March 2026 Data Breaches (So Far)
01 Mar 2026
Top data breaches of March 2026
The rising frequency and impact of data breaches have been a shared worry for organizations globally, with many left with disrupted operations, compromised data, and damaged reputation.
As attackers evolve their techniques using AI to drive more sophisticated attacks and regulators tighten cybersecurity requirements, organizations face increased pressure to maintain a resilient and compliant security posture.
Let’s examine some of the top data breaches of March 2026.
Top data breaches of March 2026
Victim: Seoul National University Hospital
About
Seoul National University Hospital is a Korea-based health care facility that offers outpatient, inpatient, and emergency care services.
Industry
Healthcare
What happened?
On 19th March, a staff member accidentally entered the wrong email address while sending an internal message, leading to the compromise of patient records.
Impact
The employee’s mistake led to an insider attack and compromised 16000 patient records. including patient identification numbers of mothers and newborns, birth, height, and weight, and details of foetuses and newborns (like medical test results and gender).
Source
Victim: AstraZeneca
About
AstraZeneca is a UK-based pharmaceutical company that offers a wide portfolio of products for oncological, cardiovascular, respiratory, and infectious diseases. It was founded in 1999 through a merger of Swedish Astra AB and British Zeneca Group.
Industry
Pharmaceutical
What happened?
AstraZeneca became a victim of a ransomware attack that was carried out by the LAPSUS$ ransomware group.
Impact
The attack compromised 3GB of data, including Source Codes, Cloud infrastructure (AWS/Azure/Terraform configs), and Secrets & Access (private keys and vault credentials).
Source
Victim: Berkadia
About
Berkadia is a New York-based real estate services provider. It is a joint venture of Berkshire Hathaway and Jefferies Financial Group. It offers a range of real estate services to multifamily and commercial clients.
Industry
Real estate
What happened?
Berkadia became a victim of a ransomware attack that was carried out by the ShinyHunters ransomware group.
Impact
The ransomware attack has compromised over 5 million Salesforce records, including PII and other internal corporate data.
Source
Victim: Intoxalock
About
Intoxalock is an Iowa-based technology manufacturer specializing in breathalyzers that are used to deter people from driving while intoxicated.
Industry
Technology
What happened?
Intoxalock discovered that attackers had flooded their servers to disrupt their services and cause nationwide disruption of all the installations, calibrations, removals, and account access.
Impact
The cyberattack caused a nationwide outage of services, impacting thousands of drivers in Maine and 45 other states.
Source
Victim: Sears Home Services
About
Sears Home Services is an Illinois-based services provider known for its home appliances repair, cleaning, home improvement, and maintenance services.
Industry
Home improvement and repair services
What happened?
A security researcher found that Sears Home Services’ AI customer service bot had a vulnerability that exposed customer service records from 2024 to 2026.
Impact
The data compromised includes 3.7 million customer service records from 2024 to 2026. It also consists of 2.1 million text files, 200000 spreadsheet logs, 1.4 million audio records, and 54000 complete chat logs.
Source
Victim: City of Foster
About
The City of Foster, California, offers multiple services to its citizens, from new resident information, recycling and garbage services, to community annual reports.
Industry
Public sector
What happened?
The City of Foster discovered on March 19th that it had experienced a cybersecurity breach.
Impact
The cyber attack had disrupted all the public services except emergency services. The nature and quantity of data compromised are under investigation.
Source
Victim: Lloyds Bank, Halifax, and Bank of Scotland
About
Lloyds Bank is a retail and commercial bank that offers banking and insurance services in parts of England and Wales.
Industry
Banking
What happened?
On 12th March, Lloyds Bank discovered that its customers were able to see transaction details of other customers due to technical vulnerabilities.
Impact
The data breach compromised the transaction-related and other financial details of the bank’s customers.
Source
Victim: Mercedes-Benz Arlington
About
Mercedes-Benz Arlington is known for its wide range of pre-owned and new Mercedes-Benz vehicles. It also offers vehicle maintenance services and certified technicians.
Industry
Automobile
What happened?
Mercedes-Benz Arlington became a victim of a ransomware attack that was orchestrated by the Dragonforce ransomware group.
Impact
The nature and quantity of data compromised is currently under investigation
Source
Victim: Krasnodar Parking System
About
The city administration of Krasnodar has created a system of paid parking to address congestion of vehicles in the city for the easy movement of pedestrians, transportation services, and emergency services.
Industry
Public sector
What happened?
Krasnodar’s Parking System became a target of a Distributed Denial of Service attack.
Impact
The cyber attack disrupted the payment system of its parking services. Government officials have reported that the payment systems will be back online by 16th March.
Source
Victim: Aura
About
Aura is a cybersecurity company known for its identity protection services designed to protect identities, devices, and online accounts.
Industry
Cybersecurity
What happened?
Aura became a target of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.
Impact
The data breach compromised 12GB of files containing over 9,00,000 records comprising the names and email addresses from a marketing tool.
Source
Victim: Intuitive
About
Intuitive Surgical Inc. is a California-based company known for the manufacturing and marketing of robotic products for surgery. It is currently ranked 459 on the Fortune 500 list.
