Menu

Monthly Cyber Threats Report - March 2026

Issue 15: March 2026

Monthly Cyber Threats Report - March 2026

Editor's note

Francisco Sanches
Francisco Sanches

This month's Cyber Threats Report covers five significant developments that highlight the evolving tactics employed by threat actors and the broadening attack surface facing organisations today.

Our first article examines the destructive cyberattack against Stryker, in which the Iranian-linked hacktivist group Handala abused Microsoft Intune's remote wipe functionality to erase over 200,000 endpoints across 79 countries. The second article covers a new wave of phishing campaigns exploiting OAuth redirect mechanisms to funnel users from trusted login pages into malicious infrastructure, bypassing multi-factor authentication entirely. The third article addresses a confirmed data breach affecting LexisNexis Legal & Professional, in which threat actors exploited a web application vulnerability to access legacy systems and leak approximately 2GB of data. Our fourth article covers two high-severity zero-day vulnerabilities in Google Chrome that are being actively exploited in the wild and require urgent patching.

A common thread across all four articles is the speed at which threat actors are capitalising on trusted platforms and widely used technologies. These developments reinforce the need for organisations to maintain robust patch management, continuous monitoring and a healthy scepticism of even seemingly legitimate digital interactions.

As a final note, the National Cyber Security Centre (NCSC) issued an alert on 2 March 2026 advising UK organisations to review their cyber security posture in light of the evolving situation in the Middle East. Organisations are encouraged to consult the NCSC's published guidance and take appropriate steps to ensure their defences remain aligned with the current threat landscape.

News
a computer screen with green text

Stryker taken down by Iran-linked wiper attack

Medical technology giant Stryker was hit by a destructive cyberattack claimed by Handala, an Iranian-linked and pro-Palestinian hacktivist group. The incident occurred on 11 March 2026 and resulted in a global disruption to the company's entire Microsoft environment.

News
Blue electronic waves

OAuth redirect tricks bypass user defences

Microsoft has identified a new wave of phishing and malware campaigns exploiting an OAuth feature to funnel users from trusted login pages into attacker‑controlled sites.

News
a close up of lines and dots

LexisNexis data breach leads to leak of stolen files

In March 2026, LexisNexis Legal & Professional confirmed that a security incident resulted in unauthorised access to a limited number of its systems after threat actors leaked allegedly stolen files from the company’s infrastructure. The incident became public when a threat actor using the alias “FulcrumSec” posted approximately 2GB of structured data on underground cybercrime forums commonly used to distribute stolen information.

Subscribe

Never miss a publication by signing up to our mailing list

Monthly Cyber Threats Report - March 2026 Issues

How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else