading

Authors

S
Shubham Jha

Share

Table of Contents

  • June 2026 breaches at a glance
  • 1. The 24-billion-record credential dump
  • 2. The Oracle PeopleSoft campaign across US universities
  • 3. The Klue OAuth supply chain attack
  • 4. Texas Parks and Wildlife: 3M+ exposed through a license vendor
  • 5. Xsolis: one phishing email, 1.4M healthcare records
  • 6. Tata Electronics: the APAC manufacturing hit
  • 7. University of Nottingham: the clearest PeopleSoft victim
  • 8. Eastman Kodak: confirmed access, claimed 2.2M count
  • What June 2026 actually tells security teams
  • Sources
  • Related Reading

Authors

S
Shubham Jha

Share

TL;DR
  • June's biggest single exposure wasn't a hack. Cybernews found a publicly exposed 8 TB database holding 24 billion credential records, mostly infostealer logs scraped from 36 sources.
  • ShinyHunters ran two parallel mass campaigns: an Oracle PeopleSoft exploit chain that hit 100+ organizations (mostly universities, including Nottingham), and the Klue OAuth supply chain attack that pulled customer data out of LastPass and a dozen others through Salesforce.
  • Almost none of these required breaking the victim's own code. A vendor held the access, a token was never rotated, a database sat public, or one employee clicked one link.
  • Tata Electronics confirmed a cyberattack on its IT infrastructure after files tied to Apple and Tesla production appeared online, the standout APAC incident of the month.
  • Everything below is confirmed by an official notice, a regulatory filing, or a primary security outlet. Attacker-claimed counts are flagged as claims.

June 2026 made the same point twice over. You don't get breached because someone cracked your encryption. You get breached because a token nobody rotated still works, a database nobody knew was public sits open for months, or one person clicks one link.

The month's single largest exposure was a misconfigured database, not a break-in. Its two largest campaigns reused one idea: find a weakness deployed across hundreds of organizations, scan for it at scale, and walk in everywhere at once. Below are the eight data breaches of June 2026 that mattered most, ranked by scale and impact, followed by the four things actually worth doing about them.

June 2026 breaches at a glance

#OrganizationScaleAttack typeThreat actorConfidence
124B credential dump24B records, 8 TBExposed databaseN/AConfirmed exposure (Cybernews)
2Oracle PeopleSoft campaign100+ orgsExploit chainShinyHuntersConfirmed campaign, counts attacker-claimed
3Klue / LastPass et al.15+ orgsOAuth supply chainIcarusConfirmed by named victims
4Texas Parks and Wildlife3,087,721 individualsThird-party vendorUnknownConfirmed by agency
5Xsolis1,396,519PhishingUnknownConfirmed, HHS-filed
6Tata ElectronicsUndisclosedCyberattack on ITUnknownAttack confirmed, file scope unverified
7University of Nottingham450,000+PeopleSoft exploitShinyHuntersConfirmed by university
8Eastman Kodak2.2M claimedExtortion / data theftShinyHuntersAccess confirmed, count attacker-claimed

1. The 24-billion-record credential dump

Discovered June 12, 2026 · Exposed database · Global · No actor (misconfiguration)

On June 12, Cybernews researchers found a publicly exposed database holding more than 24 billion credential records, one of the largest such collections ever left open on the internet. It ran past 8 terabytes, and the majority was infostealer logs: usernames, passwords, and the specific services each pair unlocked. The contents had been aggregated from 36 sources, including Telegram channels, prior breach compilations, and logs harvested directly from infected machines.

The database belonged to a threat intelligence company and was taken offline soon after discovery. Researchers were unable to fully analyze the contents or remove duplicates before it was pulled, leaving open how long it had been reachable and by whom.

What makes this the month's largest exposure is not any single victim. It is the aggregation. Thousands of prior breaches and years of infostealer activity, consolidated into one searchable index, become the raw material for the identity-driven attacks that fill the rest of this list. A leaked password is only useful if it still works, and at this volume, a meaningful share of them will.

The risk is not that this dataset exists. The risk is that too many of the credentials inside it may still work.

