S6 Ransomware Signal, June 9 to 15, 2026
TLP:CLEAR. Approved for Public Distribution

S6 RANSOMWARE SIGNAL

Week of June 9 to 15, 2026 | Published by S6 Tech


⚡ 60-SECOND VERSION

Biggest threat: ShinyHunters compromised 137,000 school staff accounts by attacking the Salesforce backend connected to Infinite Campus, the student records platform. The same group also claimed a Council of Europe breach over the weekend.

Why it matters: Your business has connected apps you probably forgot you authorized. Every one of them is a door, and the doors you forgot you opened are the ones that get walked through.

Do this now: Audit and remove unrecognized third-party app permissions in your Microsoft 365 or Google Workspace admin console. Microsoft guide. 15 minutes, free.

📋 EXECUTIVE SUMMARY

1. ShinyHunters has expanded from smash-and-grab to SaaS supply chain. The 137,000 Infinite Campus accounts came through Salesforce. The Council of Europe investigation, the Kodak claim, and the Sysco extortion all carry the same actor handle this week. The connector permissions sitting inside your Microsoft 365 or Google Workspace tenant now deserve the same audit you would give a new vendor contract.

2. The Gentlemen now has a name. Krebs on Security identified the administrator as Alexander Andreevich Yapaev, 36, of Izhevsk, with Check Point and PRODAFT corroborating at high confidence. PRODAFT also confirmed the operator uses AI to maintain ransomware tooling. The deanonymization closes a reporting arc we have run every week since mid-May. The defensive priorities do not change. See the Trendline callout below.

3. A previously low-profile actor known as deadlock posted 77 victims to its leak site inside a 24-hour window on June 15, roughly 72 percent of all disclosed activity this week. Posting bursts that large usually represent backlog releases, so the underlying breach dates span weeks rather than a single day. Either way, the victim list reads SMB: accounting firms in Spain, manufacturing in Italy and Poland, construction firms across central Europe.


📊 METRICS & INTELLIGENCE

Metric This Week What It Means
Total Disclosed Victims 107 Ninth straight week between 97 and 107. The tempo is structural, not cyclical.
Active Threat Actors 12 Sharp drop from recent fragmentation. One actor's posting surge dominates the count this week.
deadlock's Share 77 (72%) Highest single-actor concentration we have recorded. Posting backlog likely; underlying breach dates span weeks.
US-Based Victims 9 (8.4%) Lowest US share of 2026. Activity concentrated in central and southern Europe.
Professional Services Hits 12 This week's surge sector. Spain alone took 6 of the 12.
FBI Phishing-Service Takedown 1M+ URLs Outsider Enterprise infrastructure seized. Expect a short dip before replacements stand up.

Spain (14), Poland (9), USA (9), Italy (8), and Germany (5) led the geography. Central and Eastern Europe absorbed 22 victims across Poland, the Czech Republic, Hungary, Croatia, and Romania.

THREAT ACTOR MARKET SHARE, THIS WEEK

deadlock
77 (72%)
ShinyHunters
4 (3.7%)
All others (10)
26 (24.3%)

Highest single-actor concentration recorded in 2026. The 24-hour posting surge on June 15 usually represents a backlog release, not 77 same-day attacks.


🚨 ACTIVE CAMPAIGNS

ShinyHunters Expands Through SaaS Connectors 🏢🏪

137,000 school staff accounts compromised through the Salesforce link to Infinite Campus. Council of Europe breach claim under investigation. Kodak and Sysco both named on the leak site this week.

What happened: ShinyHunters did not breach Infinite Campus, the student records platform used by thousands of US school districts. They breached the Salesforce data backend that Infinite Campus connects to. Personal information for 137,000 staff accounts walked out through that integration point. The Council of Europe announced over the weekend that it is investigating a separate ShinyHunters claim. The group also posted Kodak (attackers claim 2.2 million records, the company has not confirmed), Sysco (attackers claim 61 million Salesforce records, no independent verification), and the Houston Community College System (student PII and immigration documents).

