March 2026 Data Breaches (So Far)

01 Mar 2026

Top data breaches of March 2026

The rising frequency and impact of data breaches have been a shared worry for organizations globally, with many left with disrupted operations, compromised data, and damaged reputation.

 

As attackers evolve their techniques using AI to drive more sophisticated attacks and regulators tighten cybersecurity requirements, organizations face increased pressure to maintain a resilient and compliant security posture.

 

Let’s examine some of the top data breaches of March 2026.

Top data breaches of March 2026

Victim: Seoul National University Hospital

About

Seoul National University Hospital is a Korea-based health care facility that offers outpatient, inpatient, and emergency care services.

 

Industry

Healthcare

 

What happened?

On 19th March, a staff member accidentally entered the wrong email address while sending an internal message, leading to the compromise of patient records.

 

Impact

The employee’s mistake led to an insider attack and compromised 16000 patient records. including patient identification numbers of mothers and newborns, birth, height, and weight, and details of foetuses and newborns (like medical test results and gender).

Source

Victim: AstraZeneca

About

AstraZeneca is a UK-based pharmaceutical company that offers a wide portfolio of products for oncological, cardiovascular, respiratory, and infectious diseases. It was founded in 1999 through a merger of Swedish Astra AB and British Zeneca Group.

 

Industry

Pharmaceutical

 

What happened?

AstraZeneca became a victim of a ransomware attack that was carried out by the LAPSUS$ ransomware group.

 

Impact

The attack compromised 3GB of data, including Source Codes, Cloud infrastructure (AWS/Azure/Terraform configs), and Secrets & Access (private keys and vault credentials).

Source

Victim: Berkadia

About

Berkadia is a New York-based real estate services provider. It is a joint venture of Berkshire Hathaway and Jefferies Financial Group. It offers a range of real estate services to multifamily and commercial clients.

 

Industry

Real estate

 

What happened?

Berkadia became a victim of a ransomware attack that was carried out by the ShinyHunters ransomware group.

 

Impact

The ransomware attack has compromised over 5 million Salesforce records, including PII and other internal corporate data.

Source

Victim: Intoxalock

About

Intoxalock is an Iowa-based technology manufacturer specializing in breathalyzers that are used to deter people from driving while intoxicated.

 

Industry

Technology

 

What happened?

Intoxalock discovered that attackers had flooded their servers to disrupt their services and cause nationwide disruption of all the installations, calibrations, removals, and account access.

 

Impact

The cyberattack caused a nationwide outage of services, impacting thousands of drivers in Maine and 45 other states.

Source

Victim: Sears Home Services

About

Sears Home Services is an Illinois-based services provider known for its home appliances repair, cleaning, home improvement, and maintenance services.

 

Industry

Home improvement and repair services

 

What happened?

A security researcher found that Sears Home Services’ AI customer service bot had a vulnerability that exposed customer service records from 2024 to 2026.

 

Impact

The data compromised includes 3.7 million customer service records from 2024 to 2026. It also consists of 2.1 million text files, 200000 spreadsheet logs, 1.4 million audio records, and 54000 complete chat logs.

Source

Victim: City of Foster

About

The City of Foster, California, offers multiple services to its citizens, from new resident information, recycling and garbage services, to community annual reports.

 

Industry

Public sector

 

What happened?

The City of Foster discovered on March 19th that it had experienced a cybersecurity breach.

 

Impact

The cyber attack had disrupted all the public services except emergency services. The nature and quantity of data compromised are under investigation.

Source

Victim: Lloyds Bank, Halifax, and Bank of Scotland

About

Lloyds Bank is a retail and commercial bank that offers banking and insurance services in parts of England and Wales.

 

Industry

Banking

 

What happened?

On 12th March, Lloyds Bank discovered that its customers were able to see transaction details of other customers due to technical vulnerabilities.

 

Impact

The data breach compromised the transaction-related and other financial details of the bank’s customers.

