March 2026 Cybersecurity Review: Stryker Attack, Ransomware Trends, and Instagram Encryption Changes
In the March 2026 edition of his security roundup, ESET Chief Security Evangelist Tony Anscombe analyzes critical cybersecurity developments from the past month. A major focus is the devastating cyberattack on medtech giant Stryker, attributed to the Iran-linked Handala hacktivist group, which reportedly wiped over 200,000 devices and stole 50 terabytes of data. Additionally, new research from the Google Threat Intelligence Group reveals that data theft occurred in 77% of ransomware attacks in 2025, with attackers increasingly leveraging built-in Windows utilities. The report also highlights significant policy and enforcement actions, including Instagram's decision to stop encrypting private messages starting in May and a successful Europol-led operation that dismantled Tycoon 2FA, a phishing platform responsible for 62% of phishing attempts blocked by Microsoft in mid-2025. Anscombe emphasizes these events as urgent wake-up calls for organizations to strengthen their cyber-resilience plans. The analysis underscores the evolving threat landscape, characterized by sophisticated data exfiltration techniques and the persistent danger of phishing, while noting shifts in digital privacy standards among major tech platforms.
Wire timeline
March 2026 Cybersecurity Review: Stryker Attack, Ransomware Trends, and Instagram Encryption Changes
In the March 2026 edition of his security roundup, ESET Chief Security Evangelist Tony Anscombe analyzes critical cybersecurity developments from the past month. A major focus is the devastating cyberattack on medtech giant Stryker, attributed to the Iran-linked Handala hacktivist group, which reportedly wiped over 200,000 devices and stole 50 terabytes of data. Additionally, new research from the Google Threat Intelligence Group reveals that data theft occurred in 77% of ransomware attacks in 2025, with attackers increasingly leveraging built-in Windows utilities. The report also highlights significant policy and enforcement actions, including Instagram's decision to stop encrypting private messages starting in May and a successful Europol-led operation that dismantled Tycoon 2FA, a phishing platform responsible for 62% of phishing attempts blocked by Microsoft in mid-2025. Anscombe emphasizes these events as urgent wake-up calls for organizations to strengthen their cyber-resilience plans. The analysis underscores the evolving threat landscape, characterized by sophisticated data exfiltration techniques and the persistent danger of phishing, while noting shifts in digital privacy standards among major tech platforms.
WeLiveSecurity