The Week in Breach News: 06/11/25 – 06/17/25

This week: A ransomware attack on a major food distributor leaves grocery chains with bare shelves; an entertainment ticketing platform is knocked out in South Korea; and BullPhish ID gets five new phishing simulation kits in Swedish.

Discover user protection for the modern workforce in our eBook Kaseya 365 User Protection Business Case. GET IT>>

United Natural Foods Inc. (UNFI)
Exploit: Ransomware
Industry: Food & Beverage
United Natural Foods, Inc. (UNFI), a major U.S. distributor of natural, organic and specialty foods based in Providence, RI, has reported a cybersecurity incident that is impacting its operations. The breach was first detected on June 5, when the company identified unauthorized activity within its IT systems. In response, UNFI took parts of its systems offline and initiated its incident response protocols. As a result, the company’s ability to process and fulfill orders has been disrupted. UNFI supplies over 30,000 retailers across the U.S. and Canada, including major chains like Whole Foods Market.
How It Could Affect Your Customers’ Business: A supply chain attack can disable key hubs in critical infrastructure, making rapid recovery essential to restore business operations.
Kaseya to the Rescue: Learn how Tailored Threat Response with RocketCyber Dynamic Remediation speeds up incident response with automation to minimize damage. GET THE FEATURE SHEET>>
Illinois Department of Healthcare and Family Services
https://www.scworld.com/brief/illinois-health-data-stolen-in-february-phishing-attack
Exploit: Phishing
Industry: Government

Officials at the Illinois Department of Healthcare and Family Services (HFS) have disclosed a data breach affecting 933 individuals, including 564 Illinois residents, following a phishing attack in February. According to the agency’s breach notification, threat actors gained access to an HFS employee’s email account through malicious emails sent from another compromised government account. The attackers may have exfiltrated sensitive data such as names, birthdates, driver’s license and state ID numbers, Social Security numbers and information related to child support or Medicaid finances.
How It Could Affect Your Customers’ Business: Regular phishing resistance training as part of your security awareness training program is the best way to prevent employees from falling for phishing tricks.
Kaseya to the Rescue: Learn proven strategies for mitigating both malicious and accidental insider risk to keep businesses out of trouble in our Guide to Insider Risk. DOWNLOAD IT>>
Erie Insurance
Exploit: Hacking
Industry: Insurance
Erie Insurance and Erie Indemnity Company have confirmed that a cyberattack over the weekend is the cause of widespread service disruptions and platform outages affecting their operations since Saturday, June 7. The incident has left many customers unable to access the company’s website or customer portal, with reports of difficulties filing claims or receiving essential documents. In a public statement, Erie Insurance emphasized that it will not contact customers via phone or email to request payments during the outage. The company has not yet disclosed whether ransomware was involved or if any customer data was compromised. Investigations into the scope and impact of the breach are ongoing.
How It Could Affect Your Customers’ Business: A cyber resilient business has implemented robust cybersecurity measures, a smart backup solution and a formal, tested incident response plan.
Kaseya to the Rescue: Get tips to strengthen a company’s defenses and bolster its cyber resilience with our Building a Cyber-Resilient Business checklist. GET THE CHECKLIST>>

Feeling overwhelmed by your task list? Discover four strategies for reducing your workload! GET INFOGRAPHIC>>

Ireland – Ocuco
https://www.bankinfosecurity.com/2-software-firms-report-major-health-data-theft-hacks-a-28699
Exploit: Ransomware
Industry: Technology
Ocuco, a Dublin-based software provider serving 6,750 client sites across 88 countries, has disclosed a major data breach affecting nearly 241,000 individuals, according to a report filed with the U.S. Department of Health and Human Services on May 30. The breach stems from a hacking incident involving a network server and is believed to be linked to a ransomware attack. The ransomware group KillSec has claimed responsibility for the attack on its dark web leak site, alleging it exfiltrated more than 340 gigabytes of data comprising over 670,000 files and 26,000 folders. An Ocuco spokesperson stated the company first became aware of the breach on April 1 after discovering the threat actor’s post online. The company is currently conducting a thorough review to determine what personal data may have been compromised.
How it Could Affect Your Customers’ Business: Proactive monitoring, fast breach detection and strong data inventory are key to assessing cyberattack impact and protecting individuals.
Kaseya to the Rescue: Maximize your security on a lean budget with the insights you’ll find in our infographic 5 Ways to Squeeze More From a Tight Security Budget. DOWNLOAD IT>>

See the evolution of the MSP business in our infographic 7 Key Stats From the 2025 MSP Benchmark Survey. DOWNLOAD IT>>

Canada – WestJet
Exploit: Hacking
Industry: Airline

WestJet, Canada’s second-largest airline, is investigating a cyberattack that has disrupted access to several internal systems and caused intermittent issues on its website and mobile app. While the airline confirmed that flight operations remain safe and ongoing, it admitted that the attack has affected some of its software and services. Customers may experience interruptions or errors when using digital platforms as WestJet continues to assess the full scope of the incident. It remains unclear whether the disruption is due to a ransomware attack or a precautionary shutdown of systems. The company is actively working to determine the impact and restore full functionality.
How it Could Affect Your Customers’ Business: Disruptions to internal systems can swiftly affect customer-facing services and pose significant challenges for critical infrastructure.
Kaseya to the Rescue: Identify the must-have features in a user protection solution and explore how to build a robust user protection strategy in our Modern User Protection Buyer’s Guide. GET IT>>

