Ameriprise
March 2, 2026
•[ extortion, data leak, ShinyHunters ]
In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general, Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures".
Denmark School District
March 1, 2026
•[ ransomware, cyber incident, connectivity outage ]
Reporting stated the Denmark School District in Denmark, Wisconsin, lost internet access for five school days due to a cyber incident, forcing paper-based workarounds. DataBreaches noted a ransomware tracking site listed the district domain as a claimed victim by INC Ransom with a discovery date of March 1, 2026, but emphasized that listing alone is not confirmation of ransomware or data theft. The confirmed primary effect described is a weeklong connectivity outage impacting school operations.
Department of Homeland Security (DHS)
March 1, 2026
•[ hacktivism, data leak, government contracts ]
DataBreaches summarized reporting that hacktivists calling themselves Department of Peace claimed to have hacked DHS and leaked allegedly stolen documents. The transparency collective DDoSecrets published data described as relating to contracts between DHS, ICE, and more than 6,000 companies (including major defense contractors and large technology firms). The report attributes the source to DHSs Office of Industry Partnership procurement unit; DHS confirmation and the exact intrusion method were not provided in the DataBreaches excerpt.
Undisclosed Qatari organization
March 1, 2026
•[ DLL hijacking, PlugX, backdoor malware ]
HackRead summarized Check Point Research describing a China-linked campaign beginning March 1, 2026 that used conflict-themed lures and DLL hijacking to install PlugX backdoor malware against targets in Qatar. The report described lures disguised as war news and a separate energy-sector lure delivering a Rust loader and ultimately Cobalt Strike, with the goal of espionage against Qatars military and oil/gas interests.
Bitrefill
March 1, 2026
•[ cyberattack, data breach, cryptocurrency theft ]
Bitrefill disclosed that a March 1, 2026 cyberattack originating from a compromised employee laptop enabled attackers to obtain legacy credentials, access a snapshot containing production secrets, and escalate into parts of Bitrefills infrastructure. The attackers accessed parts of the database and some cryptocurrency wallets, leading to theft of funds and misuse of gift card inventory/supply flows. Bitrefill reported exposure of about 18,500 purchase records containing customer email addresses, IP addresses, and cryptocurrency payment addresses; for about 1,000 purchases, customer names were also potentially exposed (stored encrypted, but the attackers may have obtained decryption keys). Bitrefill said it shut down systems to isolate the incident, worked with security experts/on-chain analysts/law enforcement, and assessed the method as consistent with Lazarus/BlueNoroff activity.
Bitrefill
March 1, 2026
•[ data breach, cryptocurrency theft, PII leak ]
Bitrefill published a post-mortem stating it was attacked on March 1, 2026 and attributed the activity to North Koreas Lazarus Group. The breach was discovered after suspicious purchasing patterns suggested gift card stock and supplier supply lines were being exploited. Bitrefill said attackers accessed about 18,500 purchase records containing customer email addresses, crypto payment addresses, and metadata including IP addresses. The attackers also drained some Bitrefill cryptocurrency wallets and transferred funds to attacker-controlled wallets; the company did not disclose the amount stolen and said it would absorb the losses.
Undisclosed Russian company
March 1, 2026
•[ ransomware, cyber warfare, pro-Ukrainian group ]
A pro-Ukrainian group known as Bearlyfy used GenieLocker ransomware against an undisclosed Russian company as part of a broader campaign targeting Russian firms.
Undisclosed Israeli individual smartphone
March 1, 2026
•[ malware, phishing, spyware ]
A trojanized fake Red Alert app delivered through spoofed SMS messages targeted Israeli users and, when installed, enabled theft of messages, contacts, location data, and other device information from affected smartphones.
At least one Hungarian government ministries
March 1, 2026
•[ credential leak, infostealer, stealer logs ]
Bellingcat identified 795 Hungarian government email/password combinations circulating in breach data across 12 of 13 ministries, including defence, foreign affairs, interior, and finance; stealer logs indicated 97 machines across government departments may have been compromised, with some logs as recent as March 2026.
