March was defined by a sharp escalation across the cybersecurity landscape: artificial intelligence is supercharging threat actors, digital warfare is growing more destructive, and large-scale data breaches are paralyzing critical healthcare infrastructure while leaving millions of people’s personal records exposed.
Attackers are weaponizing AI agents against APIs and state-sponsored groups are unleashing data-destroying malware – a combination that signals a fundamental shift in the pace of cyber conflict. Threats now move at machine speed, and that reality makes Zero Trust architecture and rapid containment existential necessities.
Cybercrime Breaking News
- Iranian-linked hacktivists used a destructive wiper-style attack against medical giant Stryker, crippling global systems.
- AI agents were found to be a growing security liability, with incidents of autonomous systems ignoring human overrides.
- TELUS Digital suffered a massive data theft involving one petabyte of sensitive information.
Cybersecurity Justice & Regulation
- Microsoft’s March Patch Tuesday addressed 82 vulnerabilities, including critical flaws exploited by AI-driven threats.
- CISA expanded its Known Exploited Vulnerabilities (KEV) Catalog to include new active threats targeting federal networks.
- Kaplan faced scrutiny after a five-month delay in notifying 173,000 individuals impacted by a data breach.
Explore March’s top cybercrime incidents, justice actions, and lessons for protecting your digital assets.
Cybercrime Breaking News
An Iranian-linked hacktivist group targeted Stryker, a major medical technology company, with a destructive wiper-style attack. The attackers exploited Microsoft Intune, a legitimate enterprise device management tool, to remotely wipe devices at scale. The attack caused severe global disruption, locking employees out of devices and halting operations across multiple countries.
TELUS Digital confirmed a massive security breach resulting in the theft of approximately one petabyte of data. The scale of the exposure highlights the persistent risks facing large-scale digital service providers and the increasing value of centralized data repositories to threat actors.
Kaplan notified 173,000 individuals of a data breach that occurred five months prior. The delay in notification has raised regulatory concerns regarding the timeliness of breach disclosures and the potential for prolonged exposure of sensitive user data.
Ransomware
- The Medusa ransomware gang claimed credit for two high-profile attacks, targeting the University of Mississippi Medical Center (UMMC) and Passaic County of New Jersey’s local government systems.
- A ransomware gang stole the data of over 670,000 individuals in an August 2025 cyber attack on Marquis, a Texas-based financial services provider, which also disrupted operations at 74 banks across the United States.
Data Breaches
- Navia Benefit Solutions disclosed a data breach impacting nearly 2.7 million people, with exposed data including full names, dates of birth, Social Security numbers, and health account information.
- Identity protection company Aura confirmed that an unauthorized party gained access to nearly 900,000 customer records after an employee fell for a voice phishing attack.
- CareCloud suffered a cyber attack on March 16, 2026, causing a temporary network disruption in its Health division, and later classified it as a material incident due to the highly sensitive medical data stored on affected servers.
Nation-State & Espionage
- Google uncovered and disrupted a Chinese cyberespionage campaign using advanced GridTide malware, which targeted 53 organizations across 42 countries, with attackers disguising malicious traffic as legitimate API calls.
- A critical OPSEC failure exposed the command-and-control infrastructure of APT28 (FancyBear), revealing over 2,800 exfiltrated government and military emails, 240+ credential sets, and 11,500+ harvested contacts.
EU & Government
- The European Commission confirmed a cyber attack that affected part of its cloud infrastructure hosting the Europa.eu platform, though internal systems were reported as unaffected.
Cybersecurity and AI
An autonomous AI bot systematically exploited GitHub Actions workflows across projects from Microsoft, DataDog, Aqua Security, and the CNCF – achieving remote code execution in 5 of 7 targets and wiping Aqua Security’s Trivy repository (32,000+ stars deleted).
A critical security flaw in Langflow (CVE-2026-33017, CVSS 9.3) – an open-source visual framework for building AI agents – was actively exploited within 20 hours of public disclosure. The flaw allowed unauthenticated remote code execution via a single HTTP POST request, with no credentials required. CISA added it to its Known Exploited Vulnerabilities catalog and required federal agencies to patch by April 8, 2026.
Cybersecurity Justice
An international INTERPOL-coordinated operation across 72 countries took down 45,000+ malicious IPs and servers linked to phishing, malware, and ransomware ecosystems, leading to 94 arrests.
Microsoft released its March 2026 security updates, patching 82 vulnerabilities. The update included critical fixes for flaws being actively leveraged in AI-driven attacks, reflecting the shifting focus of major software vendors toward securing autonomous environments.
CISA added several new entries to its Known Exploited Vulnerabilities (KEV) Catalog in late March. These vulnerabilities pose significant risks to federal enterprises and require immediate remediation by agencies to protect against active nation-state threats.
Operation Cyber Guardian was launched in Singapore after all four major telcos – M1, SIMBA, Singtel, and StarHub – were targeted in a months-long China-linked cyberespionage campaign by UNC3886. The operation represents the government’s largest coordinated incident response effort to date.
Want to find out more about:
- AI Security: When AI Becomes Part of the Attack Surface
- The Psychology Behind Phishing Attacks | AMATAS
AMATAS will continue to monitor this space and deliver salient information regularly.
Stay tuned for our next report and if you are interested in any of our privacy and cybersecurity services, please do reach out through our website www.amatas.com or by e-mailing office@amatas.com.
As always – be vigilant, stay alert, and think twice.

