Cybersecurity Roundup: Ransomware Surge, Government Breaches, and Supply Chain Attacks Dominate H1 2026
The first half of 2026 has seen a sharp rise in cyber threats, with ransomware groups, government database breaches, and third-party supply chain attacks leading the charge. Attackers are increasingly exploiting trusted systems and external service providers to amplify disruption and data exposure.
Qilin Leads Ransomware Activity in H1 2026
The Qilin ransomware group emerged as the most active threat actor in the first half of the year, leveraging its ransomware-as-a-service (RaaS) model to target organizations globally. Manufacturing, healthcare, construction, and professional services were among the hardest-hit sectors as the group expanded its operations.
Government Registries and Law Enforcement Databases Compromised
A breach of the Register of Beneficial Owners (VwbP) exposed data linked to 31,000 legal entities, prompting authorities to take the registry offline while investigating. Meanwhile, a Police National Legal Database (PNLD) breach leaked names, work emails, and organizational details of police officers, government partners, and criminal justice professionals, with the data later surfacing on the dark web.
Supply Chain Attacks Disrupt Retail and Healthcare Operations
Dutch retailer De Bijenkorf faced delivery delays and data exposure concerns after a cyberattack on a third-party logistics provider. While the retailer’s internal systems remained secure, investigators are assessing whether customer contact and order details were compromised. Similarly, Australian telehealth provider Updoc reported a breach of a third-party platform, exposing customer names, email addresses, and postal addresses though medical records and financial data were unaffected.
Key Trends: Third-Party Risks and Evolving Attack Vectors
This week’s incidents underscore a growing trend: attackers are increasingly targeting third-party platforms, government databases, and RaaS ecosystems to maximize impact. As organizations rely more on interconnected digital ecosystems, the security of partner networks has become as critical as internal defenses. The shift highlights the need for stronger third-party risk management, continuous monitoring, and robust incident response strategies.
Source: https://thecyberexpress.com/tce-weekly-roundup-data-breaches-h1/
Israel Police - Cyber crime unit cybersecurity rating report: https://www.rankiteo.com/company/israel-police---cyber-crime-unit
"id": "ISR1786107645",
"linkid": "israel-police---cyber-crime-unit",
"type": "Breach",
"date": "1/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '31,000 legal entities',
'industry': 'government',
'name': 'Register of Beneficial Owners (VwbP)',
'type': 'government registry'},
{'customers_affected': 'police officers, government '
'partners, criminal justice '
'professionals',
'industry': 'government/law enforcement',
'name': 'Police National Legal Database (PNLD)',
'type': 'law enforcement database'},
{'industry': 'retail',
'location': 'Netherlands',
'name': 'De Bijenkorf',
'type': 'retailer'},
{'customers_affected': 'customers (names, email '
'addresses, postal addresses)',
'industry': 'healthcare',
'location': 'Australia',
'name': 'Updoc',
'type': 'telehealth provider'}],
'attack_vector': ['third-party platforms', 'RaaS (Ransomware-as-a-Service)'],
'data_breach': {'data_exfiltration': True,
'number_of_records_exposed': ['31,000 legal entities',
'police officers, government '
'partners, criminal justice '
'professionals'],
'personally_identifiable_information': True,
'sensitivity_of_data': ['high (government/law enforcement '
'data)',
'moderate (customer contact details)'],
'type_of_data_compromised': ['names',
'work emails',
'organizational details',
'customer contact details',
'order details',
'email addresses',
'postal addresses']},
'date_publicly_disclosed': '2026-06-30',
'description': 'The first half of 2026 has seen a sharp rise in cyber '
'threats, with ransomware groups, government database '
'breaches, and third-party supply chain attacks leading the '
'charge. Attackers are increasingly exploiting trusted systems '
'and external service providers to amplify disruption and data '
'exposure.',
'impact': {'brand_reputation_impact': True,
'data_compromised': True,
'downtime': ['delivery delays (De Bijenkorf)',
'registry offline (VwbP)'],
'identity_theft_risk': True,
'operational_impact': ['disrupted retail and healthcare '
'operations'],
'systems_affected': ['third-party logistics provider',
'third-party telehealth platform',
'government registries']},
'initial_access_broker': {'data_sold_on_dark_web': ['PNLD data']},
'investigation_status': 'ongoing',
'lessons_learned': 'The shift highlights the need for stronger third-party '
'risk management, continuous monitoring, and robust '
'incident response strategies.',
'motivation': ['financial gain', 'data exposure'],
'post_incident_analysis': {'root_causes': ['exploitation of third-party '
'platforms',
'RaaS model']},
'ransomware': {'ransomware_strain': 'Qilin'},
'recommendations': ['stronger third-party risk management',
'continuous monitoring',
'robust incident response strategies'],
'references': [{'source': 'Cybersecurity Roundup H1 2026'}],
'response': {'containment_measures': ['registry taken offline (VwbP)']},
'threat_actor': ['Qilin ransomware group'],
'title': 'Cybersecurity Roundup: Ransomware Surge, Government Breaches, and '
'Supply Chain Attacks Dominate H1 2026',
'type': ['ransomware', 'data_breach', 'supply_chain_attack']}