There is a special quality to watching it happen. In March 2026, employees at Stryker — the medical technology giant whose implants and surgical systems sit inside hospitals worldwide — watched their company's computers being wiped in real time, screen by screen, in an attack linked to an Iran-aligned hacktivist group. Not encrypted for ransom. Erased. Wipers are the rarest of weapons because they monetise nothing; their currency is spectacle, and their message is always the same: we were here, and we did not come to negotiate.
Around that centrepiece, the month's tracking told a story of sheer volume: 702 ransomware attacks — the busiest month analysts had recorded — alongside 54 significant breach and leak incidents. But the analysts watching Catalyst RCM, the University of Hawaii, Michelin, and LexisNexis converged on a subtler observation: attackers were no longer merely taking what businesses store. They were going after what businesses run on — billing engines, logistics, research platforms, the machinery of function itself.
It reframed the quarter. January's grid intrusion and February's carrier sweep had looked like espionage stories; March made them chapters of the same book. When the target is function, every sector is critical infrastructure to somebody — a hospital's implant supplier no less than a power utility.
Brussels attacked, a party held hostage
On March 24 the European Commission disclosed an attack on the cloud infrastructure hosting its Europa web platform — the public face of EU governance — with early findings pointing to data exfiltration. The same month, the Qilin ransomware crew claimed Germany's Die Linke party, threatening to publish stolen internal data. Two very different intrusions, one theme: the institutions of politics themselves as targets, in a year already crowded with elections and tensions.
Telus joins the telecom ledger
A month after Singapore's four-carrier revelation, Canadian telecom Telus reported unauthorized access to its systems. The details were thinner than Singapore's accounting, but the rhythm was becoming impossible to miss: telecommunications providers — the layer every other sector stands on — were being probed, breached, or revealed as breached, monthly. What had once been an occasional headline was now a drumbeat.
The fiscal year closes; the phishers clock in
No Indian name led March's global incident lists — the month's Indian story was seasonal, and by now ritual. As the fiscal year raced to its March 31 close, the annual surge arrived on schedule: TDS-refund phishing, fake invoice fraud aimed at accounts teams clearing year-end payments, and "verify your PAN" lures timed to tax anxiety. It lands on fertile ground — losses from cyberattacks in India crossed ₹20,000 crore in 2025 — and it makes March the month every Indian finance department is simultaneously at its busiest and most phishable. The defence, as ever, is boring and effective: out-of-band verification for every payment change, no exceptions in the last week of March.
⏳ Time capsule — March 2026
- 702 ransomware attacks in one month — a record that, on current form, nobody expects to stand for long.
- "Wiper" re-entered the mainstream security vocabulary for the first time since the NotPetya era.
- Michelin and LexisNexis on the same monthly victim list — tyres and legal data, united by dependency.
- Conference season loomed, and every keynote draft discovered the phrase "resilience over prevention."
Function is the new perimeter
March's lesson compounded through the spring: April took the systems theme to its extreme — the FBI's own surveillance apparatus — and by summer, "what can they reach?" had replaced "what can they take?" as the board-level question, exactly as this month previewed. The wiper at Stryker remained the quarter's starkest image: not a countdown timer demanding payment, but screens simply going dark while their owners watched. Ransomware negotiates. Wipers editorialise. And in 2026, both were arguments for the same defensive conclusion our current editions keep returning to — segment everything, back up like you mean it, and treat availability as the asset it always was.