The fortnight belonged to the telephone: vishing, fake IT support and backups burned behind them
Nearly 6 million cruise-line customers and 4.9 million telecoms accounts exposed, both starting with a phone call. The FBI warns law firms about fake IT-support calls. Iran-linked operators wipe recovery layers, not just production. Your helpdesk, your SaaS and your backups are now primary attack surface.
Executive summary
- Every marquee incident traced back to identity-layer social engineering. An employee vished for Entra credentials led to 4.9 million leaked telecoms accounts; a socially engineered account exposed nearly 6 million cruise-line customers.
- The FBI formally warned that fake IT support is an industry. Silent Ransom Group is talking its way into law firms via callback phishing and vishing, then using legitimate remote-access tools to steal and extort, no encryption involved.
- Destructive actors are going for the recovery layer. An Iran-linked campaign deliberately destroyed VMs, databases, storage and backup platforms, the counterpart to extortion: remove the victim's ability to say no.
Key findings
Telecoms giant's data leaked after refusing extortion; entry was a vished employee
A major US telecoms and cable provider confirmed a breach after being named in a pay-or-leak campaign; when it refused to pay, data covering roughly 4.9 million unique accounts was published. Initial access came via voice-phishing an employee for Microsoft Entra credentials, then pivoting into the Salesforce CRM. Around 85,000 internal directory records were also exposed.
Cruise line notifies ~6 million people after an employee account is socially engineered
A global cruise operator began notifying 5,995,277 individuals that names, dates of birth, contact details and government-ID numbers were stolen after attackers socially engineered an employee account. The intrusion ran undetected for weeks before identification.
FBI: Silent Ransom Group raids law firms via fake IT-support calls
An FBI advisory warned that the group (aka Luna Moth) impersonates IT helpdesks by phone, directs staff into remote sessions, installs legitimate remote-management tools and exfiltrates for extortion without any encryption. Dozens of legal, financial and professional-services firms were hit between January and May, with cases escalating to in-person impersonation.
World Food Programme breach exposes 600,000 Gaza households
Unauthorised access to a self-registration application exposed names, ID and mobile numbers and location data for roughly 600,000 households, described as possibly the largest breach of humanitarian beneficiary data on record, with an acutely vulnerable exposed population.
Iran-linked operators destroy recovery layers; US sanctions the crypto rails
Researchers attributed a destruction-and-exfiltration campaign to an Iran-linked group that deliberately wiped VMs, databases, storage and backup platforms across US, Israeli, Saudi and Turkish targets, including transit agencies. Days later, the US Treasury sanctioned four Iranian crypto exchanges tied to ransomware monetisation, including one processing over half of Iran's digital-asset inflows.
The broader pattern
- The helpdesk is the breach point. Vishing and callback phishing carried the fortnight; credential prompts and remote-support flows need the same monitoring as your perimeter.
- Legitimate tools doing illegitimate things is the detection problem. RMM software, valid cloud sessions and bulk CRM exports look normal in isolation; only behavioural context flags them.
- Recovery infrastructure is a target, not a safety net. If backups share credentials, network and monitoring with production, a destructive actor takes both.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Put a verification protocol between employees and 'IT support' calls. A callback number and a shared verification step defeat most vishing scripts.
Alert on new remote-management tools appearing on endpoints. AnyDesk or Zoho Assist appearing outside the approved stack is a top-tier signal, even though the binaries are legitimate.
Pair identity telemetry with SaaS export volume in your detection content. A fresh Entra session plus a bulk CRM export is the pattern behind the fortnight's biggest leaks.
Isolate and separately credential your backup and recovery infrastructure. Destructive actors now hunt recovery layers first; immutable or offline copies decide the outcome.
Screen ransom-payment exposure against the new sanctions designations. Paying through sanctioned rails is now its own legal incident.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
Blacklight's UEBA baselines every identity, so a vished credential behaves wrongly the moment it is used: new session geometry, first-time SaaS scopes, export volumes no legitimate user produces. Remote-access tools appearing outside your approved stack and anomalous activity against backup infrastructure are investigated autonomously, with the evidence trail ready before your analyst picks it up.
Sources & methodology
Primary public sources this issue: Public disclosures and state AG filings (Carnival Corporation, Charter Communications) · Have I Been Pwned dataset listings · FBI IC3 advisory on Silent Ransom Group (26 May 2026) · World Food Programme statements with The New Humanitarian and The Record reporting · Gambit Security research on the Iran-linked destructive campaign · US Treasury OFAC designations (2 June 2026) · CISA KEV alert (26 May 2026) · NCC Group Monthly Threat Pulse (May 2026 data) · MITRE ATT&CK v15 for technique mapping.