Chime Financial, Inc.
April 1, 2026
•[ cyberattack, data theft, server outage ]
Islamic Cyber Resistance in Iraq (313 Team), also referenced as Team 313 or 313 Team, allegedly claimed responsibility online for attacking Chime's servers on April 1, 2026, causing a widespread outage that prevented customers from accessing accounts through the application and website. Lawsuits alleged that the incident also involved theft of sensitive customer information from Chime systems, but public reporting did not confirm the exact data volume, technical vector, or whether Chime independently confirmed the data-theft allegations.
Belgrade School District
April 1, 2026
•[ malware, system restoration, data breach investigation ]
Belgrade School District confirmed that malware infected certain network systems, causing technology problems and requiring isolation, removal, security work, and restoration of affected systems. The district said known malware had been removed, but crews were still working to bring affected systems back online and restoration was expected to continue into June. The incident appears distinct from the separate Canvas/Instructure breach because public reporting describes malware in Belgrade School District's own network systems, not unauthorized access to Instructure's Canvas LMS. The district was investigating whether personal information belonging to students or staff was affected, but no confirmed data exposure, encryption, ransomware group, or named perpetrator was reported.
Centre of Registers
April 1, 2026
•[ stolen credentials, unauthorized access, database breach ]
Attackers used stolen or misused login credentials assigned to authorized institutions to access Lithuania's Centre of Registers databases and extract more than 600,000 records from the Real Estate Register and Legal Entities Register. Lithuanian authorities suspected foreign-country involvement, but no specific country or actor was publicly confirmed.
Charter Communications, Inc.
April 1, 2026
•[ vishing, data leak, employee records ]
ShinyHunters claimed it breached Charter Communications on April 1, 2026 through a vishing attack that compromised an employee Microsoft Entra account and enabled access to Charter's Salesforce instance. BleepingComputer and Have I Been Pwned reported that the later published dataset exposed 4.9 million unique email addresses/accounts, along with names, phone numbers, and physical addresses; a subset of approximately 85,000 internal employee-directory records also included job titles. Public reporting did not confirm encryption, data destruction, or operational disruption.
Axios Javascript Client Library
March 31, 2026
•[ supply chain attack, account takeover, malware ]
A threat actor hijacked the npm account of Axios's lead maintainer and published malicious versions 1.14.1 and 0.30.4 with a hidden dependency that deployed a RAT on systems that installed the packages; the poisoned versions were later removed.
Town of Pepperell
March 31, 2026
•[ cyberattack, public safety, municipal systems ]
A cyberattack impacted Pepperell's employee computer systems and public safety departments, knocking out certain business phone lines and disrupting some municipal and dispatch-related systems while 911 service remained operational.
Hallmark
March 31, 2026
•[ data leak, extortion, support tickets ]
In March 2026, Hallmark suffered an alleged breach and subsequent extortion after attackers gained access to data stored within Salesforce. The data was later published after the extortion deadline passed, exposing 1.7M unique email addresses across both Hallmark and the Hallmark+ streaming service, along with names, phone numbers, physical addresses and support tickets.
Adaptavist Group
March 31, 2026
•[ unauthorized access, stolen credentials, data theft ]
Adaptavist Group detected unauthorized access to some systems in late March 2026 after an intruder used stolen credentials. Adaptavist said the accessed systems contained typical business data such as contact information, contracts, and NDAs; The Gentlemen claimed responsibility and claimed 24 GB of data theft, allegedly including source code, customer records, internal documents, credentials, and production-system references, but Adaptavist did not confirm the full claim.
Remita Payment Services Ltd
March 31, 2026
•[ data exfiltration, KYC documents, database leak ]
Remita Payment Services Ltd was named in Nigerian data-protection investigations after ByteToBreach claimed to have exfiltrated approximately 3 TB of data from Remita-linked systems, including KYC documents, databases, logs, backups, source code, password hashes, and customer and employee records. The Nigeria Data Protection Commission served notices of investigation on April 1, 2026, and the claimed data theft remains under investigation.
Świętokrzyskie Rehabilitation Center
March 31, 2026
•[ ransomware, encryption, personal data ]
witokrzyskie Rehabilitation Center reported a ransomware attack that encrypted personal-data files and may have exposed data.
Patriot Regional Emergency Communications Center
March 31, 2026
•[ cyberattack, service disruption, emergency services ]
A cyberattack disrupted non-emergency and business telephone lines for police, fire, and EMS departments in Pepperell, Dunstable, Townsend, and Ashby; 911 service remained functional and no private user information was reported compromised.
Parque Eólico Toabré
March 31, 2026
•[ cyberattack, data leak, ransomware ]
Everest claimed responsibility for a cyberattack against Parque Elico Toabr on March 31, 2026 and threatened to release sensitive data. La Estrella de Panam later listed Parque Elico Toabr among Panamanian technology incidents dated May 9, 2026, and other dark-web monitoring reported an alleged 175GB database leak. Public reporting did not confirm encryption, data destruction, operational disruption, or compromise of wind-farm control systems.
Eholo Health
March 30, 2026
•[ data leak, vulnerability exploitation, medical records ]
XP95 claimed it stole 165 GB of data from Eholo Health, including more than 1.1 million medical notes and personal information tied to 601,308 users, after exploiting a vulnerability in the company's systems.
Maine state government
March 30, 2026
•[ phishing, email account compromise, unauthorized access ]
State officials discovered that a Maine government employees email account had been accessed by cybercriminals, who used it to send phishing messages to internal staff and external contacts. The Security Operations Center secured the account, shut down the suspicious activity, and stopped additional unauthorized emails. No evidence of personal or sensitive data access was reported.
YEDNA
March 30, 2026
•[ DDoS, hacktivism, api outage ]
Pro-Russian hacker groups PalachPro and Noname057(16) claimed a DDoS attack against Ukrainian social network YEDNA less than a day after its March 29 launch. The attack disabled the platform API, leaving the website and social-network functionality unavailable to visitors; no restoration time was reported.
Statistics South Africa
March 29, 2026
•[ cyber breach, data theft, ransomware ]
Stats SA said a cyber breach affected one HR database used for online job applications, while XP95 claimed it stole 453,362 files totaling 154 GB and demanded ransom.
Scotia-Glenville Central School District Facebook page
March 29, 2026
•[ Account Takeover, Social Media Hijacking, Unauthorized Access ]
A malicious actor gained administrative control of the Scotia-Glenville Central School District Facebook page through a hacked non-district account used by its communications specialist and posted inappropriate videos and replies while posing as the district; the district said its internal servers and data systems were not compromised.
Paidwork
March 29, 2026
•[ hack, leak, technology ]
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.
Hasbro Systems
March 28, 2026
•[ unauthorized access, cyberattack, operational disruption ]
Hasbro identified unauthorized access to its network on March 28, 2026 and took select systems offline as a containment measure while continuing operations through business-continuity procedures; the company warned that interim measures could cause order-processing, shipping, and invoicing delays while it reviewed potentially impacted files.
FBI Director Kash Patel's personal Gmail
March 27, 2026
•[ data leak, email breach, state-sponsored attack ]
Iran-linked group Handala claimed it breached FBI Director Kash Patel's personal Gmail account and published historical emails, photographs, and files; the FBI said the exposed material did not involve government information.