2. The Oracle PeopleSoft campaign across US universities

Oracle advisory June 10, 2026 · Education and enterprise · Global · ShinyHunters

This was not one organization getting unlucky. It was a single shared enterprise platform turning into a mass target. ShinyHunters claimed to have compromised the Oracle PeopleSoft servers of more than 100 organizations, predominantly colleges and universities, exploiting the suite they rely on for HR, finance, and student administration. In a message to one affected institution, the group itemized what it had taken: names, home addresses, phone numbers, emails, dates of birth, ethnicity, enrollment status, GPAs, majors, and student IDs.

Oracle published a security advisory on June 10, the day the attacks went public, urging immediate mitigation and noting that only supported PeopleTools versions had been tested, with older versions assumed vulnerable as well. The scale here is a confirmed campaign across 100+ organizations; the specific record totals come from ShinyHunters and remain attacker claims until victims verify them individually.

The campaign fits a year-long ShinyHunters method of hunting for one weakness in widely deployed software, then scanning for it everywhere, following earlier waves against Salesforce, Salesloft Drift, Snowflake, and Canvas. Education absorbed the brunt because universities run PeopleSoft widely and patch it slowly. Nottingham, at #7, is the clearest single example of what this looked like on the ground.

ShinyHunters did not need 100 different ideas. One shared platform was enough.

3. The Klue OAuth supply chain attack

Discovered June 12, 2026 · Supply chain · Global · Icarus

This breach did not start inside any victim's own systems. It started with the access someone else held on their behalf. Klue discovered unauthorized activity in its integration infrastructure on June 12, tracing it to a legacy credential left active from a retired integration. Through that credential, the Icarus extortion group reached the OAuth tokens Klue held to connect into its customers' Salesforce environments, then used them to authenticate directly into customer CRM instances and exfiltrate data in bulk with automated scripts. No victim was phished, no password was cracked, and no vulnerability was exploited on the victims' side.

LastPass confirmed on June 23 that support-case data from its Salesforce environment had been taken, while noting that its products, infrastructure, and password vaults were unaffected. It was one of many. Recorded Future, Tanium, Jamf, Snyk, Sprout Social, Gong, Insurity, HackerOne, and OneTrust all confirmed exposure through the same token pipeline, bringing the confirmed victim count past 15, with Huntress and others warning the list would grow.

That is the defining property of a supply chain attack: a single token theft at one vendor reaches every downstream customer integrated with it, and none of them can see it happen, because the compromise occurs in an environment they have no visibility into.

The victims did not lose data because their Salesforce was broken. They lost it because a trusted integration stayed trusted long after it should have been reviewed.

4. Texas Parks and Wildlife: 3M+ exposed through a license vendor

Disclosed June 19, 2026 · Government · United States · Unknown

This breach did not start inside the agency either. The Texas Parks and Wildlife Department disclosed an incident affecting 3,087,721 individuals, and the compromise occurred not in TPWD's systems but at the third-party vendor that operates its hunting and fishing license platform. Texas Cyber Command detected the intrusion and TPWD was notified on May 13; the department published its formal notification on June 12 and disclosed publicly on June 18. Per TPWD's own notice, the exposed data includes driver's license information, passport numbers where provided, email addresses, phone numbers, and residential addresses, while Social Security numbers, dates of birth, and financial details were not taken.

That data mix is the part worth sitting with. Driver's license and passport numbers cannot be reset the way a password or card can, which is why TPWD is offering a year of Kroll credit monitoring and the Texas Attorney General's breach portal lists the incident among the state's largest this year. And it follows the dominant pattern across June's data breaches: an agency delegates a function, the vendor holds the records, the vendor is compromised, and the agency carries the disclosure for three million people who had no awareness of the vendor and no relationship with it.

A leaked password can be reset overnight. A driver's license number stays exposed for life.

5. Xsolis: one phishing email, 1.4M healthcare records

Disclosed June 23, 2026 · Healthcare · United States · Unknown

A single phishing email, sent to one employee on January 20, gave attackers a two-day window inside healthtech firm Xsolis before the activity was detected on January 22. That window was enough to exfiltrate files affecting 1,396,519 individuals, including names, dates of birth, Social Security numbers, health insurance details, and medical treatment records. Xsolis filed the incident to the US Department of Health and Human Services, which posted the count to its breach portal in late June, and downstream health systems including Mayo Clinic confirmed their patients were affected.

