• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
  • X
  • Facebook
  • YouTube
  • LinkedIn
Screen Connect
Support
Customer Portal
Pay Online
SWK logo.

SWK Technologies

Software Solutions & Services

  • Accounting & ERP Software
      • Acumatica Cloud ERP
        • Overview
        • Construction
        • Distribution
        • Field Service
        • Financial Management
        • Manufacturing
        • Professional Services
        • Project Accounting
        • Retail-Commerce
      • Sage Intacct
        • Overview
        • Construction and Real Estate (CRE)
        • Distribution Operations for Sage Intacct
        • Financial Services
        • Healthcare
        • Manufacturing Operations for Sage Intacct
        • Nonprofits
        • Professional Services
        • Sage Intacct Payroll powered by ADP
      • Sage 100
        • Overview
        • Business Intelligence
        • Core Accounting & Financials
        • Distribution
        • Manufacturing
        • Payroll
        • Sage 100 Contractor
      • More Accounting Products
        • QuickBooks
        • Sage 50
        • Sage 300
        • Sage 500
        • Sage BusinessWorks
      • ERP Add-ons
        • ADP Workforce Now
        • Altec
        • Avalara
        • AvidXchange
        • BigCommerce
        • CIMCloud
        • Cloud Hosting
        • DataSelf
        • Fortis
        • FreightPOP
        • Lumber
        • Microsoft 365
        • Netstock
        • Ottimate
        • Quadient
        • Sage Fixed Assets
        • Sage HRMS
        • Sage Intacct Payroll powered by ADP
        • Savant WMS
        • Endpoint Automation Solutions (FKA Scanco)
        • ScanForce
        • Solver
        • SPS Commerce
        • Velixo
        • Workforce Go!
      • More ERP Add-ons
        • Bizinsight
        • Concur
        • Crystal Reports
        • Fraxion
        • Fusion RMS
        • FYISoft
        • JobOps
        • KnowledgeSync
        • Lockstep Collect
        • Nectari
        • Pacejet
        • Planning Maestro
        • Sage CRM
        • Sage Intelligence
        • Sage Supply Chain Intelligence
        • Scissortail HCM
        • Service Pro
        • ShipStation
        • Shopify
        • Starship
        • Sugar CRM
        • Time & Billing Pro
        • Timekeeper
        • True Sky
      • Industries
        • Construction
        • Distribution
        • Financial Services
        • Healthcare
        • Manufacturing
        • Nonprofit
        • Professional Services
        • Retail
  • Managed Cloud Services
      • Managed IT Services
        • Managed Cloud Services
        • Network Assurance Core
        • Email Hosting
        • IT Support
        • Microsoft 365 Services
        • Server Monitoring
        • Virtualization
      • Cybersecurity
          • CyberAssurance CORE™
          • Cybersecurity Solutions
          • Backup & Continuity
          • Compliance
          • Dark Web Monitoring
          • EDR
          • Encryption
          • MFA
          • Penetration Testing
          • Security Training
          • SOC
          • Spam & Virus Filtering
          • vCIO
          • Vulnerability Assessment
      • Cloud Services
        • Cloud Hosting
        • Infrastructure-as-a-Service
        • Acumatica IaaS
      • Industries
        • Financial Services
        • Healthcare
        • Construction
      • Locations
          • Nationwide
          • Austin
          • California
          • Chicago
          • Minneapolis
          • New Jersey
          • New York
          • North Carolina
          • Philadelphia
          • Phoenix
          • San Diego
          • Seattle
  • Consulting & Implementation
    • Business Technology Consulting
    • eCommerce
    • Financing
    • Human Capital Management
    • Managed Cloud & IT Services
    • Partner Program
    • Software Development
    • Software Implementation
  • Resources
    • Help Desk
    • Blog Posts
    • Payments Portal
    • Webinars
    • YouTube Channels
    • Acumatica Resources
    • Sage Intacct Resources
    • Sage 100 Resources
    • IT Resource Pages
  • About
    • About SWK
    • Awards & Recognition
    • Life@SWK
    • Careers
    • Success Stories
    • SWK Gives
  • Contact
    • Contact Us
    • Support
    • Our Locations

SWK Technologies March 2026 Cybersecurity News Recap

March 23, 2026 by Hector

Home » Cybersecurity » SWK Technologies March 2026 Cybersecurity News Recap

Five cream-colored letter tiles spelling "MARCH" arranged in a horizontal row against a white background.

March 2026 saw a massive influx of cybersecurity news, with a significant wave of ransomware and other malware attacks carried out by threat actors tied to North Korea, Russia and the Islamic Republic of Iran, potentially in concert with the conflict occurring between the latter and the U.S. While there has been action by different law enforcement agencies to counter some of these, the fallout from the attacks  is still ongoing and your business should remain wary of the increased cyber risk going into April and the rest of 2026.

