There is a special quality to watching it happen. In March 2026, employees at Stryker — the medical technology giant whose implants and surgical systems sit inside hospitals worldwide — watched their company's computers being wiped in real time, screen by screen, in an attack linked to an Iran-aligned hacktivist group. Not encrypted for ransom. Erased. Wipers are the rarest of weapons because they monetise nothing; their currency is spectacle, and their message is always the same: we were here, and we did not come to negotiate.
Around that centrepiece, the month's tracking told a story of sheer volume: 702 ransomware attacks — the busiest month analysts had recorded — alongside 54 significant breach and leak incidents. But the analysts watching Catalyst RCM, the University of Hawaii, Michelin, and LexisNexis converged on a subtler observation: attackers were no longer merely taking what businesses store. They were going after what businesses run on — billing engines, logistics, research platforms, the machinery of function itself.
It reframed the quarter. January's grid intrusion and February's carrier sweep had looked like espionage stories; March made them chapters of the same book. When the target is function, every sector is critical infrastructure to somebody — a hospital's implant supplier no less than a power utility.
Brussels attacked, a party held hostage
On March 24 the European Commission disclosed an attack on the cloud infrastructure hosting its Europa web platform — the public face of EU governance — with early findings pointing to data exfiltration. The same month, the Qilin ransomware crew claimed Germany's Die Linke party, threatening to publish stolen internal data. Two very different intrusions, one theme: the institutions of politics themselves as targets, in a year already crowded with elections and tensions.
Telus joins the telecom ledger
A month after Singapore's four-carrier revelation, Canadian telecom Telus reported unauthorized access to its systems. The details were thinner than Singapore's accounting, but the rhythm was becoming impossible to miss: telecommunications providers — the layer every other sector stands on — were being probed, breached, or revealed as breached, monthly. What had once been an occasional headline was now a drumbeat.
The fiscal year closes; the phishers clock in
No Indian name led March's global incident lists — the month's Indian story was seasonal, and by now ritual. As the fiscal year raced to its March 31 close, the annual surge arrived on schedule: TDS-refund phishing, fake invoice fraud aimed at accounts teams clearing year-end payments, and "verify your PAN" lures timed to tax anxiety. It lands on fertile ground — losses from cyberattacks in India crossed ₹20,000 crore in 2025 — and it makes March the month every Indian finance department is simultaneously at its busiest and most phishable. The defence, as ever, is boring and effective: out-of-band verification for every payment change, no exceptions in the last week of March.
A flagship model and Nvidia's seventh chip
OpenAI released GPT-5.4 on 5 March 2026, in Thinking and Pro variants that at first excluded free-tier users; smaller mini and nano versions followed on 17 March. Google spent the month filling in the tier beneath its frontier line rather than above it, adding Gemini 3.1 Flash-Lite — which it called its fastest and most budget-friendly model yet — along with Gemini 3.1 Flash Live for audio and the Lyria 3 Pro music model. The month's centre of gravity, though, was San Jose. At GTC on 16 March Nvidia announced the Vera Rubin platform as seven chips in full production, naming Anthropic, Meta, Mistral AI and OpenAI among the developers building on it. The seventh was the Groq 3 LPU, the first silicon to surface from the licensing agreement and hiring of Groq's leadership that Nvidia had announced the previous December — an arrangement that drew questions in Washington about whether it was an acquisition structured to sit below antitrust review. The rack built around it was promised for the second half of the year.
CrowdStrike crosses five billion; Google closes Wiz
The endpoint sector reported its results and its consolidation in the same three weeks. CrowdStrike reported its year on 3 March 2026 with annual recurring revenue above five billion dollars and, by its own accounting, more than a billion dollars of net new ARR added over the twelve months — a first for the company — alongside positive GAAP net income for the quarter. SentinelOne followed on 12 March, passing a billion dollars of annual revenue and declaring full-year operating profitability, though that was a non-GAAP measure: on a GAAP basis the company still reported a substantial net loss. Between the two, on 11 March, Google completed its thirty-two-billion-dollar purchase of Wiz, the largest acquisition in its history and one cleared without conditions by every regulator that examined it. SecurityWeek counted thirty-eight cybersecurity deals across the month. The drift was legible again on 24 March, when CrowdStrike used the RSA conference to introduce Falcon Data Security, reaching past the endpoint into browsers, SaaS accounts and AI workflows.
⏳ Time capsule — March 2026
- 702 ransomware attacks in one month — a record that, on current form, nobody expects to stand for long.
- "Wiper" re-entered the mainstream security vocabulary for the first time since the NotPetya era.
- Michelin and LexisNexis on the same monthly victim list — tyres and legal data, united by dependency.
- Conference season loomed, and every keynote draft discovered the phrase "resilience over prevention."
Function is the new perimeter
March's lesson compounded through the spring: April took the systems theme to its extreme — the FBI's own surveillance apparatus — and by summer, "what can they reach?" had replaced "what can they take?" as the board-level question, exactly as this month previewed. The wiper at Stryker remained the quarter's starkest image: not a countdown timer demanding payment, but screens simply going dark while their owners watched. Ransomware negotiates. Wipers editorialise. And in 2026, both were arguments for the same defensive conclusion our current editions keep returning to — segment everything, back up like you mean it, and treat availability as the asset it always was.