The reported cyberattacks in June 2026 targeted applications and tools used daily, not just institutions or technical infrastructures. CERT-EU shows in its latest Cyber Brief that attackers used Instagram account recovery, fake AI intelligence plugins for programmers, fraudulent Gmail alerts, and messages that imitated Signal support to steal access to accounts, passwords, authentication codes, and recovery keys.
In short
CERT-EU mentions the abuse of the Meta AI tool for Instagram account recovery for account takeovers. At least 15 plugins on the JetBrains Marketplace, presented as AI assistants for programming, allegedly stole API keys from AI providers. The actor Ghostwriter, likely linked to Belarus, targeted Gmail users in Poland, including individuals from political life, journalists, researchers, and public administration. Actors associated with Russia targeted Signal users, attempting to obtain recovery keys for access to messages and account takeovers.
The CERT-EU report shows that cybersecurity can no longer be reduced to servers, technical vulnerabilities, and attacks on institutions. A significant part of the risk passes through known applications, personal accounts, and common professional tools. Attackers seek entry points in places where users already have trust: a security email, a recovery page, a programming plugin, or a conversation on a messaging app.
A visible case concerns Instagram. According to CERT-EU, unknown actors abused the Meta AI account recovery tool to obtain password reset codes and take over accounts without proper verification. In particular, these were accounts with short and valuable usernames, which were then quickly resold through Telegram channels.
Meta stated that there was no breach in its backend systems and that the issue was resolved after public reporting. The incident remains relevant as it shows how functions designed for access recovery can become attack tools when identity verification is not robust enough.
Software developers were targeted through a separate campaign on the JetBrains Marketplace. CERT-EU notes that researchers reported a coordinated campaign in which at least 15 plugins for development environments were presented as AI assistants for programming but secretly stole API keys from AI providers. The campaign may have affected multiple provider accounts and could have reached nearly 70,000 installations.
Stolen API keys can allow unauthorized use of AI services, account abuse, and unexpected costs for victims. In the case of developers, the risk can go further: a plugin installed in a work environment can access projects, development flows, configurations, and services used for production. A tool that seems to increase productivity can become an entry point into a company's digital infrastructure.
CERT-EU also mentions a phishing campaign likely attributed to the Ghostwriter actor, associated with Belarus. CERT Polska reported on June 12 intense campaigns targeting Gmail users in Poland. Attackers allegedly sent fraudulent emails imitating Gmail security alerts to collect authentication data and two-factor authentication codes.
The mentioned victims include individuals from political and public life, journalists, researchers, and public administration. The report also notes a wider dissemination to recipients without direct connection, caused by guessing addresses. The technique is simple but effective: the message appears to come from the security area of a known service, and the user is pushed to enter sensitive data into a fake page.
Signal was targeted through another type of phishing. The FBI announced on June 26 the actors associated with Russia, UNC5792 and UNC4221, who target Signal users' recovery keys. Attackers continue to present themselves as Signal support but are now trying to obtain the recovery key for backup, which can allow them to see saved messages, private and group messages, and take over the victim's account.
This type of attack is different from simply stealing a password. Recovery keys can provide access to historical content and conversations that may contain sensitive personal, professional, or political information. For individuals involved in administration, journalism, politics, research, or activism, compromising a messaging account can expose contact networks and private discussions.
The report also includes a case related to WhatsApp and the NSO Group. WhatsApp reported that it detected and stopped spearphishing and social engineering attempts associated with NSO, where users were being tried to be persuaded to click on malicious links. The activity allegedly included accounts and test groups removed by the platform, and WhatsApp provided indicators for identifying similar attempts on other channels, such as SMS, email, or WhatsApp.
These episodes show a shift in focus in cyberattacks. Personal and professional accounts are becoming valuable targets as they provide access to digital identity, contacts, work tools, cloud services, and private communication. Attackers do not always need to directly breach a government or corporate network if they can take over the accounts of individuals who have access to that network.
Artificial intelligence appears in the report in two ways. On one hand, attackers use interest in AI as bait, through fake plugins presented as programming assistants. On the other hand, AI tools integrated into platforms can create new attack surfaces when recovery, verification, or automation processes are abused.
CERT-EU also mentions incidents related to AI models and global competition in cybersecurity, including claims from Chinese companies regarding automatic vulnerability discovery tools and cybersecurity defense. In the same report, security researchers assessed that the GLM-5.2 model from the Chinese company Z.ai has vulnerability discovery capabilities comparable to top American models. These developments show that AI is rapidly becoming part of the competition for cyber defense and offense.
The CERT-EU report for June describes a digital space where attacks are increasingly approaching the user. The Instagram account, Gmail account, Signal key, plugin used in programming, or link received on WhatsApp can become entry points for data theft, extortion, espionage, or digital identity takeover. Cybersecurity increasingly depends on careful verification of installed tools, recovery messages, security alerts, and access granted to third-party applications.
