Date |
Source |
Org / Sector |
Incident/Impact |
URL |
| 3/3/26 | BleepingComputer | LexisNexis Legal & Professional (Data analytics, US) | Hackers breached servers via an unpatched React2Shell vulnerability (CVSS 10.0) and leaked stolen files; company confirmed access to some customer and business information, insisting no SSNs or financial data were taken. | https://www.bleepingcomputer.com/news/security/lexisnexis-confirms-data-breach-as-hackers-leak-stolen-files/
|
| 3/3/26 | BleepingComputer | AkzoNobel (Manufacturing / Paints, NL/US) | Anubis ransomware gang breached a U.S. site and claimed 170GB of data including confidential agreements, passport scans, emails, and internal technical documents; company said incident was contained and limited to that site. | https://www.bleepingcomputer.com/news/security/paint-maker-giant-akzonobel-confirms-cyberattack-on-us-site/ |
| 3/3/26 | BleepingComputer | University of Hawaii Cancer Center (Healthcare, US) | Ransomware attack from August 2025 confirmed to have stolen data belonging to nearly 1.2 million individuals from the Cancer Center’s Epidemiology Division; disclosed in March 2026. | https://www.bleepingcomputer.com/news/security/uh-cancer-center-data-breach-affects-nearly-12-million-people/ |
| 11/3/26 | The Register | Stryker (Medical technology, US) | Check Point Research called the attack ‘a significant escalation’ and the first destructive Iranian-backed attack on a major U.S. enterprise; employees watched devices wipe in real time and some lost personal data from BYOD phones enrolled in Intune. | https://www.theregister.com/2026/03/11/us_medtech_firm_stryker_cyberattack_iran/ |
| 11/3/26 | BleepingComputer | Stryker / Handala (follow-up) | FBI seized Handala’s two clearnet websites following the attack; DOJ confirmed Handala is operated by Iran’s Ministry of Intelligence and Security (MOIS) and is a state-run fake hacktivist persona used for psychological operations. | https://www.bleepingcomputer.com/news/security/fbi-seizes-handala-data-leak-site-after-stryker-cyberattack/ |
| 17/03/2026 | TechCrunch | Stryker / CISA advisory (Medical technology, US) | CISA urged all U.S. organisations to harden Microsoft Intune environments and enforce dual-admin approval for device wipe commands after Stryker attack highlighted the risk of unchecked MDM admin privileges. | https://techcrunch.com/2026/03/19/cisa-urges-companies-to-secure-microsoft-intune-systems-after-hackers-mass-wipe-stryker-devices/ |
| 11/3/26 | The Register | TELUS Digital (Business process outsourcing, Canada) | ShinyHunters claimed theft of 1 petabyte of data from TELUS Digital spanning BPO customer data, source code, FBI background checks, financial records, voice recordings, and Salesforce data; company confirmed a security incident. | https://www.theregister.com/2026/03/15/telus_breach_starbucks_attack/ |
| 19/03/2026 | BleepingComputer | Dutch Ministry of Finance (Government, Netherlands) | Breach detected on March 19 affecting employee data; systems used for tax collection and subsidies were unaffected; no threat group claimed responsibility at time of reporting. | https://www.privacyguides.org/news/2026/03/27/data-breach-roundup-mar-20-26-2026/ |
| 20/03/2026 | TechCrunch | DOJ / FBI vs. Handala (Threat actor attribution, US) | U.S. Justice Department formally accused Iran’s MOIS of operating Handala; FBI seized four domains across two hacktivist personas; DOJ linked same individuals to the 2022 Albanian government hack. | https://techcrunch.com/2026/03/20/u-s-accuses-irans-government-of-operating-hacktivist-group-that-hacked-stryker/ |
| 24/03/2026 | TechCrunch | Crunchyroll (Streaming / Entertainment, US) | Confirmed breach via downstream compromise of outsourcing partner TELUS Digital; hacker accessed Crunchyroll’s Zendesk support system and stole customer support ticket data through a compromised TELUS employee account. | https://techcrunch.com/2026/03/24/crunchyroll-confirms-data-breach-after-hacker-claims-unauthorized-access/ |
| 24/03/2026 | The Register | HackerOne / Navia (Bug bounty / Benefits admin, US) | BOLA vulnerability in benefits administrator Navia exposed HackerOne employee data including SSNs, full names, addresses, DOB, and plan details between Dec 22 2025 and Jan 15 2026; Navia’s wider breach affected 2.6M people; HackerOne criticised Navia for delayed notification. | https://www.theregister.com/2026/03/24/hackerone_supplier_breach/ |
| 24/03/2026 | BleepingComputer | Infinite Campus (EdTech / K-12 student data, US) | ShinyHunters claimed data theft from one of the most widely-used K-12 student information systems in the US; company warned customers of a breach and an extortion attempt; scope of student data affected under investigation. | https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/ |
| 26/03/2026 | BleepingComputer | Mazda Motor Corporation (Automotive, Japan) | Security breach detected in December 2025 exposed data of 692 employees and business partners from a warehouse management system in Thailand; exposed data includes user IDs, names, emails, company names, and partner IDs. | https://www.bleepingcomputer.com/news/security/mazda-discloses-security-breach-exposing-employee-and-partner-data/ |
See how we can build your digital capability,
call us on +44(0)845 226 3351 or send us an email…
-
1 July 2026
Building a Foundation for Risk
-
22 June 2026
The Convergence Imperative
-
4 June 2026
From Reactive to Resilient: Managed Splunk Operations for a Leading UK Financial Business


