
June 2026 was one of the worst months for cybersecurity in recent memory. Novo Nordisk got hit with a $25 million extortion attempt. Researchers found 24 billion exposed login credentials online. Nintendo confirmed a data breach through a third-party vendor. And Chinese state-backed hackers spent a decade inside an isolated network before anyone noticed.
Novo Nordisk: 1.3TB of Clinical Trial Data Stolen
The biggest single incident involved Novo Nordisk, the pharmaceutical giant behind Ozempic and Wegovy. Hackers group Hunters International claimed to have exfiltrated approximately 1.3 terabytes of data, including hundreds of thousands of files.
The stolen data included clinical trial patient information (sex, year of birth, biomarkers, health data, smoking and alcohol use, BMI), healthcare professional records, source code, drug research, manufacturing records, and internal AI models. Novo Nordisk confirmed that trial patient data had been pseudonymized, but the sheer volume and sensitivity of the breach raised alarm across the healthcare industry.
The attackers demanded $25 million. Novo Nordisk temporarily shut down some internal IT systems during the investigation. The breach occurred through an exposed developer credential, according to security researchers.
24 Billion Credentials Exposed in Massive Data Leak
On June 17, researchers at CyberNews revealed that approximately 24 billion login credentials had been exposed online. The credentials were compiled from numerous sources and represented one of the largest credential leaks ever documented.
The exposure dramatically increases the risk of account takeovers, identity theft, and large-scale credential-stuffing attacks. Users who reuse passwords across multiple services are particularly vulnerable. Security researchers recommended immediate password changes and mandatory two-factor authentication across all accounts.
Nintendo Data Stolen Through WebMD Subsidiary
Nintendo confirmed on June 18 that personal information belonging to job applicants was stolen after attackers breached a WebMD subsidiary’s recruitment platform. The data included applicant information that had been shared with Nintendo during the hiring process.
The breach did not affect Nintendo’s gaming infrastructure or customer accounts. It specifically targeted recruitment data, exposing the personal information of people who had applied for jobs at the company.
Other Major Breaches in June 2026
DentaQuest: 2.6 Million Accounts Exposed
One of the largest U.S. dental benefits administrators suffered a breach affecting 2.6 million people. The exposed data included Medicaid IDs and sensitive personal and health-related information, significantly increasing identity theft risk for affected members.
iRhythm Technologies: Patient Data Stolen
Medical device company iRhythm disclosed a breach in which hackers gained unauthorized access to systems and stole sensitive patient information. The company did not specify the number of affected individuals.
Chinese Hackers Compromise REDCap Servers
Chinese state-backed hackers breached vulnerable REDCap servers used by medical and research institutions, stealing sensitive medical research data. REDCap is a widely used web application for building and managing online surveys and databases in clinical research.
FortiBleed Campaign Targets FortiGate Devices
A campaign called FortiBleed deployed a custom sniffer on vulnerable FortiGate firewall devices, stealing user credentials and authentication data. Organizations running unpatched FortiGate appliances were at risk of network compromise.
Notable Cyber Attacks in June 2026
- ClickFix and FakeUpdate attacks hijacked thousands of legitimate websites, injecting malicious code that redirected visitors to malware pages.
- HTTP/2 Bomb DoS crashed vulnerable web servers in under a minute with a small number of malicious requests.
- IronWorm malware compromised 36 npm packages in a supply chain attack, exposing developers to credential theft.
- c0xM0 Botnet spread via DD-WRT router vulnerabilities, killing rival malware while expanding its network.
- GhostTree campaign used recursive Windows junctions to hide malware from security tools.
- USB Worm spread crypto-stealing malware through Windows shortcut files on infected USB drives.
- Chinese hackers hijacked authentication flows to spy on an isolated network for nearly a decade before detection.
The Attack Surface Keeps Growing
The common thread across June’s incidents is supply chain vulnerability. Nintendo was breached through a third-party recruitment platform. Novo Nordisk was compromised through a single developer credential. REDCap servers were targeted because research institutions run outdated software. The FortiBleed campaign exploited unpatched firewalls, which are supposed to be the last line of defense.
Frequently Asked Questions
What happened in the Novo Nordisk cyberattack?
Hackers group Hunters International stole approximately 1.3TB of data from Novo Nordisk, including clinical trial patient information, source code, drug research, and internal AI models. The breach occurred through an exposed developer credential, and the attackers demanded $25 million.
How many credentials were exposed in June 2026?
Researchers at CyberNews found approximately 24 billion login credentials exposed online on June 17, 2026. The credentials were compiled from numerous sources and represent one of the largest credential leaks ever documented.
Was Nintendo directly hacked?
No. Nintendo confirmed that applicant data was stolen through a WebMD subsidiary’s recruitment platform. The breach affected job applicants who had shared personal information with Nintendo during the hiring process, not Nintendo’s gaming infrastructure or customer accounts.
What is the FortiBleed campaign?
FortiBleed is a cyber attack campaign that deployed a custom sniffer on vulnerable FortiGate firewall devices to steal user credentials and authentication data. Organizations running unpatched FortiGate appliances were the primary targets.
How can I protect myself after these breaches?
Change passwords on any account where you may have reused credentials. Enable two-factor authentication everywhere possible. Monitor financial accounts for unauthorized activity. Use a password manager to generate unique passwords for each service.
