June 2025 Data Breach Round Up: Major Cybersecurity Incidents

Listen to this post – click on the play button below or read along:

June 2025 Data Breach Round Up
Loading the Elevenlabs Text to Speech AudioNative Player...

As cyberattacks grow more frequent and sophisticated, June 2025 saw a wave of high-impact data breaches across industries—from healthcare and aviation to retail and media. These incidents not only disrupted operations but also exposed the personal information of millions, raising critical concerns about third-party risk, ransomware, and supply chain vulnerabilities. At Findings, we continuously monitor these developments to help businesses understand the evolving threat landscape and strengthen their compliance and security posture. Below, we’ve rounded up the most significant breaches reported this month.

Qantas Hit by Massive Call Center Breach: 6 Million Customers Potentially Affected

Qantas confirmed a cyber incident affecting one of its third-party call centre platforms, potentially exposing the personal data of up to 6 million customers. The compromised data includes names, email addresses, phone numbers, birth dates, and frequent flyer numbers—though financial, password, and passport information were not involved. The breach was detected through unusual activity, prompting Qantas to quickly contain the system and notify authorities including the Australian Federal Police. While Qantas’ own systems remain secure, the airline is now rolling out enhanced monitoring and support services. Customers are being contacted directly, and a dedicated help page has been launched as investigations continue.

Aflac Targeted in Coordinated Insurance Industry Cyberattack

On June 12, 2025, Aflac detected unauthorized activity on its U.S. network, part of a broader cybercrime campaign targeting the insurance sector. The breach was swiftly contained without affecting business operations or involving ransomware. Preliminary findings indicate that attackers used social engineering to gain access, potentially exposing sensitive data such as claims details, health records, Social Security numbers, and personal information tied to customers, agents, and employees. A full review is underway to assess the scope of the breach. In the meantime, Aflac is offering affected individuals free identity protection and credit monitoring for 24 months.

The North Face Discloses Credential Stuffing Attack on Customer Accounts

On April 23, 2025, The North Face detected and stopped a credential stuffing attack targeting user accounts on its website. In this type of attack, cybercriminals used login credentials—stolen from unrelated breaches elsewhere—to gain unauthorized access to accounts where users had reused the same email and password. Exposed data may include names, contact information, shipping addresses, purchase history, and account preferences. No payment card details were compromised, as The North Face does not store that information on its site. While the company isn’t legally required to notify customers, it did so voluntarily, urging users to adopt stronger password practices.

Ransomware Hits Radix, Exposes Swiss Federal Administration Data on Dark Web

In June 2025, Swiss health nonprofit Radix fell victim to a ransomware attack that led to the theft and encryption of sensitive data—some of which has already been published on the dark web. Radix serves multiple Swiss Federal Administration offices, prompting an urgent response from the National Cyber Security Centre (NCSC), though no government systems were directly breached. Investigations are ongoing to identify which federal units and data were affected. The NCSC is coordinating efforts with Radix and law enforcement to assess the impact and manage fallout. The incident highlights the increasing risk ransomware poses to public-sector contractors.

2.2 Million Impacted in Ransomware Attack on Retail Giant Ahold Delhaize

Ahold Delhaize, the multinational grocery powerhouse behind brands like Food Lion and Stop & Shop, confirmed that a ransomware attack on its U.S. business systems compromised the data of over 2.2 million individuals. The stolen data spans personal identifiers, financial details, health records, and employment-related information—though customer credit card and pharmacy systems were reportedly unaffected. While the company has not officially linked the breach to any group, the INC Ransom gang has claimed responsibility and leaked samples on its dark web portal. The attack, which occurred in November 2024, was only fully disclosed in June 2025. Investigations are ongoing, and Ahold Delhaize has not disclosed whether a ransom was paid.

UNFI Cyberattack Disrupts U.S. Grocery Supply Chain, Impacts Q4 Earnings

United Natural Foods Inc. (UNFI), a key supplier to Whole Foods and thousands of grocery retailers across North America, suffered a cyberattack on June 5, 2025, that forced critical systems offline and disrupted operations. While customer and health data were not compromised, the breach crippled electronic ordering and invoicing, leading to canceled shifts, delayed deliveries, and reduced sales volume. Core systems have since been restored, but the company expects the incident to have a material impact on its Q4 financials. External forensics experts and law enforcement are investigating, though UNFI has not disclosed the nature of the attack or identified any threat group. The company expects its cybersecurity insurance to cover related costs, with full resolution anticipated in fiscal 2026.

Hawaiian Airlines Confirms Cybersecurity Incident, Flights Unaffected

On June 26, 2025, Hawaiian Airlines disclosed an ongoing cybersecurity event affecting parts of its IT systems. Despite the disruption, flight operations and guest travel remained unaffected, with the airline continuing to run its full schedule. The company promptly engaged federal authorities and cybersecurity experts to investigate and contain the incident. While few technical details have been released, Hawaiian Airlines has assured the public that safety and data security remain top priorities. Updates are expected as the investigation progresses and systems are restored.

Foreign-State Hack Suspected in Washington Post Journalist Email Breach

In mid-June 2025, The Washington Post discovered a targeted cyberattack that compromised Microsoft email accounts belonging to a select group of journalists—particularly those reporting on national security, economic policy, and China. The breach, first flagged on June 12 and disclosed internally on June 15 by Executive Editor Matt Murray, appears limited in scope and did not affect broader systems or customer data. It’s widely suspected that a foreign government orchestrated the intrusion, drawing parallels with a 2022 News Corp hack. As a precaution, all staff credentials were reset and investigations led by forensic specialists are underway. The incident underscores the sophistication of cyber threats facing media organizations covering geopolitical issues and sensitive news beats.

Medical Vendor Episource Breach Exposes Health and Insurance Data

Episource, a healthcare services provider specializing in medical coding and risk adjustment, revealed a cyberattack that exposed sensitive patient data between January 27 and February 6, 2025. The breach, detected on February 6, allowed attackers to access and copy personal information such as names, contact details, health insurance data, medical records, diagnoses, and—in some cases—Social Security numbers. While there is no evidence of misuse so far, the company began notifying affected clients and individuals starting April 23. Episource has taken systems offline, involved law enforcement, and implemented stronger cybersecurity measures. As a vendor to health plans and providers, the incident underscores third-party risks in the healthcare sector.

A Wake-Up Call for Vendor Risk Management

 

This month’s breaches serve as yet another stark reminder that no sector is immune to cyber risk—and that vendor and third-party systems are often the weakest link. Whether it’s credential stuffing, ransomware, or targeted phishing, attackers are evolving their tactics while regulators raise the bar on accountability. Organizations must prioritize not only their internal cybersecurity but also ensure continuous visibility into their extended supply chains. At Findings, we’re committed to helping enterprises stay resilient with automated, real-time risk monitoring and compliance enforcement across vendors. Stay alert, stay prepared, and stay secure.

See how teams catch vendor breaches before they spread

Already have an account?

Get Started with Findings

* indicates required

We Use Cookies.

This website uses cookies to enhance your browsing experience, analyze site traffic, and improve our services. By continuing to use this site, you consent to our use of cookies in accordance with our privacy policy. You can manage your cookie preferences at any time through your browser settings.