type: incident ยท created: 2026-08-20 ยท updated: 2026-08-22 ยท tags: [incident, breach] ยท confidence: medium ยท affected_sectors: [sector-technology] ยท au_impact: false
Google Threat Intelligence Group detailed three suspected Russian cyber-espionage clusters โ UNC6293 (a sub-cluster of Ice Relic/Cozy Bear/APT29), UNC5976 and UNC7005 โ abusing legitimate authentication flows to single out academics, aerospace and defence staff, governments and think tanks across Europe and the US. The clusters run persistent, adaptive phishing, with UNC6293 conducting OAuth phishing after targets perform legitimate logins and UNC5976 automating token collection through cloud infrastructure and file-sharing-themed domains.