Xsolis operates out of view, providing utilization and case management to more than 600 hospitals and insurers. That concentration is precisely why one compromised account exposed patient data across dozens of health systems at once. The initial access required no exploit and no zero-day, only a credential handed over to a phishing message.

One inbox mistake became a healthcare data incident across dozens of downstream organizations.

6. Tata Electronics: the APAC manufacturing hit

Confirmed June 22, 2026 · Manufacturing · India · Unknown

June's most significant APAC breach surfaced through leaked files rather than a ransom listing. Material allegedly tied to Apple and Tesla manufacturing began appearing online, threat actors claimed to hold a larger archive, and on June 22 Tata Electronics confirmed to BleepingComputer that it had been targeted in a cyberattack affecting parts of its IT infrastructure. What is established is the attack itself, confirmed by the company. What is not is the origin and full contents of the leaked files, which remained unverified and under investigation as the month closed.

The breach carries weight beyond a typical manufacturing incident because of Tata Electronics' position as a critical link in the global electronics supply chain. A compromise at a contract manufacturer extends to the intellectual property and production data of its brand-name clients, none of whom controlled how their supplier secured its systems.

The clients whose data was exposed never audited Tata's security. They inherited the consequences of it anyway.

7. University of Nottingham: the clearest PeopleSoft victim

Confirmed June 11, 2026 · Education · United Kingdom · ShinyHunters

If the PeopleSoft campaign at #2 is the wave, Nottingham is the clearest look at what it did when it hit shore. The University of Nottingham confirmed that attackers accessed its student records system, exposing data belonging to more than 450,000 current students and alumni. With over 46,000 students and 7,000 staff, the university reported the incident to the UK's Information Commissioner's Office.

What makes Nottingham instructive is the context. It was not singled out. It was simply running an exposed PeopleSoft instance when ShinyHunters scanned for them, and it became the second UK university to disclose within days, following Oxford. Two institutions, the same weakness, the same week.

Nottingham was not targeted for being Nottingham. It was targeted for running the software everyone else was running too.

8. Eastman Kodak: confirmed access, claimed 2.2M count

Listed June 15, 2026 · Manufacturing · United States · ShinyHunters

Two accounts of this incident exist, and the gap between them is the story. ShinyHunters listed Kodak on its leak site on June 15, claiming more than 2.2 million records of customer PII and internal corporate files, and set a June 18 deadline to pay before publication. Kodak's own statement was far narrower: an unauthorized third party briefly accessed a limited amount of company data.

Hold on to that distinction. Kodak confirmed unauthorized access. The 2.2 million record count came from ShinyHunters, so it stays an attacker claim until the data is independently verified, and Kodak has not publicly attributed the breach to the group. The mechanics are otherwise the familiar ShinyHunters sequence, run all year: list a victim, set a deadline, threaten release, escalate, and work several extortion cases at once. Kodak was one of June's.

Confirmed access and a claimed record count are not the same thing, and the difference is worth holding onto until the data is verified.

What June 2026 actually tells security teams

Strip away the logos and the same three threads run through almost every breach above.

Access was the way in, not exploits against the victim. The credential dump, the Klue token theft, the Xsolis phish, the TPWD vendor. None required breaking the victim's own code. They required a working credential, an un-rotated token, or one click. Standing access nobody is watching is the dominant exposure class of 2026.

Third-party access carries the damage downstream. TPWD, Klue's 15+ customers, Tata's clients, every PeopleSoft and Salesforce victim. The breached organization often wasn't the one holding the weakness. The vendor held the access and the customer absorbed the disclosure, blind to the compromise until data hit a leak site.

One weakness, deployed everywhere, becomes a mass campaign. ShinyHunters didn't find 100 ways into 100 universities. It found one PeopleSoft flaw and scanned for it. Same with the Klue OAuth tokens across Salesforce tenants. When attackers industrialize a single flaw across every org running the affected software, an annual pentest can't keep pace.

