Cybersecurity News Update: March 2025 – Threats, Breaches, and Innovations

Welcome to our monthly cybersecurity news update for March 2025. This month has been marked by a surge in cyberattacks, significant advancements in cybersecurity technology, and new regulatory measures to combat evolving threats. From high-profile data breaches to innovative security solutions, March 2025 underscores the critical need for vigilance and resilience in the digital age. This blog post provides a detailed overview of the major events, including tables summarizing key incidents, background on threat actors, and insights into trends and innovations.

Introduction

The cybersecurity landscape in March 2025 has been dynamic, with a sharp rise in cyberattacks targeting government services, critical infrastructure, and global platforms like X. These incidents, often perpetrated by hacktivist groups and state-sponsored actors, highlight the increasing sophistication and geopolitical motivations behind cyber threats. Meanwhile, innovations such as Google’s acquisition of Wiz and the growing adoption of Zero Trust security offer hope for stronger defenses. Additionally, regulatory changes, like Switzerland’s new reporting mandate, signal a global push for enhanced cybersecurity governance. This post compiles the most significant events, providing actionable insights for organizations and individuals to stay secure, with all sources properly linked.

Major Data Breaches

March 2025 witnessed a series of high-profile cyberattacks that disrupted operations across various sectors. The following table summarizes five of the most impactful incidents, detailing the date, victim, summary, threat actor, business impact, and source.

Table 1: Major Data Breaches and Cyberattacks in March 2025

Date Victim Summary Threat Actor Business Impact Source
March 03, 2025 Anne Arundel County Cyber attack limiting government services, announced on February 23, still affecting services. Unknown Multiple services down for nearly 600,000 residents, multi-day event. The Record
March 10, 2025 X (formerly Twitter) Outages due to alleged massive cyber attack, impacting global availability. Dark Storm Longest X outages tracked, consistent with denial of service attack. The Record
March 18, 2025 National Iranian Tanker Company (NITC) and Islamic Republic of Iran Shipping Lines (IRISL) Disrupted communication networks of 116 ships, targeting sanctioned companies. Lab Dookhtegan Critical to Iran’s oil sales, major attack on maritime operations. Iran International
March 23, 2025 Ukrzaliznytsia Large-scale cyber attack forced ticket sales offline. Unknown Online systems targeted, operational impact on state-owned railway. AlArabiya.net
March 25, 2025 South Africa’s Astral Foods Cyber attack caused delivery delays, lost over $1 million, started March 16. Unknown Implemented disaster recovery protocols, significant financial impact. The Record

Background on Threat Actors

  • Dark Storm Team: Active since late 2023, Dark Storm Team is a pro-Palestinian hacktivist group known for targeting entities supporting Israel, including NATO countries and the U.S. They employ large-scale DDoS campaigns and ransomware attacks, often with political motivations, and have advertised as hackers-for-hire. Their claimed attack on X on March 10, 2025, caused significant global outages, marking one of the longest disruptions in the platform’s history (Wikipedia).
  • Lab Dookhtegan: An Iranian anti-government hacktivist group, Lab Dookhtegan, meaning “sealed lips” in Farsi, is known for actions against the Iranian regime. On March 18, 2025, they claimed responsibility for disrupting communications of 116 oil tankers owned by NITC and IRISL, impacting Iran’s oil sales. The group has a history of exposing Iranian cyber operations, notably leaking APT34’s tools in 2019 (Industrial Cyber).
  • Moonstone Sleet: A North Korean state-sponsored APT group, also known as Storm-1789, Moonstone Sleet has been active since at least 2024. Operating under North Korea’s Reconnaissance General Bureau, they blend espionage with financial cybercrime, using custom malware and ransomware like Qilin. Their targets include aerospace, education, and software sectors, with notable attacks involving social engineering and fake companies (MITRE ATT&CK).
  • NoName057(16): A pro-Russia hacktivist group active since March 2022, NoName057(16) conducts DDoS attacks on entities opposing Russia, such as Ukraine and its allies. On March 24, 2025, they targeted Belgian websites, including MyGov.be and the Walloon Parliament, with limited success. The group is known for its manifesto-driven attacks and offers cryptocurrency payments to participants (Malpedia).
  • Lazarus Group: A North Korean state-sponsored APT group active since at least 2009, attributed to the Reconnaissance General Bureau. Known for high-profile attacks like the 2014 Sony Pictures hack and the 2016 Bank of Bangladesh heist, they target financial institutions, cryptocurrency platforms, and critical infrastructure. In March 2025, they executed a $1.5 billion crypto علیه Bybit, reinforcing their role in financially motivated cybercrime (MITRE ATT&CK).

