<cite index="13-4,13-5,2-14">Ransomware gangs claimed over 400 victims in the first three months of 2026, state-sponsored hackers wiped Fortune 500 companies using their own IT tools, and identity exposure reached 65.7 billion distinct records with a 23% increase year-over-year</cite>. <cite index="16-10,5-25">Healthcare infrastructure remains heavily targeted with multiple ransomware incidents while criminal phishing platforms rapidly reestablish operations after law enforcement takedowns</cite>.
Critical 200K devices records Mar 11
Iran-Linked Handala Wipes 200,000 Stryker Medical Devices
Stryker Corporation
Iran-linked group Handala compromised a Microsoft Intune administrator account and used Stryker's device management platform to remotely wipe over 200,000 devices across 79 countries with no malware or ransomware. The attack affected manufacturing and shipments but not patient-related services.
What it means: This demonstrates how legitimate IT management tools can be weaponized for mass destruction when admin accounts lack proper protection.
High 400K users records Mar 03
LexisNexis Breach Exposes 400K Users Including Federal Judges
LexisNexis Legal & Professional
Threat actor FulcrumSec exploited an unpatched React2Shell vulnerability to access AWS environment, leveraging overpermissioned IAM roles to exfiltrate 2.04GB including 3.9 million database records, with 118 exposed accounts belonging to federal judges, DOJ attorneys, and SEC staff.
What it means: Legal industry targeting creates cascading risks for ongoing cases and government operations through credential compromise.
High 1TB+ claimed records Mar 12
UMMC Ransomware Shuts Down 35 Healthcare Clinics
University of Mississippi Medical Center
Medusa ransomware hit UMMC starting February 19, forcing closure of 35 clinics across Mississippi and reverting staff to handwritten charts for nine days, with attackers demanding $800,000 ransom.
What it means: Healthcare ransomware continues disrupting patient care with direct impacts on emergency services and medical record access.
Significant 28K customers records Feb 09
Japan Airlines Luggage System Exposes 28K Customers
Japan Airlines
JAL detected unauthorized access to the Same Day Luggage Delivery Service reservation system exposing names, email addresses, phone numbers, and travel details for reservations since July 2024.
What it means: Travel data exposure enables highly targeted phishing campaigns using legitimate booking details and personal travel patterns.
Significant 900K contacts records Mar 18
Aura Identity Protection Firm Hit by Voice Phishing
Aura (identity protection company)
An attacker impersonated a trusted contact in a voice phishing call to an Aura employee, gaining system access for one hour and accessing 900,000 records including names, email addresses, and phone numbers.
What it means: Identity protection companies becoming breach victims highlights the sophistication of social engineering attacks targeting security-focused organizations.
High 18.1M API keys records Mar 19
Non-Human Identity Theft Surges with 18M API Keys Exposed
Criminal-targeting sources
SpyCloud report reveals exposure of 18.1 million API keys and tokens, plus 6.2 million credentials tied to AI tools, with non-human identities often lacking MFA enforcement and operating with broad permissions.
What it means: Machine identities are becoming prime targets as they provide persistent access to production systems and cloud infrastructure.