At least one individual
March 18, 2026
•[ phishing, malware, social engineering ]
Cyber fraudsters in Navi Mumbai impersonated Mahanagar Gas Limited officials and sent malicious WhatsApp files or links that compromised victims' phones and enabled unauthorized access to their bank accounts.
Sterling Bank Plc
March 18, 2026
•[ CVE-2025-55182, remote code execution, data leak ]
ByteToBreach exploited CVE-2025-55182 in Sterling Banks internet-facing pilot infrastructure on March 18, 2026, gaining unauthenticated remote code execution, conducting internal reconnaissance, and publishing artefacts that Web Security Lab assessed as technically substantiating compromise of customer and employee records.
Infinite Campus
March 18, 2026
•[ ransomware, leak, technology ]
In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus subsequently sent notifications, advising that the exposed data largely consisted of "names and contact information for school staff" and that "the majority is directory information commonly found on school websites".
Nordstrom
March 17, 2026
•[ phishing, cryptocurrency scam, SSO compromise ]
Cybernews reported Nordstrom customers received fraudulent emails from an official Nordstrom email address promoting a St. Patricks Day double your crypto scam. Reporting cited a source saying the breach occurred via an Okta SSO to Salesforce compromise, and scam emails were sent using Salesforce Marketing Cloud. Analysis of the scam wallet address indicated the attacker received a little over $5,600 in cryptocurrency.
The Gauteng Provincial Governmen
March 17, 2026
•[ ransomware, data leak, data exfiltration ]
Daily Maverick reported a ransomware-as-a-service syndicate calling itself XP95 claimed it stole 3.8TB of data from the Gauteng Provincial Government. The article describes the breach as a major failure of basic cybersecurity infrastructure and governance, with a massive dataset reportedly lifted/exfiltrated and allegedly offered for sale. The report did not provide a definitive public inventory of affected systems or all data elements, but characterized the exposure as potentially spanning personnel, procurement, and other government records at very large scale.
Sweden's BankID
March 17, 2026
•[ data leak, credential leak, source code leak ]
Biometric Update reported a hacker group calling itself ByteToBreach claimed a breach at CGIs Swedish division, leaking code and credentials tied to systems used by Swedish public authorities and linked in reporting to BankID authentication flows (including for the Swedish Tax Agency). The article said other databases containing personal data and electronic signature documents were allegedly being sold separately. The report is based on attacker claims and leak assertions and does not provide an official confirmation of full scope from CGI or BankID in the excerpt.
La Mutuelle Familiale
March 17, 2026
•[ cyberattack, service disruption, investigation ]
La Mutuelle Familiale disclosed a cyberattack detected on March 17, 2026 that temporarily disrupted multiple member and back-office services while investigations continued; no perpetrator or data theft was publicly confirmed.
Police Nationale (France) training platform users
March 17, 2026
•[ data breach, hacking, government ]
01net reported that data relating to French police personnel was stolen after the e-campus training platform was hacked.
Outpost24
March 16, 2026
•[ phishing, DKIM, social engineering ]
SecurityWeek reported that a C-level executive at Outpost24 was targeted with a sophisticated phishing attempt that used a DKIM-signed email, trusted redirection infrastructure, compromised servers, and Cloudflare-protected phishing pages. Outpost24s subsidiary Specops Software said it detected and blocked the attack early before any systems were compromised or users impacted.
At least one member of the Ukrainian armed forces
March 16, 2026
•[ espionage, spyware, phishing ]
The Record reported researchers attributed a new espionage campaign targeting Ukrainian organizations to the Russia-linked group Laundry Bear (Void Blizzard), active since at least 2024. The campaign used spyware embedded in documents themed around Starlink satellite terminals and a well-known Ukrainian charity. The article is campaign reporting (multiple targets) and does not provide a single named victim incident with bounded impact metrics.
At least one KakaoTalk user
March 16, 2026
•[ malware, account takeover, cyberattack ]
Yonhap/The Korea Times reported a North Korea-linked group used stolen KakaoTalk accounts to distribute malware in recent cyberattacks, highlighting a new propagation tactic. Reporting said the threat actors compromise victims, gain access to KakaoTalk desktop accounts, and then use that trusted messaging channel to push malicious payloads to selected contacts.
CareCloud
March 16, 2026
•[ unauthorized access, service disruption, electronic health record ]
An unauthorized third party temporarily accessed part of CareCloud Health and partially disrupted functionality and data access in one electronic health record environment before service was restored the same evening.
Roan and Eurocamp
March 16, 2026
•[ data breach, phishing, supply chain attack ]
Roan and Eurocamp disclosed that an unauthorized third party exploited a vulnerability in a third-party technology provider on March 16, 2026 and stole guest booking data later used in WhatsApp scam attempts; no encryption was reported.
CareCloud, Inc.
March 16, 2026
•[ unauthorized access, network disruption, electronic health records ]
CareCloud experienced unauthorized access and a temporary network disruption on March 16, 2026 that partially affected functionality and data access to one of its six electronic health record environments for approximately eight hours.
Omi Kenshi Co., Ltd
March 16, 2026
•[ unauthorized access, system failure, operational disruption ]
On March 16, 2026, Omi Kenshi Co., Ltd. experienced unauthorized external access that caused system failure and suspension of core systems, delaying financial closing procedures.
Los Angeles County Metropolitan Transportation Authority
March 16, 2026
•[ unauthorized access, infrastructure disruption, state-sponsored ]
Los Angeles County Metropolitan Transportation Authority detected unauthorized activity on March 16, 2026 and restricted parts of its internal network while reviewing and restoring systems. Rail and bus service continued, but some customer-facing services, including arrival information displays and TAP card reload functions, were disrupted. Ababil of Minab claimed responsibility, and Gambit Security linked the operation to Iranian state-associated infrastructure.
COMPAS (French Ministry of Education)
March 15, 2026
•[ data leak, intrusion, personal information ]
An intrusion into the French Education Ministry's COMPAS system exposed personal information linked to approximately 243,000 trainees and permanent education staff.
Intoxalock
March 14, 2026
•[ cyberattack, denial of service, DDoS ]
DataBreaches summarized local reporting that a cyberattack shut down Intoxalocks nationwide breathalyzer interlock system, preventing affected drivers from starting vehicles because server-side systems were down. Intoxalock stated hackers were flooding its servers to stop them from functioning. The outage affected device-related services such as installations, removals, calibrations, and account access across 46 states. The company stated user data was secure and did not disclose whether a ransom demand was made; no public claim of responsibility was noted at publication.
City of Minot Water Treatment Plant
March 14, 2026
•[ ransomware, critical infrastructure, utilities ]
Minot, North Dakota officials confirmed a ransomware event impacted a server at the citys water treatment plant on March 14, 2026. The city said the water treatment plant and broader water system remained operational and safe, with no interruption to water service reported.
Divine Skins
March 13, 2026
•[ data breach, unauthorised access, data leak ]
In March 2026, the League of Legends custom skins service Divine Skins suffered a data breach. The incident was disclosed via the service's Discord server, where Divine Skins stated that an unauthorised third party accessed part of its systems, deleted all skins from the database and exposed email addresses and usernames. The data also contained a history of purchases made by users.