Undisclosed U.S. aerospace and defense firm
March 6, 2026
•[ backdoor, data exfiltration, nation-state actor ]
SecurityWeek summarized Broadcom Symantec/Carbon Black reporting that Iran-linked MuddyWater (also known as Seedworm/Mango Sandstorm and linked to Irans MOIS) had established presence in multiple organizations networks, including a US airport, a US bank, an NGO operating in the US and Canada, an aerospace and defense contractor, and a software company with a presence in Israel. The report said MuddyWater deployed a new backdoor called Dindoor in several environments and a Python backdoor called Fakeset in others, and attempted to exfiltrate data from the software companys Israeli branch.
Undisclosed telecom company in South America
March 6, 2026
•[ cyberespionage, threat cluster, malware ]
Cisco Talos reported a China-linked threat cluster tracked as UAT-9244 has targeted telecommunications infrastructure in South America since 2024, using multiple implants across Windows, Linux, and edge devices. The toolset described includes TernDoor (Windows), PeerTime (Linux), and BruteEntry (edge devices used for mass scanning and brute forcing services like SSH, Postgres, and Tomcat). The report describes tradecraft and malware but does not identify a single named victim organization or a bounded primary-effect incident suitable for a discrete event record.
Orthopaedic Institute of Western Kentucky
March 6, 2026
•[ data breach, third-party vendor, medical records ]
Orthopaedic Institute of Western Kentucky disclosed a patient data breach tied to two separate security incidents at its third-party vendor Keystone Technologies. Reporting stated one incident occurred in April 2025 and another occurred between July and August 1, 2025, and that in both cases unauthorized parties accessed files containing patient information. The disclosure indicated the potentially exposed data could include medical records, Social Security numbers, and addresses. No threat actor attribution, precise access method, or affected-patient count was provided in the brief report.
CFGI
March 6, 2026
•[ ransomware, leak, finance ]
In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign. The group subsequently publicised data allegedly obtained from CFGI comprising corporate contact information, including 243k unique email addresses, names, phone numbers and physical addresses.
Wikimedia Foundation
March 5, 2026
•[ JavaScript worm, script injection, vandalism ]
A self-propagating JavaScript worm modified user scripts and vandalized Meta-Wiki pages, triggering automated edits that injected hidden scripts and disruptive content. Wikimedia engineers temporarily restricted editing across projects during investigation and cleanup, then reverted malicious changes and restored editing. Reporting indicated nearly 4,000 pages were modified and about 85 users had their common.js files replaced during the incident.
Soreco
March 5, 2026
•[ ransomware, data theft, extortion ]
Swiss business software provider Soreco confirmed it was hit by a ransomware attack. The Bravox group claimed responsibility on its leak site and asserted it stole roughly 118.2 GB of Soreco data while attempting to extort the company. Soreco told media that operational impact was minimal and that it did not intend to pay the ransom. Public reporting did not specify the intrusion vector, affected systems, or whether any data was published at the time of reporting.
Woflow
March 5, 2026
•[ supply-chain risk, extortion, data leak ]
ShinyHunters claimed it compromised Woflow, an AI-driven merchant data platform, in what was described as a supply-chain risk for major clients. The group threatened to leak data by March 6, 2026 if demands were not met, and claimed it stole internal corporate information, personally identifiable information, and transaction/order details. Reporting noted the group did not provide a verifiable public data sample and Woflow did not provide a public response at the time, so the incident remains an alleged breach based on the extortion claim.
Uyghur Post
March 5, 2026
•[ DDoS attack, availability, website offline ]
Uyghur Post was hit by a sustained DDoS attack that knocked the website offline and prevented publication.
Station Casinos LLC
March 5, 2026
•[ unauthorized access, personal information, PII ]
Station Casinos LLC identified unauthorized external access to its systems on March 5, 2026 and began notifying affected individuals in May 2026. Public filings confirmed names were exposed and warned that additional personal information may have been compromised, but the company had not publicly confirmed the total number of affected individuals.
SUCCESS
March 4, 2026
•[ data breach, personal information, password hashes ]
In March 2026, the personal development and achievement media brand SUCCESS suffered a data breach. The incident exposed 250k unique email addresses along with names, IP addresses, phone numbers and, for a limited number of staff members, bcrypt password hashes. The data also included orders containing physical addresses and the payment method used. In SUCCESS' disclosure notice, they advised their system had also been abused to send offensive newsletters with quotes falsely attributed to contributors.