Cybersecurity Innovations

March 2025 brought significant advancements in cybersecurity, reflecting the industry’s response to escalating threats:

  • Google’s Acquisition of Wiz: Google announced its $32 billion acquisition of Wiz, a cloud security startup, marking its largest acquisition to date. This move aims to enhance Google Cloud’s security capabilities, addressing the growing need for robust cloud protection as AI and digital transformation accelerate (AP News).
  • Zero Trust Security Adoption: The adoption of Zero Trust security principles is gaining momentum. By requiring continuous verification of users and devices, Zero Trust mitigates risks from sophisticated attacks. This approach is particularly relevant for protecting critical infrastructure and cloud environments (Xage).
  • AI-Driven Threat Detection: While not specific to March 2025, the broader trend of AI-driven threat detection systems continues to evolve. These systems enhance real-time monitoring and response, helping organizations stay ahead of advanced persistent threats (APTs) and ransomware.

Table 2: Cybersecurity Innovations in March 2025

Innovation Developer/Organization Description Source
Wiz Acquisition Google (Alphabet) $32 billion acquisition to enhance cloud security for Google Cloud. AP News
Zero Trust Security Industry-Wide Growing adoption of verification-based security frameworks. Xage

Notable Cyber Threats

Ransomware continues to dominate the threat landscape, with March 2025 seeing intensified attacks on critical infrastructure and industrial sectors. Key ransomware groups and trends include:

  • Medusa Ransomware: A Ransomware-as-a-Service (RaaS) operation, Medusa impacted over 300 critical infrastructure organizations by March 2025. Using double and triple extortion tactics, it demands payments for data decryption and non-disclosure (CISA).
  • Qilin Ransomware: Deployed by North Korean actors, including Moonstone Sleet, Qilin was used in targeted attacks, such as the Lee Enterprises breach, stealing 350 GB of data. Its use by state-sponsored groups highlights a shift toward financially motivated cyberattacks (Security Affairs).
  • SuperBlack Ransomware: Exploited Fortinet firewall vulnerabilities (CVE-2024-55591 and CVE-2025-24472), affecting 8,000 exposed systems in the U.S. This underscores the critical need for timely patching and vulnerability management (Xage).
  • Ransomware Trends: The Dragos OT Cybersecurity Report noted an 87% increase in ransomware attacks targeting industrial organizations in 2024, with manufacturing bearing the brunt. These attacks achieved a 100% impact rate, causing full shutdowns (25%) or partial disruptions (75%) (Xage).

Table 3: Notable Cyber Threats in March 2025

Threat Type Target Impact Source
Medusa Ransomware Critical Infrastructure Impacted 300+ organizations, double/triple extortion. CISA
Qilin Ransomware Various Sectors Data theft, financial losses, linked to North Korean actors. Security Affairs
SuperBlack Ransomware Fortinet Firewalls Exploited vulnerabilities, affected 8,000 systems. Xage

Other Notable Incidents

  • Bybit Crypto Heist: The Lazarus Group executed a $1.5 billion cryptocurrency heist against Bybit, the second-largest crypto exchange, in March 2025. This attack, one of the largest in crypto history, raised concerns about the security of digital assets and North Korea’s growing crypto holdings (BBC).
  • CISA Workforce Challenges: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) faced a 4% workforce reduction in February 2025, linked to budget cuts under the DOGE initiative. This raised concerns about federal cybersecurity capabilities, though some staff were rehired by court order (CBS News).
  • HIPAA Violation Lawsuits: Legacy Professionals LLP, an Illinois accounting firm, faced lawsuits for a 2024 data breach reported in March 2025, affecting 217,000 individuals. The incident highlighted the complexities of HIPAA compliance and delayed breach reporting (BankInfoSecurity).

