Week 22 | One Criminal Gang Is Eating the Internet
May 22–28, 2026 · 4 stories
Week 22 | One Criminal Gang Is Eating the Internet
May 22–28, 2026 · 4 stories

This Week in 30 Seconds
📌 A single hacking group, ShinyHunters, hit 7-Eleven, education platforms, and video services in the same campaign — proving that if your vendor uses Salesforce, you may already be exposed.
📌 New York’s largest public hospital system lost fingerprints, medical records, and Social Security numbers for 1.8 million patients after hackers lived inside their network for three months undetected.
📌 The FBI issued an emergency warning about a $250/month phishing subscription service that defeats multi-factor authentication on Microsoft 365.
News #1: NYC’s Biggest Public Hospital Lost Fingerprints of 1.8 Million Patients
What happened?
NYC Health + Hospitals (America’s largest public healthcare system) disclosed a months-long breach via a third-party vendor that exposed highly sensitive patient and employee data for at least 1.8 million people, including medical records, government IDs, geolocation data, and fingerprint and palm-print biometrics. Attackers had access from roughly late November 2025 through February 2026, during which they copied files containing personal, medical, financial, and biometric information.
Who’s affected?
Patients and staff of NYC’s public hospitals — a safety-net health system serving over one million residents, most of whom are on Medicaid or state benefits. Any organisation using third-party health tech vendors should take notice. Australian health providers regulated under the My Health Records Act face similar vendor-chain risks.
Business impact?
As one CISO noted: “If a password is stolen, you can change it. If a fingerprint is stolen, that identifier is tied to a person permanently.” Lawsuits are already being filed. Victims are being offered 24 months of credit monitoring retroactively applied to anyone who interacted with NYC Health since 2020. That alone costs millions — before litigation.
Takeaway for you
Ask your IT team this week: which third-party vendors have access to our network, and when was their security last audited?
Source: TechCrunch
News #2: ShinyHunters Hit 7-Eleven, Then Published Everything When They Didn’t Pay
What happened?
Convenience store giant 7-Eleven confirmed that its systems were breached by the ShinyHunters extortion group. Attackers gained access to systems storing franchisee documents in early April, and the gang claimed to have stolen over 600,000 Salesforce records containing corporate data and personally identifiable information. After 7-Eleven refused to pay ransom, ShinyHunters leaked a 9.4GB archive on the dark web.
Who’s affected?
About 185,000 people had data exposed, primarily franchise applicants. But this is part of a much bigger pattern: by March 2026, ShinyHunters told reporters they had breached between 300 and 400 organisations in this campaign alone. Retail, education, and any business using Salesforce Experience Cloud is in the crosshairs.
Business impact?
Legal fees from class-action lawsuits, regulatory fines, and identity protection costs will likely impact operational profitability. The intrusion was tied to “phishing, misconfigurations, or third-party integrations” — not vulnerabilities in Salesforce’s own code. The weakest link lies in how organisations implement their SaaS environments.
Takeaway for you
If your company uses Salesforce, audit your guest-user permissions and OAuth integrations this week. ShinyHunters is exploiting misconfigurations, not bugs.
Source: BleepingComputer
News #3: The FBI Says a $250/Month Subscription Can Bypass Your Company’s MFA
What happened?
The FBI published a dedicated public service announcement warning about “Kali365”, a phishing-as-a-service platform that helps even low-skilled attackers hijack Microsoft 365 accounts by stealing access tokens instead of passwords. It works by tricking users into entering a code on a real Microsoft login page, so victims never see a fake page, and their multi-factor authentication (MFA — that extra code your phone generates) is completely bypassed.
Who’s affected?
The FBI warned that attackers are targeting organisations across education, healthcare, finance, and government. A separate campaign targeted Microsoft 365 identities across more than 340 organisations in the U.S., Canada, Australia, New Zealand and Germany.
Business impact?
A compromised account can be used to read sensitive communications, launch business email compromise schemes, impersonate executives, or move laterally through an organisation. Microsoft confirmed “hundreds of compromises occurring daily across affected environments.”
Takeaway for you
Ask your IT team to block device-code authentication flow in Microsoft Entra ID this week. Most organisations don’t use it — but criminals do.
Source: Cybersecurity Dive
News #4: 700+ Trusted Websites — Including Harvard and Oxford — Were Quietly Turned Into Malware Traps
What happened?
Threat actors exploited a critical security flaw in Ghost CMS (a popular blogging and publishing platform) to inject malicious code into websites. The vulnerability was an SQL injection flaw, and the fix had been available since February 2026 — but hundreds of site owners never applied it. Researchers confirmed impact on more than 700 domains, including university portals, AI/SaaS companies, and media outlets. Attackers planted malicious code on the websites of Harvard University, Oxford University, and DuckDuckGo.
Who’s affected?
Any person visiting those websites. Visitors were served a fake Cloudflare verification prompt and instructed to paste a command on their Windows command prompt, which dropped malware onto their systems. Businesses running Ghost CMS for blogs or newsletters are directly at risk.
Business impact?
Reputational damage is instant. If your company blog infects a customer’s laptop, trust evaporates. Ghost is actively used by over 100,000 websites, many of them small businesses and independent publishers.
Takeaway for you
If your marketing team runs a blog or newsletter platform, verify this week whether it’s been updated. The patch has existed for three months — delay is the vulnerability now.
Source: The Hacker News
🌐 Weekly Trend Observation
This week, one name kept appearing across my screen: ShinyHunters. They hit 7-Eleven. They hit Canvas. They’ve been linked to breaches at Vimeo, Zara, Medtronic, the European Commission, and reportedly 300–400 organisations since September. What strikes me is that they’re not deploying traditional ransomware that locks your files. They’re stealing your data quietly, then threatening to publish it. As Kaspersky’s researchers noted, this reflects a growing shift toward “encryptionless extortion” — by avoiding encryption, attackers reduce detection risk, shorten attack timelines, and eliminate dependencies on stable encryption routines. Your systems keep running. You don’t even know you’ve been hit.
The businesses most exposed right now are those with sprawling SaaS ecosystems — especially Salesforce, Microsoft 365, and third-party vendor integrations. The Kali365 phishing kit shows that MFA alone is no longer a finish line. Supply chains are now attack surfaces.
My prediction for the next 60–90 days
We’ll see regulators — especially in the US, EU, and Australia — start demanding mandatory vendor security attestation as a condition of doing business. The NYC Health breach, and the Canvas breach all share one root cause: a trusted third party was the way in. Boards that aren’t asking “who are our vendors, and who audits them?” will be the ones reading about themselves in columns like this.
Cybersecurity, TRANSLATED. Written weekly for business leaders who want to understand cyber risk without needing a technical degree. If this was useful, follow for next week’s edition.
메타데이터
- post_id
- 3cb39c1f76d0
- slug
- week-22-one-criminal-gang-is-eating-the-internet-3cb39c1f76d0
- url
- https://medium.com/cybersecurity-translated/week-22-one-criminal-gang-is-eating-the-internet-3cb39c1f76d0
- canonical_url
- https://medium.com/cybersecurity-translated/week-22-one-criminal-gang-is-eating-the-internet-3cb39c1f76d0
- author_url
- https://medium.com/@arianchen0827
- status
- ok
- fetched_at
- 2026-06-15 20:49:13