Why it matters: Our April coverage flagged ShinyHunters running phone-based attacks against ADT and Udemy. Three months later, the same group is pulling 137,000 accounts in a single move through a SaaS connector that the victim organizations forgot they had authorized. The connector permissions your business granted last year to a productivity plugin, a shipping integration, or a marketing tool sit at the same risk level. Auditing them takes ten minutes per platform. The "Just Do This" section below walks you through it.

Source: BleepingComputer (Infinite Campus), BleepingComputer (Council of Europe)

AI-Brand Phishing Campaigns 🏢🏪

Microsoft documented multiple campaigns impersonating ChatGPT, Claude, and DeepSeek to deliver credential theft and infostealer payloads.

What it does: One campaign sends what looks like a billing notice from ChatGPT and routes the recipient through legitimate services (Bitrix24, Amazon tracking links, Rebrandly) before landing on a credit card capture page. A second uses a PDF claiming a Claude account "policy violation," then feeds the target through a CAPTCHA into an AiTM phishing kit. AiTM (adversary-in-the-middle) is the technique where attackers sit between the user and the real Microsoft login to capture the password and the active session token in real time, which bypasses standard MFA. Microsoft also observed Storm-3075 pushing malvertising on movie streaming sites that drops fake "AI plugin" downloads carrying the Vidar infostealer. South African enterprises received over 4,500 of the ChatGPT lures. The Claude campaign reached more than 2,000 organizations across the US, UK, and India.

Why it matters: This is the sixth consecutive issue covering identity-bypass attacks against SaaS platforms. Tycoon2FA, Kali365, Carnival, Silent Ransom, Oxford via Group GTI, and now AiTM kits behind AI-brand impersonation. The vector changes weekly. The model does not. No employee should expect a "policy violation" email from an AI service to be real. Train them, and turn on Safe Links or its equivalent so the redirect chains get inspected at click time.

Source: Microsoft Security Blog


✅ JUST DO THIS

Audit Third-Party App Permissions in Your Microsoft 365 or Google Workspace Tenant

⏱️ 10 to 15 minutes per platform | 💰 Free

Why now: ShinyHunters did not need to breach Infinite Campus. They reached the data through a Salesforce integration the platform's customers had quietly authorized. Your tenant has the same shape. A marketing tool from two years ago. A shipping plugin a former employee installed. An AI trial from last quarter. Each one has scopes that may read mail, read OneDrive or Drive, or act on behalf of users. The doors you forgot you opened are the ones that get walked through.

Platform Steps
Microsoft 365 Admin Center, then Settings, then Integrated apps. Review the list and remove anything you do not recognize. Then open Entra ID, Enterprise applications, and audit OAuth-granted permissions there separately. Microsoft guide.
Google Workspace Admin Console, then Security, then API Controls, then App Access Control. Open Third-party apps and revoke anything unfamiliar. Google guide.
Other Search "[your platform] connected apps admin," or ask your IT provider in one sentence: "Can you show me the list of third-party apps connected to our tenant and remove anything unused?"

Verify it worked: After removal, the remaining list should contain only apps your team uses this month. If unfamiliar vendor names remain, treat them as compromise candidates and rotate any credentials those apps may have accessed.


🎯 THREAT ACTOR SPOTLIGHT

deadlock 🏪🏢

77 victims posted in a 24-hour window, 72 percent of the week's disclosed activity. New entry on our coverage. Heavy SMB concentration in European professional services.

This is the first time deadlock has led our coverage. The 77-victim posting on June 15 is the largest single-actor concentration we have recorded in 2026. Ransomware.live captured the posts inside a 24-hour window. Surges that large usually represent backlog releases rather than 77 same-day attacks, so the underlying breach dates probably span four to six weeks. The victim list is what matters either way.