Regulatory Changes

Switzerland introduced a significant regulatory measure to strengthen cybersecurity resilience. Effective April 1, 2025, critical infrastructure entities in sectors like energy, water, transport, and administration must report cyberattacks within 24 hours to the National Cyber Security Centre (NCSC). This mandate aims to enhance rapid response and coordination, reflecting a broader global trend toward stricter cybersecurity governance (InfoSecurity Magazine).

Table 4: Regulatory Changes in March 2025

Regulation Country Description Effective Date Source
Cyberattack Reporting Mandate Switzerland Critical infrastructure must report attacks within 24 hours to NCSC. April 1, 2025 InfoSecurity Magazine

Conclusion

March 2025 has been a critical month for cybersecurity, marked by significant data breaches, a surge in ransomware attacks, and promising innovations. The cyberattacks on X, Iranian oil tankers, and other entities highlight the growing role of hacktivist and state-sponsored actors in exploiting digital vulnerabilities. Meanwhile, Google’s acquisition of Wiz and the rise of Zero Trust security demonstrate the industry’s commitment to countering these threats. Switzerland’s new reporting mandate further emphasizes the importance of rapid response and regulatory oversight.

To stay secure, organizations should prioritize timely patching, employee training, and advanced security frameworks like Zero Trust. Staying informed through reputable sources is also crucial for navigating the evolving threat landscape. For more details on these events and ongoing cybersecurity developments, explore the cited sources below.

Key Citations

  • CM-Alliance: Biggest Cyber Attacks, Ransomware Attacks, Data Breaches of March 2025
  • Iran International: Cyber Group Disrupts Iranian Shipping Communications
  • The Record: Cybersecurity News and Analysis
  • AlArabiya.net: General News and Updates
  • Wikipedia: Dark Storm Team Overview
  • Industrial Cyber: Cydome Analyzes Lab Dookhtegan Cyber Attack on Iranian Oil Tankers
  • MITRE ATT&CK: Moonstone Sleet (G1036) Profile
  • MITRE ATT&CK: Lazarus Group (G0032) Profile
  • Malpedia: NoName057(16) Threat Actor Profile
  • AP News: Google to Buy Wiz for $32 Billion
  • Xage: Cyber Attack News – Risk Roundup – March 2025
  • CISA: Joint Cybersecurity Advisory on Medusa Ransomware
  • Security Affairs: North Korea-Linked Moonstone Sleet Used Qilin Ransomware
  • InfoSecurity Magazine: Switzerland Mandates Cyberattack Reporting
  • BBC: North Korea’s Lazarus Group Behind $1.5B Bybit Heist
  • CBS News: CISA Faces Workforce Cuts Amid DOGE Initiative
  • BankInfoSecurity: Accounting Firm Faces HIPAA Lawsuits for 2024 Breach

 

VeriTech Services

True Tech Advisors – Simple solutions to complex problems. Helping businesses identify and use new and emerging technologies.

Michael Murphy

Cloud Engineering Team Lead

Michael is a cloud engineering and technology leader with seven years of IT experience spanning networking, cybersecurity, systems administration, and cloud engineering. He specializes in designing and supporting cloud-based solutions, strengthening cybersecurity postures, coordinating complex technical initiatives, and developing effective technology strategies across rapidly evolving environments. His experience spans AWS, Google Cloud Platform (GCP), and Microsoft Azure, allowing him to help organizations evaluate, implement, and support solutions across multiple cloud platforms.
 