Industry
Medical appliances & equipment
What happened?
Intuitive Surgical reported on 13th March that it became a victim of a cyber attack carried out via phishing and unauthorized access to its internal applications.
Impact
The attack compromised its customers’ data, business data, contact information, corporate data, and employee information.
Source
Victim: Elmwood Pharmacy
About
Elmwood Pharmacy is an Omaha-based pharmacy known for its prescription services, home medical equipment, and personalized customer care.
Industry
Pharmaceuticals
What happened?
Elmwood Pharmacy became a victim of a ransomware attack carried out by LockBit5.
Impact
The nature and quantity of data compromised is currently under investigation.
Source
Victim: Rok hardware
About
Rok Hardware is a California-based hardware manufacturer specializing in screws, end pulls, knobs, and pulls for drawers, beds, and other office accessories.
Industry
Hardware
What happened?
Rok Hardware discovered that its database containing customer records was published on a data breach forum.
Impact
The company compromised 167,593 customer records, containing information including customer IDs, dates of birth, names, addresses, loyalty rewards program data, and payment processing information.
Source
Victim: Telus digital
About
TELUS Digital is a Canada-based company that offers business process outsourcing and technology services. It has clients from industries including e-commerce, banking, travel, healthcare, and automotive.
Industry
IT services
What happened?
On March 11, TELUS Digital confirmed that it became a victim of a cyber attack that was orchestrated by the ShinyHunterz ransomware group.
Impact
The cyberattack compromised 1 petabyte of data belonging to its BPO customers, source codes, FBI background checks, financial information, voice recordings, and Salesforce data for various companies.
Source
Victim: Big Brothers Big Sisters of America
About
Big Brothers Big Sisters of America is a Florida-based non-profit organization that was founded in 1904. It offers youth mentoring services, offering guidance and support through its network of BBBS agencies.
Industry
Non-profit
What happened?
BBBS became a target of a ransomware attack that was carried out by the
Impact
The nature and quantity of data compromised is currently under investigation.
Source
Victim: Stryker
About
Stryker is a Michigan-based company that manufactures technological products. It is known for its surgical equipment, endoscopy systems, and patient & caregiver safety technologies.
Industry
Technology
What happened?
On March 11th, Stryker detected suspicious activity on its systems and devices connected globally. It immediately launched its incident response measures and investigation. The cyber attack was orchestrated by the Iranian hacktivist group Handala.
Impact
The cyber attack caused operational disruption, compromised data from over 200000 servers, mobile devices, and other systems across 79 countries, and caused a loss of 50 TB of critical data.
Source
Victim: Paraguay Institute of Social Security
About
The Paraguay Institute of Social Security was created in 1943 by the government as an institution responsible for managing the social security system in Paraguay.
Industry
Public sector
What happened?
The Paraguay Institute of Social Security became a victim of a ransomware attack that was carried out by the Kairos ransomware group.
Impact
The nature and quantity of data compromised is currently under investigation.
Source
Victim: Paass Logistik
About
Paas Logistik is a German logistics company that offers multiple warehouse logistics and value-added services.
Industry
Logistics
What happened?
Paas Logistik became a victim of a ransomware attack that was carried out by the Akira ransomware group.
Impact
The ransomware attack compromised 26GB of data, including employee IDs, client contract-related details, NDAs, and financials.
Source
Victim: FBI
About
The Federal Bureau of Investigation is America’s principal federal law enforcement agency under the United States Department of Justice. It has over 38000 employees and was formed in 1908.
Industry
Public sector
What happened?
The FBI became a victim of a cyber attack that affected its systems used to manage surveillance and wiretap warrants.
Impact
The nature and quantity of data compromised by the cyber attack are currently under investigation.
Source
Victim: Loblaw
About
Loblaw Companies Ltd. is a Canada-based retailer that was founded in 1919, operating grocery stores, franchises, and supermarkets across 22 regional and market segments like banking, apparel, and pharmacies.
Industry
Retail
What happened?
Loblaw Companies Ltd. detected suspicious activity on its network and immediately activated its incident response measures.
Impact
The data compromised in the attack includes names, phone numbers, and email addresses of customers. The quantity of data compromised is under investigation.
Source
Victim: The Independent Public Regional Hospital
About
The Independent Public Regional Hospital is a Poland-based hospital that offers multiple medical services to the residents of Szczecin.
Industry
Healthcare
What happened?
The Independent Public Regional Hospital became a target of a ransomware attack that disrupted its IT systems, digital operations, and emergency operations.
Impact
The attack disrupted the hospital’s digital operations and compelled the hospital to switch to paper-based workflows. The attackers also encrypted parts of the hospital data and staff’s access to digital records.
Source
Victim: The Albany Engineering Company
About
The Alabany Engineering Company is a manufacturing company that is based in Lydney, known for its industrial, petroleum, fire, and other kinds of pumps tailored specifically to industry.
Industry
Manufacturing
What happened?
The Albany Engineering Company became a victim of a ransomware attack that was orchestrated by the Qilin ransomware group.