Passaic County
March 4, 2026
•[ malware, cyberattack, availability disruption ]
Passaic County, New Jersey reported a malware attack that disrupted county IT systems and took down phone lines used across government offices. The county first announced the phone outage the morning of March 4 and later confirmed the same day that the outage was caused by a cyberattack. Officials said they were working with federal and state partners to investigate and contain the issue and would provide updates once resolved. No data theft, ransomware demand, or impacted record counts were disclosed in the public statement; the confirmed primary effect is availability disruption affecting communications and IT services.
Lehigh Carbon Community College
March 4, 2026
•[ data breach, IT disruption, campus closure ]
Reporting stated that Lehigh Carbon Community College in Pennsylvania suffered a data breach that forced the college to close all campuses for more than a week in early March 2026. After reopening, IT disruptions reportedly persisted (including lack of Wi-Fi and phone service), indicating ongoing recovery and restoration of core services. A trustee publicly attributed the closures to a data breach, but the college did not disclose a threat actor, entry vector, or specific data types in the public reporting cited.
Woflow
March 4, 2026
•[ data breach, extortion, PII ]
In March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group. The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of email addresses, names, phone numbers and physical addresses, with the data indicating it related to Woflow customers and, in turn, the customers of merchants using their platform.
Tehran traffic cameras
March 3, 2026
•[ hacking, surveillance, espionage ]
DataBreaches summarized reporting alleging Israeli intelligence hacked or accessed a very large portion of Tehrans traffic camera network over multiple years to track senior Iranian officials, including Ayatollah Ali Khamenei. The reporting claimed real-time camera data (including cameras around Khameneis compound) was encrypted and transmitted to servers in Israel and used to build pattern of life intelligence, such as where security teams parked vehicles.
AkzoNobel
March 3, 2026
•[ ransomware, data leak, internal correspondence ]
AkzoNobel confirmed a security incident at one of its U.S. sites after the Anubis ransomware group published a partial leak. AkzoNobel stated the incident was contained and limited to the affected site. The leak samples described in reporting included confidential client agreements, internal email correspondence, technical specification sheets, material testing documents, and contact data such as email addresses and phone numbers, as well as passport scans.
Ten official Syrian government accounts on the social media platform X
March 3, 2026
•[ social media compromise, account takeover, coordinated intrusion ]
Weekly Blitz reported Syrias Ministry of Communications and Information Technology confirmed that at least ten official Syrian government accounts on X were briefly compromised in a coordinated intrusion. The article lists affected accounts including the General Secretariat of the Presidency, the Syrian Central Bank, and multiple ministries (Transport, Higher Education, Education, Youth and Sports), as well as the elections committee account. The primary impact described is unauthorized takeover of social media accounts (posting capability), not a broader breach of internal government IT systems or confirmed data theft.
Blanchard Training and Development, Inc.
March 3, 2026
•[ unauthorized access, PII, financial information ]
Blanchard Training and Development, Inc. identified unusual activity in its network environment on March 4, 2026, and later determined that an unauthorized individual may have copied certain information between March 3 and March 4. DataBreach indexed 494,404 rows tied to Blanchard, including names, contact information, addresses, and bank account information.
Iranian energy and aviation infrastructure
March 2, 2026
•[ DDoS, wipers, intrusions ]
This SecurityWeek link is an overview/analysis of cyber activity during escalating USIsraelIran conflict, describing multiple incidents (e.g., DDoS, wipers, claims of intrusions) by different actors across different targets. It does not describe one discrete cyberattack against a single clearly identified victim with a bounded timeline and measurable primary effects suitable for a single incident record.
Geo News
March 2, 2026
•[ cyberattack, broadcast hijacking, satellite hacking ]
Pakistan Observer reported Geo News said it suffered a sustained and sophisticated cyberattack over the prior 24 hours in which its transmission via Pakistans PakSat satellite was hacked. The channel said attackers breached the broadcast feed, caused repeated interruptions, and hijacked the screen to air unauthorized messages. Geo News stated it had no connection to the malicious content and was working to restore secure operations. The report focuses on disruption of broadcast integrity/availability rather than data theft.
Fusion Superplex
March 2, 2026
•[ ransomware, server infrastructure, internal operations ]
Fusion Superplex said a ransomware attack temporarily affected server infrastructure, internal operations, its IMAX system, and online ticketing.