SWK Technologies has put together this month’s Cybersecurity News Recap to help your business keep track of the biggest threats and what they mean for your security posture:

Medusa Gang Attacks NJ Passaic County and Mississippi Hospital

The Medusa ransomware gang claimed credit for two high-profile attacks in March 2026, targeting the University of Mississippi Medical Center (UMMC) and Passaic County of New Jersey’s local government systems. The UMMC breach began February 19 and forced the closure of 35 clinics across the state, suspended elective surgeries and imaging appointments, and cut off access to the hospital’s Epic electronic health record system for nine days. Staff reportedly reverted to handwritten charts and some patients were diverted to other facilities.

Medusa added UMMC to its dark web leak site on March 12, claiming to have exfiltrated more than 1 TB of data including patient health information and employee records, and demanding $800,000 in ransom. Medusa also claimed a separate attack on Passaic County on March 17, demanding the same amount and disrupting phone lines and IT systems serving nearly 600,000 residents.

Operating a ransomware-as-a-service (RaaS) model, the group has been active and has a history of targeting critical infrastructure organizations from healthcare to the public sector. Medusa has already claimed various other victims in 2026, including Frauenshuh Commercial Real Estate, Acme Truck Line, Bell Ambulance, Grandview Family Medicine and many more. The gang seemingly became more active last year in the wake of international law enforcement actions that took down several of the leading ransomware groups.

Medtech Vendor Stryker Hit by Pro-Iran Hackers

The Iran-linked hacktivist group Handala claimed responsibility for a destructive cyber attack against medical technology manufacturer Stryker on March 11, framing the attack as retaliation for a U.S. airstrike on a school in Iran. The attackers, suspected to be linked to Iran’s Ministry of Intelligence and Security (MOIS), appear to have gained access to a Microsoft Intune device management console using compromised administrator credentials – potentially obtained through infostealer malware – then issued a remote wipe command that affected more than 200,000 devices across 79 countries.

Stryker claimed to have confirmed that the disruption was confined to its Microsoft environment and found no evidence of ransomware or malware deployed on its systems, and stated that Internet-connected medical products remained safe to use. As of March 15, 2026, the company was actively restoring impacted systems, with priority given to those supporting orders and shipping. The FBI and CISA actively engaged with Stryker during the investigation, and the former announced on March 19 that they had seized Handala’s data leak website, among several other domains tied to group (more on this below).

Named after a cartoon character drawn by a Palestinian artist, the Handala group emerged in 2023, claiming to be a pro-Palestinian hacktivist collective retaliating against Israel for its operations in Gaza at the time. Though they have claimed credit for multiple attacks against targets within the Israeli government and private sectors, the March 11 incident appears to be their first major attack against an American target.

Qilin Hits Texas Construction Firm and Puerto Rico Food Processor

The Qilin ransomware gang claimed responsibility for multiple new attacks on March 18, 2026, including:

  1. L.H. Lacy, a large Texas-based contractor serving the construction industry
  2. Productos La Aguadillana, a food and beverage processor in Puerto Rico
  3. Jacob & Sons, a retailer based in Pennsylvania
  4. BTX Global Logistics, a logistics service provider headquartered in Connecticut

All of the victims were hit with double extortion – wherein data is first stolen and then threatened to be leaked if a ransom payment is not received – which is typical of Qilin’s M.O.

The group had already claimed more than 400 victims in 2026 at the time of this writing, continuing a surge that saw it list over 1000 victims in 2025 and emerge as the most active ransomware gang of the year. Other high-profile attacks they have claimed includes breaches against the LISI Group of France, Nissan, Tulsa International Airport, the Tennessee Valley Electric Cooperative and the Church of Scientology, all within a six-month period. First observed in 2022, Qilin operates a RaaS model, is suspected to be linked to Russia, and consistently targets industries where data sensitivity and operational disruption increase pressure on victims to pay.

U.S. DOJ Claims Seizure of 4 Domains Linked to Iranian Hackers

The Department of Justice announced on March 19 the court-authorized seizure of four Internet domains operated by Iran’s MOIS, including two tied to the Handala hacker persona that claimed responsibility for the Stryker attack. The seized domains – Handala-Hack[.]to, Handala-Redwanted[.]to, Justicehomeland[.]org and Karmabelow80[.]org – were used to claim cyber attacks, publish stolen data, dox targets and issue death threats against Iranian dissidents, journalists and Israeli-linked individuals, according to the DOJ’s press release.

