Hackers know what you ordered and where you live, EU hacked, hundreds of millions private records leaked, and your TV is spying on you
March had massive global data breaches. Hackers exposed 1,000,000 Gigabyte of data from TELUS Digital, over 840 million files from SpeedX, and sensitive medical records in France and the United States.
Samsung settled a major lawsuit for tracking Smart TV users without consent.
Furthermore, a highly controversial United States executive order attempted to compile a national citizen database, raising severe privacy concerns.

The biggest data leaks and hacks in March 2026
This month had a lot of breaches and leaks, even the top list is long. Also read below how to find out if you are affected and what to do.
TELUS Digital [Canada]: Tens of millions affected
The ransomware group ShinyHunterz stole one petabyte (that is 1,000 terabyte - a modern phone or regular PC has 0,5 terabyte of storage) of unencrypted data from the telecommunications company.
The breach exposed personally identifiable information, call data, background checks from the FBI, corporate financial information, voice recordings, source codes, and Salesforce data. TELUS acts as a business process outsourcing partner, meaning the stolen files belong to various global clients.
This breach is catastrophic because of the sheer volume and the extreme sensitivity of FBI background checks.
The hackers gained unauthorized access to internal systems, likely using compromised employee credentials. TELUS confirmed the breach on March 11. The company has been relatively straightforward about the cyberattack, although the full impact on their business clients remains under investigation as of today.
SpeedX [United States]: Tens of millions affected
Cybernews researchers discovered an exposed cloud database containing over 840 million records.
The unencrypted leak includes 618 million parcel photos showing home addresses, images of driver licenses, shipping labels, and screenshots of SpeedX application credentials. The files openly list the full names and home addresses of parcel recipients.
Based on the file count, this leak affects tens of millions of customers and delivery drivers across the country.
This leak is especially dangerous because it enables widespread identity theft and physical security risks. Hackers can see who ordered expensive items or house security items and know where they live.
The data leaked through a misconfigured Microsoft Azure storage bucket that lacked password protection. Researchers discovered the open database on March 13 and notified the company. SpeedX secured the database but controversially claimed no unauthorized access occurred. They framed the event as a simple configuration issue rather than a massive data exposure.
Stryker Corporation / Microsoft Intune Platform: Hundreds of thousands affected
The hacktivist group Handala compromised 50 terabytes of data from this global medical device manufacturer. The group wiped 200,000 servers, mobile devices, and other connected systems across 79 countries.
A 50 terabyte loss across a corporate network implies the exposure of extensive corporate communications, employee records, and potentially unencrypted medical provider data affecting hundreds of thousands of individuals.
The hackers compromised a single Microsoft Intune administrator account to gain control over the device management platform. Stryker detected the attack immediately and filed an official report. The company was open about the operational disruption, which halted production and order processing worldwide.
European Commission - Europa.eu [European Union]: ~100,000 affected
The ShinyHunters extortion group stole 350 gigabytes of data from the public cloud infrastructure supporting the Europa web platform.
The unencrypted data dump contains mail server databases, confidential documents, and contracts. Given the size of 350 gigabytes, researchers estimate the breach exposed the private email records and internal communications of roughly 100,000 individuals connected to the European Union.
The hackers exploited vulnerabilities in the cloud infrastructure to extract the files. The European Commission confirmed a cyber incident occurred but stated it only affected the public web platform and not their core internal networks. Security analysts dispute this claim, noting that the leaked database clearly contains private email records.
AkzoNobel [United States]: Thousands affected
The Anubis ransomware group extracted 170 gigabytes of unencrypted data from a US branch of the Dutch paint manufacturer.
The files include confidential agreements, passport scans, private emails, phone numbers, material testing documents, and internal technical specifications. A 170 gigabyte dump primarily consisting of documents and passport scans suggests that several thousand employees, contractors, and business partners are affected.
The attackers infiltrated the local network and deployed ransomware after extracting the files. AkzoNobel confirmed the cyberattack to the media shortly after the hackers published their claims. The company was straightforward about the incident, admitting the breach occurred on their American network infrastructure.
Cegedim Sante - MonLogicielMedical [France]: 15.8 million affected
Hackers stole the medical records of 15.8 million patients from a software platform used by French doctors.
The unencrypted data includes 165,000 highly sensitive files containing free text notes from medical professionals. These notes reveal HIV statuses, psychiatric diagnoses, mental health conditions, and sexual orientations of patients, including prominent politicians.
The public outrage is massive, as this ranks among the largest and most sensitive healthcare breaches in European history and the company even tried to hide it.
The attackers breached the software platform months prior. The company detected the breach in late 2025 and filed a criminal complaint, but kept it completely secret from the public. They only admitted to the breach on March 3 after the media broke the story, drawing heavy criticism for their lack of transparency.
University of Hawaiʻi Cancer Center [United States]: 1.2 million affected
A ransomware attack exposed the personal data of 1.2 million people.
The compromised, unencrypted files include full names, Social Security numbers, driver license details, health related research information, and voter registration data. The breach spans four distinct cancer studies and two epidemiological research databases.
This is a severe failure to protect highly sensitive medical and government identification data.
Cybercriminals gained access through a ransomware deployment on the university network. The university officially notified the public and updated their initial estimates in early March to reflect the true scale of the disaster. They have been relatively straightforward since discovering the full scope.
Pathstone Family Office [United States]: 641,000 affected
The ShinyHunters ransomware group stole 641,000 records from this financial advisory firm.
The unencrypted data includes Social Security numbers, dates of birth, home addresses, and potentially detailed financial profiles of their wealthy clients.
This is a highly critical breach due to the wealth of the targeted individuals.
The hackers infiltrated the network, exfiltrated the sensitive data, and deployed ransomware. They attempted to extort the company by threatening to release the data on the dark web. The company reported the event, though details emerged primarily through the extortion threats.
Corporate Surveillance and Privacy Lawsuits
Samsung spied on everything you are watching and sold that information
Samsung Electronics settled a major privacy lawsuit with the State of Texas over unauthorized data collection.
Samsung used Automated Content Recognition technology on their Smart TVs to systematically track real time viewing habits, on screen content preferences, and gaming data without informed consent.
To be clear: That means EVERYTHING the TV displays, not just what movies from a streaming platform you watch.
They profiled consumers and shared this data with third party advertisers. This unauthorized collection allowed advertisers to create invasive psychological profiles of users based on their private home viewing habits.
Governmental Decisions Weakening Privacy
The US president continues to interfere with elections
On March 31, 2026, the United States President issued a sweeping Executive Order titled "Ensuring Citizen Verification and Integrity in Federal Elections."
This order directed federal agencies to compile a comprehensive national list of all US citizens and directed the US Postal Service to restrict mail voting to an approved list.
Civil rights groups strongly condemned this decision. They argued that creating an unauthorized national database of citizens creates a massive target for hackers and acts as a tool for state surveillance, fundamentally weakening voter privacy rights.
And of course it is aimed to suppress a specific groups of voters.
Protect Your Identity
Take a moment to check if your email appears in these leaks using a service like Have I Been Pwned.
A password manager with two factor authentication (2FA) support provides excellent defense against these breaches. The manager generates and stores a unique, complex password for every single account.
If criminals breach one company, they cannot use your stolen password to unlock your other accounts. Adding 2FA requires a secondary code to log in. Even if hackers buy your password from a data dump, they cannot access your account without that second step.