Get expert advice for protecting your organization’s most vulnerable gateway in this infographic. DOWNLOAD IT>>

South Korea – Yes24
https://therecord.media/yes24-south-korea-ransomware-attack
Exploit: Ransomware
Industry: Entertainment
A ransomware attack on Yes24, one of South Korea’s largest ticketing platforms and online book retailers, has caused widespread disruption across the country’s entertainment sector. The cyberattack took Yes24’s website and services offline for four days, halting online bookings for concerts, e-book access, and community forums, before full operations were restored by June 15. The outage led to the cancellation or postponement of events featuring stars such as Park Bo-gum, Enhypen, Ateez and rapper B.I. Additionally, musical producers for shows like The Bridges of Madison County and Aladdin implemented stricter entry procedures, requiring audiences to present printed or emailed ticket confirmations. Several attendees were reportedly turned away earlier in the week due to their inability to verify their reservations.
How it Could Affect Your Customers’ Business: It is essential for those at the center of any supply chain to recover quickly, as disruptions can have widespread impacts on many businesses.
Kaseya to the Rescue: Discover how Kaseya 365 User delivers comprehensive protection beyond the endpoint without breaking the bank. GET THE EBOOK>>
India – Zoomcar
https://therecord.media/8-million-affected-zoomcar-data-breach
Exploit: Hacking
Industry: Transportation
Indian car-sharing company Zoomcar has disclosed a data breach impacting the personal information of approximately 8.4 million users. The company first became aware of the incident on June 9, when hackers contacted Zoomcar employees claiming to have accessed its systems and stolen user data. The compromised information includes names, phone numbers, car registration numbers, addresses and email addresses. Zoomcar, which operates in 99 cities across India and serves over 10 million users, is investigating the breach but stated there is currently no evidence that financial details or passwords were compromised. This marks the second major breach for Zoomcar, following a significant incident in July 2018.
How it Could Affect Your Customers’ Business: A data breach undermines customer trust, and companies that experience repeated issues risk losing customers rapidly.
Kaseya to the Rescue: Explore the biggest challenges professionals contended with in 2024 and the impact of AI on cybersecurity in the Kaseya Cybersecurity Survey 2024. GET THE REPORT>>

Take a deep dive into why an AI-powered anti-phishing solution is a smart financial choice. GET EBOOK>>


5 new finance-themed phishing simulations are available now in Swedish
Boost your team’s phishing awareness with our new Swedish-language phishing resistance training kits featuring related to finance.
- Betaltjänst – Misslyckad betalning
- Skatteverket – Skatteåterbäring tillgängli
- Skatteverket – Obehörig inloggning
- Skatteverket – Anställningsförmåner
- Swedbank – Obehörig aktivitet upptäckt på ditt konto
Learn more about these kits and other new releases in the BullPhish ID Release Notes.

Learn how to spot today’s most dangerous cyberattack & get defensive tips in Phishing 101 GET EBOOK>>

How cyber resilient are you?
Strengthen any organization’s defenses with our “Building a Cyber-Resilient Business” checklist. From risk assessments to incident response planning, this actionable guide helps ensure businesses can withstand and recover from today’s evolving cyber threats.
Download the checklist now! DOWNLOAD IT>>

Beyond MFA: How to Prevent Session Hijacking and Protect Business Email
June 24, 2025 | 1:00 PM ET
Multi-factor authentication (MFA) alone won’t stop today’s advanced threats. Adversary-in-the-Middle (AiTM) attacks can sidestep MFA and seize Microsoft 365 sessions—exposing critical data and disrupting business operations.
Join us to learn how these attacks operate and what you can do to stop them. We’ll dive into real-world defenses including token protection, hardened M365 settings and automated detection with SaaS Alerts.
June 19: Tech Jam: Managing Mobile Devices with Kaseya VSA 10 REGISTER NOW>>
June 24: DACH Monthly REGISTER NOW>>
July 3: Kaseya + Datto Connect Local: Perth REGISTER NOW>>
July 15: Kaseya + Datto Connect Local: Montreal REGISTER NOW>>
July 22: Kaseya + Datto Connect Local: Toronto Symposium REGISTER NOW>>
August 5: Kaseya + Datto Connect Local: Los Angeles REGISTER NOW>>
August 12: Kaseya + Datto Connect Local: Houston REGISTER NOW>>
August 14: Kaseya + Datto Connect Local: Dallas REGISTER NOW>>
August 28: Kaseya+Datto Connect Local: Brisbane REGISTER NOW>>
September 4: Kaseya+Datto Connect Local: Adelaide REGISTER NOW>>
September 4: Kaseya+Datto Connect Local: Adelaide REGISTER NOW>>
October 6 – 8: Kaseya DattoCon Miami REGISTER NOW>>
October 28 – 30: Kaseya DattoCon Asia-Pacific REGISTER NOW>>

Do you have comments? Requests? News tips? Complaints (or compliments)? We love to hear from our readers! Send a message to the editor.
Partners: Feel free to reuse this content. When you get a chance, email [email protected] to let us know how our content works for you!

Read our case studies and see how MSPs and businesses have benefited from using our solutions. READ NOW>