So the defense isn't eight different checklists. It's four moves that map to the patterns above:

  1. Treat credential exposure as continuous. Monitor your domains and employee accounts in infostealer feeds, enforce phishing-resistant MFA, and move high-value access toward passkeys. A reset closes the window the 24-billion-record dump leaves open.
  2. Put third-party access on your attack surface map. Inventory every vendor and SaaS integration that holds data or OAuth tokens into your environment, scope each to the minimum needed, and rotate on any incident or contract end. This is the gap the exposure management view is built to close.
  3. Patch internet-facing enterprise software on attacker time. PeopleSoft, your CRM, your support platforms. The window between an Oracle advisory and mass exploitation is measured in days, not quarters. Treat unsupported versions as already compromised.
  4. Validate, don't assume. A point-in-time pentest tells you what was exploitable last quarter. Continuous validation proves what's reachable right now and re-checks every fix, which is the only way to keep up with attackers who rescan the moment you change anything. ShinyHunters has run this model across education, retail, manufacturing, and enterprise SaaS in a single year.

Strobes perspective

The PeopleSoft campaign is a clean illustration of the real gap. Every breached university had tooling that could see the PeopleSoft instance and list its CVEs. What none of it confirmed was whether that specific instance was actually exploitable from the outside, which is the only question ShinyHunters was asking. A flagged vulnerability and a validated exploit are not the same thing, and the distance between them is where these breaches happened. Scanning tells you what exists; adversarial validation tells you what an attacker can actually reach.

Sources

  1. Cybernews — 24 billion credentials exposed
  2. Texas Parks and Wildlife Department — Notification of Data Security Incident (primary)
  3. SecurityWeek — Texas Parks and Wildlife data breach affects 3 million
  4. BleepingComputer — LastPass confirms breach in Klue supply chain attack
  5. BleepingComputer — Klue OAuth breach victim list grows
  6. Help Net Security — Xsolis phishing breach (HHS-filed count)
  7. BleepingComputer — Nottingham University data breach
  8. SWK Technologies — June 2026 cybersecurity recap (Kodak, PeopleSoft)
  9. SecurityWeek — BeyondTrust, LastPass impacted by Klue-Salesforce incident

Written by Shubham Jha, Product Marketing Lead at Strobes. Shubham covers the offensive security and exposure management beat for Strobes, tracking the breach campaigns and CVE activity shaping how security teams defend their attack surface.

Related Reading

  • What Is an Exposure Assessment Platform?
  • Top 10 Exposure Management Platforms That Truly Reduce Risk
  • Adversarial Exposure Validation (AEV)
  • Tracking ShinyHunters and Supply Chain Ransomware Threat Actors
Tags
data breaches June 2026ShinyHunters PeopleSoftKlue OAuth breach24 billion recordssupply chain attackthird-party vendor breachbiggest data breaches 2026

Stop chasing vulnerabilities Start reducing exposure

See how Strobes AI agents validate and fix your most critical exposures automatically.

Book a Demo
Continue Reading

Related Posts

Top Databreaches of May 2026
Data BreachesSupply Chain Security

Top 8 Data Breaches of May 2026

The 8 confirmed data breaches of May 2026, from the 275M-record Canvas LMS breach to GitHub's VS Code supply chain attack, and how to defend against each pattern.

Jun 3, 202622 min
The TanStack npm Attack That Punishes You for Fixing It — 170+ packages compromised, 84 malicious versions, 6 min publish window, 518M cumulative downloads
Supply Chain SecurityCybersecurity

The TanStack npm Supply Chain Attack That Hit 170 Packages and Punishes You for Revoking Your Token

The TanStack npm supply chain attack hit 12 million weekly downloads using three public techniques and zero novel code. Here is exactly how it worked.

May 13, 202613 min
Top 10 Data Breaches of April 2026 - Monthly Security Briefing
Data BreachesCybersecurity

Top 10 Data Breaches of April 2026

The biggest data breaches of April 2026 ranked and analyzed, from Checkmarx supply chain poisoning to Salesforce misconfigurations and ransomware hitting two major US banks.

May 1, 202615 min