Target profile: Small and mid-sized professional services firms, light manufacturing, and logistics providers. Twelve accounting, legal, and tax advisory practices appeared in one 24-hour window: Summa4 (Spain), Nobani & Co (Jordan), Consulting Valladolid (Spain), Schlenker & Cantwell P.A. (USA), EFCA (France), and Linnecken & Partner (Germany). Manufacturing victims included Zhangjiagang Fortune Chemical (Singapore), Starconn (Taiwan), Cole Manufacturing (USA), and Bridgeport S.p.A. (Italy). Construction firms across Hungary, the Czech Republic, Poland, and Germany made up another eleven. Most of the named businesses run on staffs of ten to a hundred.

Known TTPs (plain English):

  • Internet-facing service exploitation: The opportunistic victim profile suggests scanning of public-facing applications. No specific CVE has been publicly attributed.
  • Heavy exfiltration: Leak posts cite data volumes from 50GB up to 650GB. That range indicates full network compromise, not a quick file-share grab.
  • Double extortion: Files encrypted, with separate threats of public release. Leak countdowns observed on multiple posts.

Defensive Priorities:

# Action Plain English
1 Audit internet-facing services List every service in your network reachable from the public internet. Patch what you can, retire what you cannot, document what is left.
2 Network segmentation Limit how far an attacker can move after one foothold. Workstations should not be able to reach every server on the network.
3 Offline backup verification Confirm your backups exist and confirm they restore without network access. A backup that lives on the same network the attacker just compromised is not a backup.

📈 TRENDLINE: The Gentlemen, Week 5 of Continuous Coverage

The Gentlemen has appeared in every issue since mid-May (SystemBC botnet on April 27, Huntress defense-evasion writeup on May 25, the Microsoft worm-propagation analysis on June 1, and the leak-site lead on June 8). This week, Krebs on Security named the administrator as Alexander Andreevich Yapaev, 36, of Izhevsk, Russia. Check Point and PRODAFT corroborated at high confidence, and PRODAFT confirmed the operator uses AI to assist with ransomware tooling and post-exploitation. The story arc is complete. The defensive priorities from the prior four issues still apply.


🏭 SECTOR TARGETING

Manufacturing, 19 victims 🏭

Threat actors: deadlock (most), The Gentlemen. Notable incidents: Zhangjiagang Fortune Chemical (Singapore), Starconn / Chief Land Electronic (Taiwan), Cole Manufacturing (USA), Bridgeport S.p.A. (Italy), Seçil Kauçuk (Turkey). Volume leader by sector this week. Mid-market firms with international supply chains took most of the attention.

Professional Services, 12 victims 🏪🏢

Threat actors: deadlock (almost all), The Gentlemen. Notable incidents: Summa4 (Spain), Nobani & Co (Jordan), Consulting Valladolid (Spain), Schlenker & Cantwell P.A. (USA), EFCA (France), Linnecken & Partner (Germany). Data exposed per leak posts: Client financial records, tax filings, legal correspondence. Spain alone took six of the twelve. Firm sizes range from solo practitioners up to regional outfits.

Construction and Engineering, 11 victims 🏢

Threat actors: deadlock, The Gentlemen. Notable incidents: Weinberg '93 Építő Kft. (Hungary, attackers claim 650GB stolen, figure not independently verified), FIRESTA (Czech Republic), Geopartner (Poland), 8.2 Group (Germany, renewable-energy specialist). Central European construction firms took an outsized share, consistent with deadlock's geographic concentration this week.

Government and Municipal, 4 victims 🏢

Threat actors: deadlock, Nova. Notable incidents: Židlochovice City (Czech Republic, attackers claim 150GB; the mayor has publicly disputed the breach), Picassent City Council (Spain), NSW Government (Australia), Morton Grove Park District (USA).

