Cyber Breaches & Enterprise Incidents – March 2026

 

Date

Source

Org / Sector

Incident/Impact

 URL

3/3/26 BleepingComputer LexisNexis Legal & Professional (Data analytics, US) Hackers breached servers via an unpatched React2Shell vulnerability (CVSS 10.0) and leaked stolen files; company confirmed access to some customer and business information, insisting no SSNs or financial data were taken. https://www.bleepingcomputer.com/news/security/lexisnexis-confirms-data-breach-as-hackers-leak-stolen-files/

 

3/3/26 BleepingComputer AkzoNobel (Manufacturing / Paints, NL/US) Anubis ransomware gang breached a U.S. site and claimed 170GB of data including confidential agreements, passport scans, emails, and internal technical documents; company said incident was contained and limited to that site. https://www.bleepingcomputer.com/news/security/paint-maker-giant-akzonobel-confirms-cyberattack-on-us-site/
3/3/26 BleepingComputer University of Hawaii Cancer Center (Healthcare, US) Ransomware attack from August 2025 confirmed to have stolen data belonging to nearly 1.2 million individuals from the Cancer Center’s Epidemiology Division; disclosed in March 2026. https://www.bleepingcomputer.com/news/security/uh-cancer-center-data-breach-affects-nearly-12-million-people/
11/3/26 The Register Stryker (Medical technology, US) Check Point Research called the attack ‘a significant escalation’ and the first destructive Iranian-backed attack on a major U.S. enterprise; employees watched devices wipe in real time and some lost personal data from BYOD phones enrolled in Intune. https://www.theregister.com/2026/03/11/us_medtech_firm_stryker_cyberattack_iran/
11/3/26 BleepingComputer Stryker / Handala (follow-up) FBI seized Handala’s two clearnet websites following the attack; DOJ confirmed Handala is operated by Iran’s Ministry of Intelligence and Security (MOIS) and is a state-run fake hacktivist persona used for psychological operations. https://www.bleepingcomputer.com/news/security/fbi-seizes-handala-data-leak-site-after-stryker-cyberattack/
17/03/2026 TechCrunch Stryker / CISA advisory (Medical technology, US) CISA urged all U.S. organisations to harden Microsoft Intune environments and enforce dual-admin approval for device wipe commands after Stryker attack highlighted the risk of unchecked MDM admin privileges. https://techcrunch.com/2026/03/19/cisa-urges-companies-to-secure-microsoft-intune-systems-after-hackers-mass-wipe-stryker-devices/
11/3/26 The Register TELUS Digital (Business process outsourcing, Canada) ShinyHunters claimed theft of 1 petabyte of data from TELUS Digital spanning BPO customer data, source code, FBI background checks, financial records, voice recordings, and Salesforce data; company confirmed a security incident. https://www.theregister.com/2026/03/15/telus_breach_starbucks_attack/
19/03/2026 BleepingComputer Dutch Ministry of Finance (Government, Netherlands) Breach detected on March 19 affecting employee data; systems used for tax collection and subsidies were unaffected; no threat group claimed responsibility at time of reporting. https://www.privacyguides.org/news/2026/03/27/data-breach-roundup-mar-20-26-2026/
20/03/2026 TechCrunch DOJ / FBI vs. Handala (Threat actor attribution, US) U.S. Justice Department formally accused Iran’s MOIS of operating Handala; FBI seized four domains across two hacktivist personas; DOJ linked same individuals to the 2022 Albanian government hack. https://techcrunch.com/2026/03/20/u-s-accuses-irans-government-of-operating-hacktivist-group-that-hacked-stryker/
24/03/2026 TechCrunch Crunchyroll (Streaming / Entertainment, US) Confirmed breach via downstream compromise of outsourcing partner TELUS Digital; hacker accessed Crunchyroll’s Zendesk support system and stole customer support ticket data through a compromised TELUS employee account. https://techcrunch.com/2026/03/24/crunchyroll-confirms-data-breach-after-hacker-claims-unauthorized-access/
24/03/2026 The Register HackerOne / Navia (Bug bounty / Benefits admin, US) BOLA vulnerability in benefits administrator Navia exposed HackerOne employee data including SSNs, full names, addresses, DOB, and plan details between Dec 22 2025 and Jan 15 2026; Navia’s wider breach affected 2.6M people; HackerOne criticised Navia for delayed notification. https://www.theregister.com/2026/03/24/hackerone_supplier_breach/
24/03/2026 BleepingComputer Infinite Campus (EdTech / K-12 student data, US) ShinyHunters claimed data theft from one of the most widely-used K-12 student information systems in the US; company warned customers of a breach and an extortion attempt; scope of student data affected under investigation. https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/
26/03/2026 BleepingComputer Mazda Motor Corporation (Automotive, Japan) Security breach detected in December 2025 exposed data of 692 employees and business partners from a warehouse management system in Thailand; exposed data includes user IDs, names, emails, company names, and partner IDs. https://www.bleepingcomputer.com/news/security/mazda-discloses-security-breach-exposing-employee-and-partner-data/

See how we can build your digital capability,
call us on +44(0)845 226 3351 or send us an email…