IntelliOS Threat Intel Operating System
Sign In
© 2026 IntelliOS
AboutBlogsNewsroomContactLegal

Activity Cards

v1.0Last updated Jul 23, 2026Last AI Agent update: Government Cybersecurity Actions & Advisories Activity Cards Publisher
Published · v4

Ransomware Activity

Ransomware Activity — June 2026

June 2026 ransomware reporting showed elevated public activity, rapid movement among leading RaaS brands, continued pressure on healthcare, services, and education, and multiple access paths that reward early identity, edge, and pre-encryption detection.

17%

Leading published share

102

Publicly disclosed attacks

31

Groups represented

Healthcare

Top BlackFog sector

June 1–30, 20264 sources
Open Activity Card
Published · v4

Government Cybersecurity Actions & Advisories Activity

Government Cybersecurity Actions & Advisories — June 2026

June 2026 government cybersecurity activity combined accelerated KEV remediation demands, joint critical-infrastructure guidance, public-private disruption, and international infrastructure action. The operational value is in recognizing which government outputs create a deadline, which change defensive priorities, and which document a bounded enforcement result.

23

June KEV additions

18

Vendors represented

3–14d

Remediation windows

4

Government action lanes

June 1–30, 20264 sources
Open Activity Card
Published · v4

Law Enforcement Disruption Activity

Law Enforcement Disruption Activity — June 2026

June 2026 enforcement activity applied pressure across malware delivery, fraud platforms, laundering infrastructure, cybercrime-enabling services, and individual operators. The operational value is in understanding what was actually seized, dismantled, frozen, or prosecuted—and what could still reconstitute.

6

June operations retained

326

Servers actioned

142

Domains actioned

~15K

Websites remediated

June 1–30, 20266 sources
Open Activity Card

Source-governed cards track meaningful activity as it emerges and connect relevant findings to Actor, Campaign, and CVE/KEV Cards.

HomeActorsCampaignsCVE/KEVActivityCompass

Definition

Activity Cards: track and preserve source-backed intelligence about significant activity across threat actors, campaigns, law enforcement, government actions, BEC, ransomware, broader cybercrime, and other developments worth monitoring. Cards are published when the evidence warrants.

Search activity

Search Results / Output

Activity Cards

Search across card titles, summaries, activity signals, sectors, impacts, defensive priorities, briefing points, metrics, and retained sources.

4 activity cards

Published · v4

Government Cybersecurity Actions & Advisories Activity

Government Cybersecurity Actions & Advisories — June 2026

June 2026 government cybersecurity activity combined accelerated KEV remediation demands, joint critical-infrastructure guidance, public-private disruption, and international infrastructure action. The operational value is in recognizing which government outputs create a deadline, which change defensive priorities, and which document a bounded enforcement result.

23

June KEV additions

18

Vendors represented

3–14d

Remediation windows

4

Government action lanes

June 1–30, 2026·4 retained sources
Open activity card
Published · v4

Law Enforcement Disruption Activity

Law Enforcement Disruption Activity — June 2026

June 2026 enforcement activity applied pressure across malware delivery, fraud platforms, laundering infrastructure, cybercrime-enabling services, and individual operators. The operational value is in understanding what was actually seized, dismantled, frozen, or prosecuted—and what could still reconstitute.

6

June operations retained

326

Servers actioned

142

Domains actioned

~15K

Websites remediated

June 1–30, 2026·6 retained sources
Open activity card
Published · v4

Business Email Compromise Activity

BEC Activity — June 2026

June 2026 BEC activity combined rising attack volume with higher requested wire amounts, continued gift-card and payroll diversion, and identity-centric techniques that can bypass basic MFA through token and session theft.

+22%

Period-over-period change

59.9%

Gift-card cash-out

$71,295

Average wire request

72%

Free-webmail delivery

June 1–30, 2026·4 retained sources
Open activity card
Rows per page(3 cards)
1
1-3 of 4

Change Log

Activity Cards

v1.0 / last updated Jul 23, 2026

New Activity Card publications and material source-backed revisions are recorded here. Routine monitoring checks that do not change a published card are omitted.

BEC Activity — June 2026 published

Jul 17, 2026

Published v4 with 10 briefing points, 4 retained sources, source-specific claim treatment, and linked CARDS where applicable.

Government Cybersecurity Actions & Advisories — June 2026 published

Jul 18, 2026

Published v4 with 10 briefing points, 4 retained sources, source-specific claim treatment, and linked CARDS where applicable.

Law Enforcement Disruption Activity — June 2026 published

Jul 18, 2026

Published v4 with 10 briefing points, 6 retained sources, source-specific claim treatment, and linked CARDS where applicable.

Ransomware Activity — June 2026 published

Jul 17, 2026

Published v4 with 10 briefing points, 4 retained sources, source-specific claim treatment, and linked CARDS where applicable.