Impact
The ransomware group has threatened to publish company-specific data. The exact nature and quantity of data compromised is currently under investigation.
Source
Victim: AFDL
About
Alum, Ferrer, Diaz, & Luaces is a Florida-based legal services provider known for its legal representation and advisory services.
Industry
Legal
What happened?
AFDL became a victim of a ransomware attack that was carried out by the Qilin ransomware group.
Impact
The nature and quantity of data compromised is currently under investigation and not yet disclosed.
Source
Victim: Advanced Rehabilitation Technology
About
Advanced Rehabilitation Technology is an Ohio-based technology solution provider that offers solutions for the repair and rehabilitation of water and wastewater structures.
Industry
Technology
What happened?
Advanced Rehabilitation Technology became a victim of a ransomware attack that was orchestrated by the Dragonforce ransomware group.
Impact
The nature and quantity of data compromised in the data breach are currently under investigation.
Source
Victim: AC Scott Electric
About
AC Scott Electric is a New Jersey-based electric services company that offers a wide range of professional services, including commercial, industrial, and utility-specific electric services.
Industry
Electric services
What happened?
AC Scott Electric became a victim of a ransomware attack that was orchestrated by the DragonForce ransomware group.
Impact
The data breach compromised 22.84 GB of the company’s data, including company credentials and other sensitive data.
Source
Victim: 11th Street Hospital
About
11th Street Veterinary Hospital is a Huntsville-based hospital that offers multiple services for pet care, including testing, diagnostics, dental care, surgery, and advanced care services.
Industry
Veterinery
What happened?
11th Street Veterinary Hospital became a target of a ransomware attack that was orchestrated by the Nightspire ransomware group.
Impact
The quantity of data compromised is still under investigation. The ransomware group has claimed that it has stolen client and operation-specific data.
Source
Victim: Infutor
About
Infutor is a Plainfield-based identity resolution and consumer intelligence data solutions provider for marketers and data companies. It was acquired by Verisk, a data analytics company, in 2022.
Industry
Software
What happened?
Infutor became a victim of a massive data breach in which a hacker posted a database of personal information belonging to Americans.
Impact
The data compromised includes personal data of 676798866 citizens, including their full names, physical address-related details, phone numbers, dates of birth, and Social Security Numbers (SSN).
Source
Victim: Akzo Nobel
About
AkzoNobel is a manufacturing company that is based in the Netherlands. It was founded in 1994 and is known for a wide range of paints and performance coatings globally.
Industry
Chemicals
What happened?
AkzoNobel became a victim of a ransomware attack that was orchestrated by the Anubis ransomware group.
Impact
The ransomware attack compromised 170GB of data comprising 170000 files, including confidential information like agreements with high-profile clients, phone numbers, email addresses, private email correspondence, passport details, internal technical specification sheets, and material testing documents.
Source
Victim: LexisNexis
About
LexisNexis is a New York-based company that offers data analytics and other digital products like case law, media monitoring tools, law practice management tools, and sales intelligence solutions.
Industry
Publishing/Information and analytics
What happened?
LexisNexis became a target of a ransomware attack that was carried out by the FulcrumSec ransomware group by exploiting its vulnerable React container.
Impact
The ransomware attack has compromised LexisNexis’s 2GB of data, including 536 Redshift tables, 53 AWS Secret Manager secrets in plaintext, 430+ VPC database tables, 3.9 million database records, 21042 customer accounts, 45 employee password hashes, VPC infrastructure mapping, and 5582 attorney survey responses.
Source
Victim: USHA International
About
USHA International is an Indian appliance and consumer durables manufacturing company that was founded in 1934. It is known for its appliances like sewing machines, fans, water coolers, and heaters.
Industry
Appliances
What happened?
USHA International became the target of a ransomware attack that was orchestrated by
Impact
The data breach has compromised the company’s data including employee data, CMR, CMS, and SAP databases.
Source
Victim: Lacoste
About
Lacoste SA is a France based apparel company that specializes in sportswear, leather goods, watches, footwear, and sunglasses.
Industry
Apparel
What happened?
Lacoste became a target of a ransomware attack that was orchestrated by the Lapsus$ ransomware group.
Impact
The nature and quantity of data compromised in the data breach are under investigation.
Source
Victim: Malaysia Airlines
About
Malaysia Airlines is one of Malaysia’s biggest carriers that operates across multiple locations in Europe, Oceania, and Asia. Its primary hub is Kuala Lumpur International Airport, and it serves more than 16 million passengers every year.
Industry
Aviation
What happened?
Malaysia Airlines became a target of a ransomware attack orchestrated by the Quilin ransomware group.
Impact
The data compromised in the data breach includes passenger booking, contact records, personnel files of employees, vendor contracts, operational documents, and internal communications.
Source
To be continued
Last month, we saw how even some of the most reputable global companies fell victim to a cyber attack. Keep checking this space as we update our list of March’s top data breaches with a closer look at the top data breaches, how they happened, and their impact.
Note: Our list only highlights the breaches that have either occurred in 2026 or reported/disclosed in 2026. All breaches reported in previous years, as of 2026, will be excluded from the list.