Source

Victim: Mercedes-Benz Arlington

About

Mercedes-Benz Arlington is known for its wide range of pre-owned and new Mercedes-Benz vehicles. It also offers vehicle maintenance services and certified technicians.

 

Industry

Automobile

 

What happened?

Mercedes-Benz Arlington became a victim of a ransomware attack that was orchestrated by the Dragonforce ransomware group.

 

Impact

The nature and quantity of data compromised is currently under investigation

Source

Victim: Krasnodar Parking System

About

The city administration of Krasnodar has created a system of paid parking to address congestion of vehicles in the city for the easy movement of pedestrians, transportation services, and emergency services.

 

Industry

Public sector

 

What happened?

Krasnodar’s Parking System became a target of a Distributed Denial of Service attack.

 

Impact

The cyber attack disrupted the payment system of its parking services. Government officials have reported that the payment systems will be back online by 16th March.

Source

Victim: Aura

About

Aura is a cybersecurity company known for its identity protection services designed to protect identities, devices, and online accounts.

 

Industry

Cybersecurity

 

What happened?

Aura became a target of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.

 

Impact

The data breach compromised 12GB of files containing over 9,00,000 records comprising the names and email addresses from a marketing tool.

Source

Victim: Intuitive

About

Intuitive Surgical Inc. is a California-based company known for the manufacturing and marketing of robotic products for surgery. It is currently ranked 459 on the Fortune 500 list.

 

Industry

Medical appliances & equipment

 

What happened?

Intuitive Surgical reported on 13th March that it became a victim of a cyber attack carried out via phishing and unauthorized access to its internal applications.

 

Impact

The attack compromised its customers’ data, business data, contact information, corporate data, and employee information.

Source

Victim: Elmwood Pharmacy

About

Elmwood Pharmacy is an Omaha-based pharmacy known for its prescription services, home medical equipment, and personalized customer care.

 

Industry

Pharmaceuticals

 

What happened?

Elmwood Pharmacy became a victim of a ransomware attack carried out by LockBit5.

 

Impact

The nature and quantity of data compromised is currently under investigation.

Source

Victim: Rok hardware

About

Rok Hardware is a California-based hardware manufacturer specializing in screws, end pulls, knobs, and pulls for drawers, beds, and other office accessories.

 

Industry

Hardware

 

What happened?

Rok Hardware discovered that its database containing customer records was published on a data breach forum.

 

Impact

The company compromised 167,593 customer records, containing information including customer IDs, dates of birth, names, addresses, loyalty rewards program data, and payment processing information.

Source

Victim: Telus digital

About

TELUS Digital is a Canada-based company that offers business process outsourcing and technology services. It has clients from industries including e-commerce, banking, travel, healthcare, and automotive.

 

Industry

IT services

 

What happened?

On March 11, TELUS Digital confirmed that it became a victim of a cyber attack that was orchestrated by the ShinyHunterz ransomware group.

 

Impact

The cyberattack compromised 1 petabyte of data belonging to its BPO customers, source codes, FBI background checks, financial information, voice recordings, and Salesforce data for various companies.

Source

Victim: Big Brothers Big Sisters of America

About

Big Brothers Big Sisters of America is a Florida-based non-profit organization that was founded in 1904. It offers youth mentoring services, offering guidance and support through its network of BBBS agencies.

 

Industry

Non-profit

 

What happened?

BBBS became a target of a ransomware attack that was carried out by the

 

Impact

The nature and quantity of data compromised is currently under investigation.

Source

Victim: Stryker

About

Stryker is a Michigan-based company that manufactures technological products. It is known for its surgical equipment, endoscopy systems, and patient & caregiver safety technologies.

 

Industry

Technology

 

What happened?

On March 11th, Stryker detected suspicious activity on its systems and devices connected globally. It immediately launched its incident response measures and investigation. The cyber attack was orchestrated by the Iranian hacktivist group Handala.

 

Impact

The cyber attack caused operational disruption, compromised data from over 200000 servers, mobile devices, and other systems across 79 countries, and caused a loss of 50 TB of critical data.