⚠️ SMB Sector Alert: European Professional Services

Twelve accounting, legal, and tax advisory firms posted in a single 24-hour window is not a coincidence. The deadlock surge concentrated on small practices in Spain, France, Germany, and Jordan, with firm sizes from solo practitioners up to regional offices with forty-plus years of operation. If your firm handles client financial data or tax filings and runs on under fifty staff, you fit the current target profile. The internet-facing audit, the segmentation work, and the third-party app review in this issue are the cheap moves that change the math.


🏪 SMB REALITY CHECK

If you are under 50 employees with no dedicated security staff, here is what actually matters this week:

The third-party app audit is the action. The ShinyHunters story is not really about Infinite Campus or K-12 districts. It is about every business that has ever authorized a SaaS connector and then forgotten. Ten minutes inside your Microsoft 365 or Google Workspace admin console will surface the unfamiliar names. Anything you cannot identify gets removed. That alone closes the most common modern attack chain.

The AI-themed phishing is the conversation. Tell your team once, in writing: no AI service sends urgent payment emails, and no AI service sends policy violation notices that demand you log in within twenty-four hours. Anything that wants you to act right now is the wrong thing to act on.

💡 The control that works is the audit you would rather skip

There is a pattern across the last six weeks of this newsletter. The attacks land because nobody is watching the connector list, the VPN firmware, the inbox forwarding rule, or the OAuth token. The fixes never make a vendor pitch deck. They keep working anyway.

Your Stack, Your Actions:

If You Use... Do This Time
Microsoft 365 Admin Center, then Settings, then Integrated apps. Review and remove anything unfamiliar. Then audit Entra ID Enterprise applications separately. 15 min
Google Workspace Admin Console, then Security, then API Controls, then App Access Control. Revoke any third-party app you do not recognize. 10 min
QuickBooks Online Verify MFA is on for every user. Confirm no unfamiliar accountants hold admin permission. Remove anyone who should not be there. 10 min
Any AI tool (paid or free) Tell staff once, in writing: no AI service sends urgent payment or policy violation emails. The whole class of those messages is fraud. 5 min

📞 When to Call for Help

If your Microsoft 365 or Google Workspace shows a connected third-party app you have never heard of with read access to mail or files, treat it as a possible compromise. Have your IT provider check sign-in logs and inbox forwarding rules for any account that app could have touched, the same day, not the next morning.

Safe to ignore this week: The Council of Europe breach claim (intergovernmental target only), the 23andMe bankruptcy settlement (consumer issue, not a business action), and the cyberattack on Russian tech firm Astral. None of these change anything on your defensive list.


🔮 LOOKING AHEAD

Identity Is the Perimeter, and Identity Has Connectors

The security press has said "identity is the new perimeter" for five years. This week makes the next move visible. Identity now includes every SaaS app, plugin, and connector your tenant has authorized. The ShinyHunters Salesforce chain was an identity-perimeter compromise, even though no employee password was phished. The OAuth scopes did the work a stolen password used to do.

What to watch: Expect more breach disclosures over the next sixty days that name a third-party integration rather than the underlying platform. Salesforce, HubSpot, Slack, ServiceNow, and the long tail of niche SaaS connectors all sit on the same risk surface. Expect regulators to start asking about connector inventories during breach investigations, the way they currently ask about backup posture and MFA coverage.

📅 Next Month's Priority

Build a single-page inventory of every third-party app authorized inside your Microsoft 365 or Google Workspace tenant. List the app, its data scopes, the business owner, the date authorized, and the next review date. Cost: zero, just spreadsheet time. Roughly two hours of work that prevents a Salesforce-style chain reaching your data.


CLASSIFICATION: TLP:CLEAR

Sources: BleepingComputer (June 14-15, 2026), Krebs on Security (June 10, 2026), Microsoft Security Blog (June 8, 2026), Huntress (May 21, 2026), Check Point research, PRODAFT research, Ransomware.live API, RansomLook.io API. Intelligence aggregation by S6 Tech.

S6 RANSOMWARE SIGNAL

Your data is an asset. We guard it like one.

Intelligence cutoff: June 15, 2026, 14:00 ET | Next edition: June 22, 2026