EVENTS
EVENTS/DAY
0
EVENTS
0
EVENTS/DAY
0

It’s time to publish the second cyber attacks timeline of March, covering the main events occurred in the second half of this month. In this timeline I have collected 123 events, with an average rate of 7.7 events per day.

The ProxyLogon vulnerability continue to characterize this period, with new cyber criminal groups trying to capitalize it (such as the Black Kingdom ransomware).

Effectively, ransomware is still the top threat with nearly 23% of events (but they could be many more since too many organizations still do not completely disclose the reason of some unspecified “outages”.

Always related to ransomware is the exploitation of the Accellion FTA 0-day, (carried out by the Clop and FIN11 gangs), whose effect must not be underestimated: eight additional high-profile victims have joined the list in this timeline.

On the Cyber Espionage front, this timeline has seen multiple campaigns carried out by threat actors such as Mustang Panda (AKA RedDelta), targeting multiple telco organizations worldwide, China Chopper (exploiting the ProxyLogon vulnerability), Charming Kitten, the Lazarus Group, and an unspecified “sophisticated threat actor” discovered by Google exploiting 11 0-day vulnerabilities on Android and iOS.

Expand for details

Enjoy the interactive timeline, and thanks for sharing it, and supporting my work in spreading the risk awareness across the community. Also, don’t forget to follow @paulsparrows on Twitter, or even connect on Linkedin, for the latest updates.

Last but not least, on the cyber crime front,another important trend to consider is the occurrence of new mega breaches targeting organizations in India, Israel, The Netherlands, and the US.

BREACHOMETER

The “Breachometer” compares the current number of events/day with the max and min values recorded in the previous 12 months.

12 MONTHS TREND
RECOMMENDED
POPULAR POSTS
  • Maga Breaches 2026 Front ImageMega Breaches in 2026

    Here’s a collection of the main mega breaches (that is data breaches with more than one million records compromised and possibly leaked) during 2026. The information is derived from the cyber attacks timelines that I published, normally, on a bi-weekly basis.

  • Exploited Security Vendor Vulnerabilities in 2026

    Security vendors were prime targets in the first half of 2026, with 55 confirmed exploitation incidents involving 66 CVEs across the main vendors. Explore the full interactive timeline and charts.

  • July 2026 Cyber Attacks Statistics

    July 2026 saw 188 confirmed cyber attacks across 69 countries, with financially motivated Cyber Crime driving three in four incidents. Malware remained attackers' weapon of choice, exposed public-facing applications were the most common way in, and Information & Communication infrastructure absorbed the heaviest share of ...

  • 1-15 August 2026 Cyber Attacks Timeline

    Cyber crime dominated the first half of August 2026, driving 108 confirmed incidents in just fifteen days. Malware remained the attacker's weapon of choice, a third of breaches traced back to an exploited public-facing application, and Public Administration emerged as the hardest-hit sector.

  • 16-31 July 2026 Cyber Attacks Timeline

    103 confirmed cyber incidents reported between 15 and 31 July 2026 — including attacker motivations, top techniques, initial access vectors, hardest-hit sectors, and targeted countries, all in one interactive HACKMAGEDDON timeline.

FOLLOW ME ON TWITTER

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.