Source

Victim: Paraguay Institute of Social Security

About

The Paraguay Institute of Social Security was created in 1943 by the government as an institution responsible for managing the social security system in Paraguay.

 

Industry

Public sector

 

What happened?

The Paraguay Institute of Social Security became a victim of a ransomware attack that was carried out by the Kairos ransomware group.

 

Impact

The nature and quantity of data compromised is currently under investigation.

Source

Victim: Paass Logistik

About

Paas Logistik is a German logistics company that offers multiple warehouse logistics and value-added services.

 

Industry

Logistics

 

What happened?

Paas Logistik became a victim of a ransomware attack that was carried out by the Akira ransomware group.

 

Impact

The ransomware attack compromised 26GB of data, including employee IDs, client contract-related details, NDAs, and financials.

Source

Victim: FBI

About

The Federal Bureau of Investigation is America’s principal federal law enforcement agency under the United States Department of Justice. It has over 38000 employees and was formed in 1908.

 

Industry

Public sector

 

What happened?

The FBI became a victim of a cyber attack that affected its systems used to manage surveillance and wiretap warrants.

 

Impact

The nature and quantity of data compromised by the cyber attack are currently under investigation.

Source

Victim: Loblaw

About

Loblaw Companies Ltd. is a Canada-based retailer that was founded in 1919, operating grocery stores, franchises, and supermarkets across 22 regional and market segments like banking, apparel, and pharmacies.

 

Industry

Retail

 

What happened?

Loblaw Companies Ltd. detected suspicious activity on its network and immediately activated its incident response measures.

 

Impact

The data compromised in the attack includes names, phone numbers, and email addresses of customers. The quantity of data compromised is under investigation.

Source

Victim: The Independent Public Regional Hospital

About

The Independent Public Regional Hospital is a Poland-based hospital that offers multiple medical services to the residents of Szczecin.

 

Industry

Healthcare

 

What happened?

The Independent Public Regional Hospital became a target of a ransomware attack that disrupted its IT systems, digital operations, and emergency operations.

 

Impact

The attack disrupted the hospital’s digital operations and compelled the hospital to switch to paper-based workflows. The attackers also encrypted parts of the hospital data and staff’s access to digital records.

Source

Victim: The Albany Engineering Company

About

The Alabany Engineering Company is a manufacturing company that is based in Lydney, known for its industrial, petroleum, fire, and other kinds of pumps tailored specifically to industry.

 

Industry

Manufacturing

 

What happened?

The Albany Engineering Company became a victim of a ransomware attack that was orchestrated by the Qilin ransomware group.

 

Impact

The ransomware group has threatened to publish company-specific data. The exact nature and quantity of data compromised is currently under investigation.

Source

Victim: AFDL

About

Alum, Ferrer, Diaz, & Luaces is a Florida-based legal services provider known for its legal representation and advisory services.

 

Industry

Legal

 

What happened?

AFDL became a victim of a ransomware attack that was carried out by the Qilin ransomware group.

 

Impact

The nature and quantity of data compromised is currently under investigation and not yet disclosed.

Source

Victim: Advanced Rehabilitation Technology

About

Advanced Rehabilitation Technology is an Ohio-based technology solution provider that offers solutions for the repair and rehabilitation of water and wastewater structures.

 

Industry

Technology

 

What happened?

Advanced Rehabilitation Technology became a victim of a ransomware attack that was orchestrated by the Dragonforce ransomware group.

 

Impact

The nature and quantity of data compromised in the data breach are currently under investigation.

Source

Victim: AC Scott Electric

About

AC Scott Electric is a New Jersey-based electric services company that offers a wide range of professional services, including commercial, industrial, and utility-specific electric services.

 

Industry

Electric services

 

What happened?

AC Scott Electric became a victim of a ransomware attack that was orchestrated by the DragonForce ransomware group.

 

Impact

The data breach compromised 22.84 GB of the company’s data, including company credentials and other sensitive data.

Source

Victim: 11th Street Hospital

About

11th Street Veterinary Hospital is a Huntsville-based hospital that offers multiple services for pet care, including testing, diagnostics, dental care, surgery, and advanced care services.

