Security spends fortunes defending against sophisticated adversaries. In March 2025, the United States leaked its own war plans because someone added the wrong contact to a group chat. On March 24, The Atlantic's editor-in-chief Jeffrey Goldberg revealed that he had been inadvertently added — on March 13, by an account belonging to National Security Adviser Michael Waltz — to a Signal group called "Houthi PC small group." Its roughly 18 members included the Vice President, the Defense Secretary, the Secretary of State, the CIA Director, and the Director of National Intelligence. And on March 15, about two hours before US strikes on Houthi targets in Yemen began, the Defense Secretary posted operational sequencing to the chat — including launch times for F/A-18 strike aircraft.
The National Security Council confirmed the thread appeared authentic; the White House insisted no classified information had been shared. On March 26, The Atlantic published the messages nearly in full, withholding only a CIA officer's name, reasoning that if the administration was adamant nothing was classified, there was no basis for restraint. The next day a federal judge ordered the government to preserve the messages, some of which had been set to auto-delete — turning a consumer-app convenience feature into a federal-records problem.
"Signalgate" was, in the purest sense, a human-factors breach. Signal's encryption worked perfectly; the failure was operational discipline — using a consumer messaging app for war planning, and the oldest mistake in the address book: adding the wrong person. No firewall defends against a fat finger. For every security team that had spent the year hardening against nation-states, March was a reminder that the likeliest source of the next catastrophic leak is sitting in the group chat, one autocomplete away.
23andMe's bankruptcy and 15 million customers
On March 23, 23andMe filed for Chapter 11 bankruptcy and co-founder Anne Wojcicki resigned as CEO — turning the genetic data of roughly 15 million customers into a potential sale asset and raising the question no privacy policy had answered: what happens to your DNA when the company holding it goes broke? California's Attorney General had issued an urgent delete-your-data alert on March 21, two days before the filing, with other state AGs following. The company's decline traced partly to its 2023 breach of about 6.9 million people. It was a landmark case in the most permanent kind of personal data — the kind you can't reset — becoming a line item in a bankruptcy estate.
Oracle's double denial
Around March 20–21, a threat actor called "rose87168" offered for sale roughly 6 million records — encrypted SSO passwords, key files, LDAP data — claimed to be from Oracle Cloud login servers and allegedly affecting more than 140,000 tenants, per security firm CloudSEK. Oracle publicly and flatly denied any breach of Oracle Cloud. Then came the awkward part: reporting indicated Oracle had privately told customers that its legacy "Gen 1" Oracle Cloud Classic servers had been compromised — a public denial and a private admission, running side by side. Separately, Oracle Health quietly notified US hospitals that patient data had been stolen from legacy migration servers. Two Oracle breaches, two uncomfortable silences. (The record counts above are the seller's claims, never confirmed by Oracle; the legacy-server compromise came from Oracle's own customer notifications.)
Tata Technologies on the leak site
In the first week of March, the Hunters International ransomware group listed Pune-headquartered Tata Technologies on its dark-web leak site, claiming theft of 1.4 TB of data across roughly 730,000 files. The underlying ransomware attack had been disclosed by the company in a January 31 stock-exchange filing — where it said a few IT assets were temporarily suspended while client delivery continued unaffected. The gang threatened to publish within about a week; Tata Technologies did not confirm the alleged theft, and by mid-March reports said the data had been released. Coverage flagged industrial-espionage risk given the engineering firm's reported client roster of automakers and aerospace names. It was an early 2025 signal of the theme India's year would sharpen: the country's globally-woven engineering and IT-services firms are high-value targets precisely because their files belong, in effect, to everyone they build for.
⏳ Time capsule — March 2025
- Gold crossed $3,000 an ounce for the first time in history on March 14, driven by tariff anxiety.
- NASA astronauts Suni Williams and Butch Wilmore splashed down on March 18, ending an unplanned 286-day ISS stay that began with Boeing Starliner's troubled test flight.
- OpenAI switched on native image generation in GPT-4o on March 25, igniting the viral Studio Ghibli portrait trend.
- India beat New Zealand in Dubai on March 9 to win the ICC Champions Trophy — its third title.
The fat finger and the firewall
Signalgate became the permanent go-to example for a truth security culture resists: the human operator, not the exotic exploit, is the likeliest point of catastrophic failure — and it hardened rules on approved channels for sensitive discussion across governments and enterprises alike. 23andMe's bankruptcy left a lasting question mark over data custody in insolvency that regulators are still working through, every time a data-rich company teeters. And Oracle's double denial entered the case studies as a lesson in breach communication — that the gap between what a company says and what the record shows can do more lasting damage than the intrusion itself. March 2025 proved that the scariest breaches sometimes have no hacker at all.