What Are the Biggest Cyber Attacks, Ransomware Incidents, and Data Breaches That Happened in June 2025?
In June 2026, several major cyber attacks, ransomware incidents, and data breaches impacted global organizations across sectors. Victims included United Natural Foods, The North Face, ZoomCar, McLaren Health, and more. These events highlight the critical need for businesses to adopt a proactive cybersecurity strategy, including updating software, running tabletop exercises, and strengthening incident response plans. From ransomware groups like INC Ransom and Scattered Spider to nation-state actors like Predatory Sparrow, June 2025 saw a diverse range of cyber threats unfold globally.
Quick answer: June 2025 saw ransomware hit government services and hospitals, with attacks on Lee Enterprises, Kettering Health and Optima Tax Relief, plus breaches at The North Face and Cartier linked to Scattered Spider. The common causes were misconfigurations, unpatched systems and human error, so an incident response plan is essential.
Key takeaways
- Scattered Spider was linked to breaches at The North Face and Cartier, which shows help desk social engineering is still working.
- Most June incidents came from misconfigurations, unpatched systems and human error, not from clever new exploits.
- Use a monthly roundup like this to check your own patching and backup routines.
Table of Contents
- Why June 2025 Became a Tipping Point in Cybersecurity
- Top Ransomware Attacks in June 2025
- Major Data Breaches That Shook June
- Notable Cyber Attacks
- New Ransomware and Malware Families
- Zero-Days and Security Patches Released
- Lessons from June: Why Every Business Needs a Cyber Resilience Strategy
- Actionable Steps Moving Forward
- Conclusion

United Natural Foods. The North Face. Cartier. ZoomCar. The Washington Post. What do these companies have in common? Very little, until June 2025, when each became the latest victim of cybercrime’s ruthless evolution.
June wasn’t just another month. It was a warning shot.
Why June 2025 Became a Tipping Point in Cybersecurity
As summer rolled in, a cyberstorm hit industries from healthcare to luxury retail, and from public administration to airline carriers. This wasn't about just data anymore, it was about disruption, extortion, and widespread digital chaos. Ransomware gangs, hacktivist collectives, and nation-state actors exploited misconfigurations, unpatched systems, and human error.
“A Cyber Incident Response Plan is no longer a ‘nice-to-have’, it’s a lifeline.”
, Cyber Resilience Analyst, RedTeam Global
Top Ransomware Attacks in June 2025
| Date | Victim | Attack Summary | Threat Actor | Impact |
|---|---|---|---|---|
| June 01 | Durant (OK), Lorain County (OH), Puerto Rico Justice Dept | Courts and services disrupted across multiple states | RansomHub | Government paralysis |
| June 04 | Lee Enterprises | 40,000 SSNs leaked; $2M recovery cost | Qilin Ransomware | Publishing operations affected |
| June 05 | Kettering Health | Hospitals diverted, health records breached | Interlock | 14 hospitals affected |
| June 06 | Optima Tax Relief | 69 GB data leaked (double extortion) | Chaos Ransomware | Financial and client data loss |
| June 09 | Sensata Technologies | Employee personal data exposed | Unknown | 15,000+ affected |
| June 10 | Yes24 (South Korea) | Concerts cancelled; platform offline | Unknown | Entertainment industry hit hard |
Major Data Breaches That Shook June
| Date | Organization | Breach Summary | Likely Actor | Data Exposed |
|---|---|---|---|---|
| June 02 | The North Face | 3,000 customer accounts breached | Scattered Spider | Personal purchase data |
| June 02 | Cartier | Targeted customer data stolen | Scattered Spider | Customer info |
| June 09 | TxDOT (Texas) | 300,000 crash reports leaked | Unknown | SSNs, license data |
| June 12 | Aflac | Claims and SSNs accessed | Scattered Spider | Health & PII |
| June 16 | ZoomCar (India) | 8.4 million records stolen | Unknown | Names, emails, vehicle data |
| June 17 | Episource | 5.4M patient records compromised | Unknown | Medical, insurance data |
| June 22 | McLaren Health | 740,000+ records leaked | INC Ransom | Health, ID, insurance info |
Notable Cyber Attacks
-
United Natural Foods: Distribution halted, orders delayed.
-
The Washington Post: Journalists' emails accessed.
-
WestJet Airlines: Internal systems hit; app and site went down.
-
Bank Sepah & Nobitex (Iran): Politically motivated attacks by Predatory Sparrow.
New Ransomware and Malware Families
-
Acreed Malware: Replacing Lumma as top infostealer in Russian underground.
-
DarkGaboon: Leaking LockBit 3.0 to attack domestic Russian targets.
-
SuperCard: NFC-based malware stealing financial data via Android.
Zero-Days and Security Patches Released
| Date | CVE(s) | Summary |
|---|---|---|
| June 02 | CVE-2025-21479 to 21480 | Qualcomm GPU zero-days |
| June 03 | CVE-2025-37093 | HPE StoreOnce vulnerability |
| June 10 | CVE-2025-33053 | WebDAV zero-day used in APT attacks |
| June 13 | CVE‑2024‑57727 | RMM software exploited in ransomware |
| June 26 | CVE-2025-20281, 20282 | Critical Cisco ISE RCE flaws |
Lessons from June: Why Every Business Needs a Cyber Resilience Strategy
Many companies targeted in June were not lacking in cybersecurity tools. What they lacked was preparedness:
-
No tabletop simulations of real-world incidents.
-
Outdated or missing incident response plans.
-
Limited cross-department coordination during a breach.
ZoomCar, for example, responded quickly to their breach, but the lack of clarity around data misuse left customers confused and media spinning.
Actionable Steps Moving Forward
-
Perform a Ransomware Risk Assessment
Simulate attacks like those seen in Kettering Health or Optima Tax Relief. -
Update Software and Patch Vulnerabilities
Stay ahead of exploits like the ASUS, Chrome, or WebDAV zero-days. -
Train Your Staff
Human error remains the weakest link. Make awareness training routine. -
Adopt a Zero Trust Architecture
Compartmentalize access, enforce MFA, and monitor everything. -
Run Tabletop Exercises Quarterly
Don't just plan, practice your breach response.
Conclusion
June 2025 will be remembered not just for how much damage cybercriminals caused, but for how prepared (or not) organizations were.
If your company hasn’t re-evaluated its risk posture after these incidents, the question is no longer if you’ll be attacked, but when.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0