 

Industry

Veterinery

 

What happened?

11th Street Veterinary Hospital became a target of a ransomware attack that was orchestrated by the Nightspire ransomware group.

 

Impact

The quantity of data compromised is still under investigation. The ransomware group has claimed that it has stolen client and operation-specific data.

Source

Victim: Infutor

About

Infutor is a Plainfield-based identity resolution and consumer intelligence data solutions provider for marketers and data companies. It was acquired by Verisk, a data analytics company, in 2022.

 

Industry

Software

 

What happened?

Infutor became a victim of a massive data breach in which a hacker posted a database of personal information belonging to Americans.

 

Impact

The data compromised includes personal data of 676798866 citizens, including their full names, physical address-related details, phone numbers, dates of birth, and Social Security Numbers (SSN).

Source

Victim: Akzo Nobel

About

AkzoNobel is a manufacturing company that is based in the Netherlands. It was founded in 1994 and is known for a wide range of paints and performance coatings globally.

 

Industry

Chemicals

 

What happened?

AkzoNobel became a victim of a ransomware attack that was orchestrated by the Anubis ransomware group.

 

Impact

The ransomware attack compromised 170GB of data comprising 170000 files, including confidential information like agreements with high-profile clients, phone numbers, email addresses, private email correspondence, passport details, internal technical specification sheets, and material testing documents.

Source

Victim: LexisNexis

About

LexisNexis is a New York-based company that offers data analytics and other digital products like case law, media monitoring tools, law practice management tools, and sales intelligence solutions.

 

Industry

Publishing/Information and analytics

 

What happened?

LexisNexis became a target of a ransomware attack that was carried out by the FulcrumSec ransomware group by exploiting its vulnerable React container.

 

Impact

The ransomware attack has compromised LexisNexis’s 2GB of data, including 536 Redshift tables, 53 AWS Secret Manager secrets in plaintext, 430+ VPC database tables, 3.9 million database records, 21042 customer accounts, 45 employee password hashes, VPC infrastructure mapping, and 5582 attorney survey responses.

Source

Victim: USHA International

About

USHA International is an Indian appliance and consumer durables manufacturing company that was founded in 1934. It is known for its appliances like sewing machines, fans, water coolers, and heaters.

 

Industry

Appliances

 

What happened?

USHA International became the target of a ransomware attack that was orchestrated by

 

Impact

The data breach has compromised the company’s data including employee data, CMR, CMS, and SAP databases.

Source

Victim: Lacoste

About

Lacoste SA is a France based apparel company that specializes in sportswear, leather goods, watches, footwear, and sunglasses.

 

Industry

Apparel

 

What happened?

Lacoste became a target of a ransomware attack that was orchestrated by the Lapsus$ ransomware group.

 

Impact

The nature and quantity of data compromised in the data breach are under investigation.

Source

Victim: Malaysia Airlines

About

Malaysia Airlines is one of Malaysia’s biggest carriers that operates across multiple locations in Europe, Oceania, and Asia. Its primary hub is Kuala Lumpur International Airport, and it serves more than 16 million passengers every year.

 

Industry

Aviation

 

What happened?

Malaysia Airlines became a target of a ransomware attack orchestrated by the Quilin ransomware group.

 

Impact

The data compromised in the data breach includes passenger booking, contact records, personnel files of employees, vendor contracts, operational documents, and internal communications.

Source

To be continued

Last month, we saw how even some of the most reputable global companies fell victim to a cyber attack. Keep checking this space as we update our list of March’s top data breaches with a closer look at the top data breaches, how they happened, and their impact.

 

Note: Our list only highlights the breaches that have either occurred in 2026 or reported/disclosed in 2026. All breaches reported in previous years, as of 2026, will be excluded from the list.

List of Data Breach April 2026

Here are some of the biggest data breaches of April 2026. Let us understand their impact through insights like how much data is compromised, the entities affected, regulatory fines, and ransom paid.

READ MORE