Security spends fortunes defending against sophisticated adversaries. In March 2025, the United States leaked its own war plans because someone added the wrong contact to a group chat. On March 24, The Atlantic's editor-in-chief Jeffrey Goldberg revealed that he had been inadvertently added — on March 13, by an account belonging to National Security Adviser Michael Waltz — to a Signal group called "Houthi PC small group." Its roughly 18 members included the Vice President, the Defense Secretary, the Secretary of State, the CIA Director, and the Director of National Intelligence. And on March 15, about two hours before US strikes on Houthi targets in Yemen began, the Defense Secretary posted operational sequencing to the chat — including launch times for F/A-18 strike aircraft.

The National Security Council confirmed the thread appeared authentic; the White House insisted no classified information had been shared. On March 26, The Atlantic published the messages nearly in full, withholding only a CIA officer's name, reasoning that if the administration was adamant nothing was classified, there was no basis for restraint. The next day a federal judge ordered the government to preserve the messages, some of which had been set to auto-delete — turning a consumer-app convenience feature into a federal-records problem.

"Signalgate" was, in the purest sense, a human-factors breach. Signal's encryption worked perfectly; the failure was operational discipline — using a consumer messaging app for war planning, and the oldest mistake in the address book: adding the wrong person. No firewall defends against a fat finger. For every security team that had spent the year hardening against nation-states, March was a reminder that the likeliest source of the next catastrophic leak is sitting in the group chat, one autocomplete away.

Also that month · The genome on the auction block

23andMe's bankruptcy and 15 million customers

On March 23, 23andMe filed for Chapter 11 bankruptcy and co-founder Anne Wojcicki resigned as CEO — turning the genetic data of roughly 15 million customers into a potential sale asset and raising the question no privacy policy had answered: what happens to your DNA when the company holding it goes broke? California's Attorney General had issued an urgent delete-your-data alert on March 21, two days before the filing, with other state AGs following. The company's decline traced partly to its 2023 breach of about 6.9 million people. It was a landmark case in the most permanent kind of personal data — the kind you can't reset — becoming a line item in a bankruptcy estate.

Also that month · The breach that "wasn't"

Oracle's double denial

Around March 20–21, a threat actor called "rose87168" offered for sale roughly 6 million records — encrypted SSO passwords, key files, LDAP data — claimed to be from Oracle Cloud login servers and allegedly affecting more than 140,000 tenants, per security firm CloudSEK. Oracle publicly and flatly denied any breach of Oracle Cloud. Then came the awkward part: reporting indicated Oracle had privately told customers that its legacy "Gen 1" Oracle Cloud Classic servers had been compromised — a public denial and a private admission, running side by side. Separately, Oracle Health quietly notified US hospitals that patient data had been stolen from legacy migration servers. Two Oracle breaches, two uncomfortable silences. (The record counts above are the seller's claims, never confirmed by Oracle; the legacy-server compromise came from Oracle's own customer notifications.)

India desk · March 2025

Tata Technologies on the leak site

In the first week of March, the Hunters International ransomware group listed Pune-headquartered Tata Technologies on its dark-web leak site, claiming theft of 1.4 TB of data across roughly 730,000 files. The underlying ransomware attack had been disclosed by the company in a January 31 stock-exchange filing — where it said a few IT assets were temporarily suspended while client delivery continued unaffected. The gang threatened to publish within about a week; Tata Technologies did not confirm the alleged theft, and by mid-March reports said the data had been released. Coverage flagged industrial-espionage risk given the engineering firm's reported client roster of automakers and aerospace names. It was an early 2025 signal of the theme India's year would sharpen: the country's globally-woven engineering and IT-services firms are high-value targets precisely because their files belong, in effect, to everyone they build for.

AI Tech desk · March 2025

Native images and melting GPUs

On 25 March 2025 OpenAI switched on native image generation inside GPT-4o, replacing the DALL·E pipeline with a model that could render legible text, accept images as input and follow long instructions. Within days users were converting photographs into Studio Ghibli-style illustrations at a volume OpenAI had not planned for; Sam Altman wrote on 27 March that the company's GPUs were melting, and free-tier generation was rate-limited while capacity caught up. The wave also reopened the training-data argument, since imitating a named studio's house style was precisely what the model did best. Google had shipped Gemini 2.5 Pro that same 25 March, an experimental reasoning model that topped the LMArena leaderboard at launch, and on 27 March Anthropic published interpretability work tracing the internal steps a language model takes before answering — finding, among other things, that it plans ahead rather than composing strictly word by word. Looking back from 2026, March was the month generative images stopped being a separate product and became a feature of the chat window.

Digital Guard desk · March 2025

The shortcut flaw Microsoft declined to patch

The month's sharpest endpoint story was a disagreement about what counts as a vulnerability. On 18 March 2025 Trend Micro's Zero Day Initiative published ZDI-CAN-25373, a flaw in the way Windows handles shortcut files that let an attacker conceal malicious command-line arguments so the file looked harmless in the properties dialog. ZDI counted nearly a thousand malicious samples and at least eleven state-sponsored groups — North Korean, Iranian, Russian and Chinese — abusing it in campaigns going back to 2017. Microsoft declined to ship an urgent fix, saying the issue did not meet its bar for immediate servicing and that Defender and Smart App Control already blocked the activity. Six days later Microsoft unveiled agentic additions to Security Copilot, among them a phishing-triage agent for Defender — automation arriving faster than patches. The business news was steadier: CrowdStrike reported annual recurring revenue of $4.24 billion on 4 March, the first full-year figures to span its July 2024 update outage. The shortcut flaw was quietly addressed later in 2025, once a CVE was finally assigned.

⏳ Time capsule — March 2025

  • Gold crossed $3,000 an ounce for the first time in history on March 14, driven by tariff anxiety.
  • NASA astronauts Suni Williams and Butch Wilmore splashed down on March 18, ending an unplanned 286-day ISS stay that began with Boeing Starliner's troubled test flight.
  • OpenAI switched on native image generation in GPT-4o on March 25, igniting the viral Studio Ghibli portrait trend.
  • India beat New Zealand in Dubai on March 9 to win the ICC Champions Trophy — its third title.
Where it stands today — 2026

The fat finger and the firewall

Signalgate became the permanent go-to example for a truth security culture resists: the human operator, not the exotic exploit, is the likeliest point of catastrophic failure — and it hardened rules on approved channels for sensitive discussion across governments and enterprises alike. 23andMe's bankruptcy left a lasting question mark over data custody in insolvency that regulators are still working through, every time a data-rich company teeters. And Oracle's double denial entered the case studies as a lesson in breach communication — that the gap between what a company says and what the record shows can do more lasting damage than the intrusion itself. March 2025 proved that the scariest breaches sometimes have no hacker at all.