Court documents also revealed that an associated email account was used to send death threats to victims in the U.S. and abroad, as well as claimed coordination between the Handala group and the Jalisco New Generation Cartel – formerly headed by the late “El Mencho” – with declarations that personal information had been passed to enforcers of the latter. The Trump administration has stated that what they uncovered ostensibly proves the hacktivist group is a front for Iran’s MOIS, and FBI Director Kash Patel said that his agency would “hunt down every actor” behind both the cyber attacks and the threats made to the victims. However, several experts told outlet Cybersecurity Dive that the seizures will only minimally disrupt Handala’s capabilities for the time being.

CISA Warns of Microsoft Intune and SharePoint Risks

In the wake of the 2026 Stryker breach, CISA issued an alert on March 18 urging all U.S. organizations to harden their Microsoft Intune environments, warning that cyber attackers are increasingly targeting endpoint management systems to gain privileged access and execute destructive actions without deploying traditional malware. Key recommendations made by both the agency and Microsoft itself for securing Intune include enforcing least-privilege access through role-based controls, requiring phishing-resistant multifactor authentication (MFA) for privileged accounts and enabling Multi-Admin Approval for high-impact actions such as device wipes.

On the same day, CISA added CVE-2026-20963 to its Known Exploited Vulnerabilities catalog – a critical remote code execution flaw in Microsoft SharePoint affecting versions 2016, 2019 and Subscription Edition, with a CVSS score of 9.8. Federal agencies were ordered to patch by March 21. CISA has not linked the flaw to any ransomware campaigns as of this writing, though the severity and low exploitation complexity make it a high-priority fix for any business running SharePoint on-premise.

Contact SWK to Learn More About the Latest Cyber Threats

March 2026 was a busy month for cybersecurity news, to say the least, but the incidents this month reflect a broader pattern of threat actors — state-linked and criminal alike — weaponizing the everyday tools businesses depend on to carry out attacks at scale. SWK Technologies will help you uncover and plug the gaps within your security posture that could put you at risk against emerging cyber threats, and work with your team to ensure your defenses are hardened from the inside and out against the most common types of attacks.

Contact SWK here to learn about our cybersecurity solutions and discover how we can help protect your network, systems and data from the latest threats.

Reach Out to Us Here

Category: Cybersecurity, Blog, News and Events

Sidebar

Recent Posts

  • SWK Technologies March 2026 Cybersecurity News Recap
  • Gain Real-time Jobsite Access from Sage 100 Contractor in the Cloud
  • How to Use Recurring Journal Entries in Sage Intacct
  • How to Use Auto Generate Invoices in Sage 100
  • How the CCPA Audit Rule Affects SMBs in 2026
  • Cybersecurity Training – Why You Need More Than a Checkbox
  • How to Set Up AI Studio in Acumatica 2025 R2

Categories

Ready to take the next step?

Contact SWK today to get in touch with one of our experts. We’ll go over your business challenges and unique needs, and see where you can unlock new value from your technology and make your operations run easier.

Get in touch!

Our Latest Posts

Five cream-colored letter tiles spelling "MARCH" arranged in a horizontal row against a white background.

SWK Technologies March 2026 Cybersecurity News Recap

Read moreSWK Technologies March 2026 Cybersecurity News Recap
Aerial view of an active construction jobsite with multiple workers in orange safety vests and hard hats working across concrete formwork, rebar grids and red metal shoring panels during a large-scale building project.

Gain Real-time Jobsite Access from Sage 100 Contractor in the Cloud

Read moreGain Real-time Jobsite Access from Sage 100 Contractor in the Cloud
Sage Intacct recurring journal entries Transaction tab showing a new entry form with Book set to Accrual, Journal set to GJ–General Journal, Description set to Rent, Reference number 1, and two entry lines: a $1,500 debit to account 60300–Rent and a $1,500 credit to account 20100–Accounts Payable, both assigned to Department 100–Admin and Location 100–Entity 1.

How to Use Recurring Journal Entries in Sage Intacct

Read moreHow to Use Recurring Journal Entries in Sage Intacct

Awards and Accreditations

Top work places in NJ 2020.
Acumatica the Cloud ERP gold certified partner.
The Gold Microsoft partner logo on a black background.
Sage business partner diamond logo.
Dell Technologies Gold Partner
Sage tech partner logo.

Stay in the know!

Subscribe for exclusive ERP, process automation, IT and cybersecurity news.

Twitter
  • Facebook
  • YouTube
  • LinkedIn

Home
About
Contact

Support
Screen Connect
Pay Online
Downloads

SWK logo.

Headquarters:
120 Eagle Rock Ave, Suite 330
East Hanover, NJ 07936

Contact:
info@swktech.com
(877) 979-5462

Copyright © 2026 · SWK Technologies, Inc. · All Rights Reserved · Terms of Use · Privacy Policy

This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. By continuing to browse this site you agree to the use of cookies. Visit our privacy policy to learn more.