In short
CERT-EU mentions the abuse of the Meta AI tool for Instagram account recovery for account takeovers. At least 15 plugins on the JetBrains Marketplace, presented as AI assistants for programming, allegedly stole API keys from AI providers. The actor Ghostwriter, likely linked to Belarus, targeted Gmail users in Poland, including individuals from political life, journalists, researchers, and public administration. Actors associated with Russia targeted Signal users, attempting to obtain recovery keys for access to messages and account takeovers.
The CERT-EU report shows that cybersecurity can no longer be reduced to servers, technical vulnerabilities, and attacks on institutions. A significant part of the risk passes through known applications, personal accounts, and common professional tools. Attackers seek entry points in places where users already have trust: a security email, a recovery page, a programming plugin, or a conversation on a messaging app.
A visible case concerns Instagram. According to CERT-EU, unknown actors abused the Meta AI account recovery tool to obtain password reset codes and take over accounts without proper verification. In particular, these were accounts with short and valuable usernames, which were then quickly resold through Telegram channels.
Meta stated that there was no breach in its backend systems and that the issue was resolved after public reporting. The incident remains relevant as it shows how functions designed for access recovery can become attack tools when identity verification is not robust enough.
Software developers were targeted through a separate campaign on the JetBrains Marketplace. CERT-EU notes that researchers reported a coordinated campaign in which at least 15 plugins for development environments were presented as AI assistants for programming but secretly stole API keys from AI providers. The campaign may have affected multiple provider accounts and could have reached nearly 70,000 installations.
Stolen API keys can allow unauthorized use of AI services, account abuse, and unexpected costs for victims. In the case of developers, the risk can go further: a plugin installed in a work environment can access projects, development flows, configurations, and services used for production. A tool that seems to increase productivity can become an entry point into a company's digital infrastructure.
CERT-EU also mentions a phishing campaign likely attributed to the Ghostwriter actor, associated with Belarus. CERT Polska reported on June 12 intense campaigns targeting Gmail users in Poland. Attackers allegedly sent fraudulent emails imitating Gmail security alerts to collect authentication data and two-factor authentication codes.
The mentioned victims include individuals from political and public life, journalists, researchers, and public administration. The report also notes a wider dissemination to recipients without direct connection, caused by guessing addresses. The technique is simple but effective: the message appears to come from the security area of a known service, and the user is pushed to enter sensitive data into a fake page.
Signal was targeted through another type of phishing. The FBI announced on June 26 the actors associated with Russia, UNC5792 and UNC4221, who target Signal users' recovery keys. Attackers continue to present themselves as Signal support but are now trying to obtain the recovery key for backup, which can allow them to see saved messages, private and group messages, and take over the victim's account.
This type of attack is different from simply stealing a password. Recovery keys can provide access to historical content and conversations that may contain sensitive personal, professional, or political information. For individuals involved in administration, journalism, politics, research, or activism, compromising a messaging account can expose contact networks and private discussions.
The report also includes a case related to WhatsApp and the NSO Group. WhatsApp reported that it detected and stopped spearphishing and social engineering attempts associated with NSO, where users were being tried to be persuaded to click on malicious links. The activity allegedly included accounts and test groups removed by the platform, and WhatsApp provided indicators for identifying similar attempts on other channels, such as SMS, email, or WhatsApp.
These episodes show a shift in focus in cyberattacks. Personal and professional accounts are becoming valuable targets as they provide access to digital identity, contacts, work tools, cloud services, and private communication. Attackers do not always need to directly breach a government or corporate network if they can take over the accounts of individuals who have access to that network.
Artificial intelligence appears in the report in two ways. On one hand, attackers use interest in AI as bait, through fake plugins presented as programming assistants. On the other hand, AI tools integrated into platforms can create new attack surfaces when recovery, verification, or automation processes are abused.
CERT-EU also mentions incidents related to AI models and global competition in cybersecurity, including claims from Chinese companies regarding automatic vulnerability discovery tools and cybersecurity defense. In the same report, security researchers assessed that the GLM-5.2 model from the Chinese company Z.ai has vulnerability discovery capabilities comparable to top American models. These developments show that AI is rapidly becoming part of the competition for cyber defense and offense.
The CERT-EU report for June describes a digital space where attacks are increasingly approaching the user. The Instagram account, Gmail account, Signal key, plugin used in programming, or link received on WhatsApp can become entry points for data theft, extortion, espionage, or digital identity takeover. Cybersecurity increasingly depends on careful verification of installed tools, recovery messages, security alerts, and access granted to third-party applications.
Latest News
19:14
Lando Norris secured pole position at the Dutch Grand Prix qualifying, followed by George Russell and Kimi Antonelli
19:00
The police in Focșani took notice after a man was caught on the roof of a moving taxi.
18:55
The German Foreign Minister, Johann Wadephul, announced in Kiev the allocation of 60 million euros for Ukraine, of which 50 million is for humanitarian aid and 10 million for NATO assistance.
18:50
Serena Williams will play in a team with Carlos Alcaraz in the mixed doubles event at the U.S. Open, marking her return to competition after 2022.
18:41
Resumption of medical activity at Fundeni Institute after the rapid extinguishing of a minor fire in a ward
See more news