170 Ukrainian prosecutors and investigators
March 1, 2026
•[ espionage, email compromise, state-sponsored ]
Russia-linked hackers compromised Ukrainian prosecutors and investigators email accounts as part of a broader email-espionage campaign involving at least 284 inboxes.
At least one critical infrastructure provider
March 1, 2026
•[ advanced persistent threat, critical infrastructure, programmable logic controllers ]
Iran-affiliated advanced persistent threat actors accessed internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers at one or more U.S. critical infrastructure providers, manipulated project files and HMI/SCADA displays, resulting in operational disruption and financial loss.
RXNT
March 1, 2026
•[ data breach, healthcare, PII ]
RXNT, the SaaS provider for the Office of the Attending Physician, experienced a breach on March132026 where attackers accessed the platform and copied patient prescription records, including names, addresses, dates of birth, and medication details.
At least one Ukrainian government organization
March 1, 2026
•[ spear-phishing, malware, cyber espionage ]
Ghostwriter, also tracked as FrostyNeighbor, UNC1151, UAC-0057, TA445, PUSHCHA, Storm-0257, and related names, conducted a March 2026 spear-phishing campaign against Ukrainian government organizations. The campaign used malicious PDF lures impersonating Ukrtelecom, geofenced delivery to Ukrainian IP addresses, JavaScript PicassoLoader, host fingerprinting, and selective delivery of Cobalt Strike Beacon. Although no specific Ukrainian government agency was publicly named, reporting described successful compromise activity against Ukrainian government targets; no stolen data volume was reported.
Hutt City Council
March 1, 2026
•[ phishing, unauthorized access, email compromise ]
Hutt City Council experienced a malicious phishing attack in March 2026 that resulted in unauthorized access to a number of email accounts. The council determined that five individuals had identity information compromised and 732 people may have had financial information exposed through email correspondence.
Adelante Soluciones Financieras
March 1, 2026
•[ data leak, unauthorized access, PII ]
Addi identified unauthorized activity on its platform in March 2026 and advised customers that personal information may have been compromised. ShinyHunters later claimed responsibility and published a large trove of personal data allegedly obtained from Addi. DataBreach indexed 67,979,172 rows tied to the breach, while HIBP reported approximately 34 million exposed email addresses and credit-related data points. Public sources did not confirm encryption, data destruction, operational disruption, or a precise intrusion vector.
BadeSaba
February 28, 2026
•[ hacking, hacktivism, propaganda ]
BadeSaba, a religious calendar app with more than 5 million downloads, was hacked to display anti-regime messages to users. The compromised app showed propaganda urging armed forces to surrender and join the people.
IRNA
February 28, 2026
•[ hacktivism, website defacement, political messaging ]
IRNA was hacked to display political messages during the same campaign that affected BadeSaba. Reporting says multiple Iranian news websites were compromised, and this row captures IRNA as one named victim.
Murata Manufacturing Co., Ltd.
February 28, 2026
•[ unauthorized access, data leak, IT environment breach ]
Murata Manufacturing confirmed unauthorized third-party access to its IT environment and improper access to data, with later updates identifying possible leakage of employee, associated-person, customer, supplier, stakeholder, and business partner information.
Roskomnadzor
February 27, 2026
•[ DDoS attack, multi-vector attack, traffic scrubbing ]
A multi-vector DDoS attack targeted Roskomnadzor online resources. Traffic peaked at 33 Gbps and 36.9 million packets per second before malicious traffic was redirected to scrubbing servers and access was restored.
Ministry of Defence of the Russian Federation
February 27, 2026
•[ DDoS attack, multi-vector attack, cyber attack ]
A multi-vector DDoS attack targeted online resources associated with the Russian Ministry of Defense. Traffic peaked at 33 Gbps and 36.9 million packets per second before mitigation restored access.