Skip to content
All resources
Cybersecurity Intel · № 11 · 25 May – 7 June 2026

The fortnight belonged to the telephone: vishing, fake IT support and backups burned behind them

Nearly 6 million cruise-line customers and 4.9 million telecoms accounts exposed, both starting with a phone call. The FBI warns law firms about fake IT-support calls. Iran-linked operators wipe recovery layers, not just production. Your helpdesk, your SaaS and your backups are now primary attack surface.

Published 8 June 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
6M
People notified in a cruise-line breach that began with a socially engineered account
4.9M
Telecoms accounts leaked after a refused pay-or-leak demand (Have I Been Pwned)
600k
Gaza households exposed in likely the largest humanitarian-data breach on record
749
Ransomware incidents recorded globally in May 2026 (NCC Group)

Executive summary

  • Every marquee incident traced back to identity-layer social engineering. An employee vished for Entra credentials led to 4.9 million leaked telecoms accounts; a socially engineered account exposed nearly 6 million cruise-line customers.
  • The FBI formally warned that fake IT support is an industry. Silent Ransom Group is talking its way into law firms via callback phishing and vishing, then using legitimate remote-access tools to steal and extort, no encryption involved.
  • Destructive actors are going for the recovery layer. An Iran-linked campaign deliberately destroyed VMs, databases, storage and backup platforms, the counterpart to extortion: remove the victim's ability to say no.

Key findings

29 May 2026 ATT&CK T1566.004

Telecoms giant's data leaked after refusing extortion; entry was a vished employee

A major US telecoms and cable provider confirmed a breach after being named in a pay-or-leak campaign; when it refused to pay, data covering roughly 4.9 million unique accounts was published. Initial access came via voice-phishing an employee for Microsoft Entra credentials, then pivoting into the Salesforce CRM. Around 85,000 internal directory records were also exposed.

27 May 2026 ATT&CK T1656

Cruise line notifies ~6 million people after an employee account is socially engineered

A global cruise operator began notifying 5,995,277 individuals that names, dates of birth, contact details and government-ID numbers were stolen after attackers socially engineered an employee account. The intrusion ran undetected for weeks before identification.

26 May 2026 FBI advisory

FBI: Silent Ransom Group raids law firms via fake IT-support calls

An FBI advisory warned that the group (aka Luna Moth) impersonates IT helpdesks by phone, directs staff into remote sessions, installs legitimate remote-management tools and exfiltrates for extortion without any encryption. Dozens of legal, financial and professional-services firms were hit between January and May, with cases escalating to in-person impersonation.

31 May – 2 June 2026 Humanitarian

World Food Programme breach exposes 600,000 Gaza households

Unauthorised access to a self-registration application exposed names, ID and mobile numbers and location data for roughly 600,000 households, described as possibly the largest breach of humanitarian beneficiary data on record, with an acutely vulnerable exposed population.

26 May – 2 June 2026 ATT&CK T1485 / T1490

Iran-linked operators destroy recovery layers; US sanctions the crypto rails

Researchers attributed a destruction-and-exfiltration campaign to an Iran-linked group that deliberately wiped VMs, databases, storage and backup platforms across US, Israeli, Saudi and Turkish targets, including transit agencies. Days later, the US Treasury sanctioned four Iranian crypto exchanges tied to ransomware monetisation, including one processing over half of Iran's digital-asset inflows.

The broader pattern

  • The helpdesk is the breach point. Vishing and callback phishing carried the fortnight; credential prompts and remote-support flows need the same monitoring as your perimeter.
  • Legitimate tools doing illegitimate things is the detection problem. RMM software, valid cloud sessions and bulk CRM exports look normal in isolation; only behavioural context flags them.
  • Recovery infrastructure is a target, not a safety net. If backups share credentials, network and monitoring with production, a destructive actor takes both.

Sector lens

Telecoms & media
Subscriber datasets are prime pay-or-leak inventory. Watch Entra and Okta sign-ins paired with anomalous CRM export volume; that pairing was this fortnight's kill chain.
Travel & hospitality
Guest-identity data (passports, government IDs) drives regulatory exposure across every jurisdiction you sail or fly through. Socially engineered accounts, not malware, opened the door.
Legal & professional services
The FBI advisory is your board briefing: fake IT-support calls, real remote-access tools, no encryption. Pre-agree a verification protocol between staff and the actual helpdesk.
Public sector & humanitarian
Beneficiary data is life-safety data. Registration platforms need the same hardening as payment systems.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

Put a verification protocol between employees and 'IT support' calls. A callback number and a shared verification step defeat most vishing scripts.

02

Alert on new remote-management tools appearing on endpoints. AnyDesk or Zoho Assist appearing outside the approved stack is a top-tier signal, even though the binaries are legitimate.

03

Pair identity telemetry with SaaS export volume in your detection content. A fresh Entra session plus a bulk CRM export is the pattern behind the fortnight's biggest leaks.

04

Isolate and separately credential your backup and recovery infrastructure. Destructive actors now hunt recovery layers first; immutable or offline copies decide the outcome.

05

Screen ransom-payment exposure against the new sanctions designations. Paying through sanctioned rails is now its own legal incident.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

Blacklight's UEBA baselines every identity, so a vished credential behaves wrongly the moment it is used: new session geometry, first-time SaaS scopes, export volumes no legitimate user produces. Remote-access tools appearing outside your approved stack and anomalous activity against backup infrastructure are investigated autonomously, with the evidence trail ready before your analyst picks it up.

Book a Demo

Sources & methodology

Primary public sources this issue: Public disclosures and state AG filings (Carnival Corporation, Charter Communications) · Have I Been Pwned dataset listings · FBI IC3 advisory on Silent Ransom Group (26 May 2026) · World Food Programme statements with The New Humanitarian and The Record reporting · Gambit Security research on the Iran-linked destructive campaign · US Treasury OFAC designations (2 June 2026) · CISA KEV alert (26 May 2026) · NCC Group Monthly Threat Pulse (May 2026 data) · MITRE ATT&CK v15 for technique mapping.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 11 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.