As Cloud Engineering Team Lead at VeriTech Consulting, Michael is responsible for incident response planning, cybersecurity posture management, cloud service coordination, and facilitating the technical requirements necessary to implement new services. He works across cloud platforms to help translate organizational needs into practical technical solutions, coordinate dependencies, and ensure complex cloud computing initiatives are executed effectively. He also leads the delegation and coordination of technical tasks, helping engineering teams break down complex requirements into manageable workstreams while maintaining focus on security, reliability, and operational effectiveness.
 
Michael began his career in IT through roles focused on network administration and systems administration, including serving as a Network Administrator in the United States Marine Corps and later as a Network and Systems Administrator for a school district. He joined VeriTech Consulting part-time in 2024, transitioned to full-time in 2025, and was promoted to Cloud Engineering Team Lead in 2026. This progression reflects his ability to combine hands-on technical expertise with leadership, problem-solving, and organizational coordination.
 
Michael is also a six-year United States Marine Corps veteran, where he earned the rank of Sergeant and developed a strong foundation in leadership, accountability, discipline, and team development. His military experience emphasized leading by example, making decisions under pressure, delegating responsibilities, developing junior personnel, and maintaining mission focus in demanding environments. He is a Global War on Terror veteran and received multiple military honors and achievements, including Meritorious Promotions to Lance Corporal and Sergeant, Noncommissioned Officer of the Quarter, the Navy and Marine Corps Achievement Medal, the Global War on Terrorism Expeditionary Medal, and the Marine Corps Expeditionary Medal.
 
Michael’s professional development includes certifications and training in cloud engineering, cybersecurity, networking, and project management, including AWS Cloud Practitioner, CompTIA Cloud+, Google Cloud engineering, Google Cybersecurity, Cisco CCST, Fortinet Cybersecurity, and Lean Six Sigma Green Belt. His combination of technical expertise, cybersecurity awareness, cloud engineering experience, and proven leadership enables him to help organizations navigate complex technology challenges while building secure, scalable, and effective cloud environments.

Nathan Watkins

Chief Product & Technical Director

Chief Product & Technical Director | Product Ownership & Delivery | Cyber Intelligence Specialist
 
Nathan Watkins is a retired U.S. Army Chief Warrant Officer 4 who spent thirty years working at the point where intelligence and cyberspace operations meet, during the years when that intersection was still being invented. He helped build the tradecraft, the workflows, and the governance that turned intelligence from something adjacent to cyber operations into something integral to them.
 
He joined VeriTech Consulting directly from active service. As Chief Product & Technical Director, Nathan owns the customer-facing life of the company’s platforms end to end. He runs the demonstrations, shapes the technical approach, carries engagements from introduction to execution, and stays with the customer through delivery, adoption, and renewal. The person who shows a customer what the capability does is the person accountable for it working once they own it.
 
His approach is shaped by three decades of supporting commanders who needed an answer before the situation resolved itself. Nathan is direct about what a capability does and does not do, methodical about turning a stated requirement into something deliverable, and unflappable when the requirement changes mid-stride.

Key Expertise & Accomplishments:

Cyber Intelligence & Operations SME — Pioneered intelligence support to cyberspace operations, establishing tradecraft and integration models at a time when no established practice existed.

Decision Advantage — Experienced planner in identifying, prioritizing, and satisfying critical information needs across dynamic operational environments.

Steady Counsel Under Pressure — Trusted advisor in high-tempo, high-consequence environments where clarity and composure determine outcomes.

Career Highlights:

🔹 Senior Staff Advisor — Shaped and led intelligence operations for a Service Cyber Command, directing collection, analysis, and integration in support of cyberspace operations.

🔹 Senior Technician, U.S. Army Cyber Command (ARCYBER) — Responsible for operational oversight and governance of intelligence programs supporting Army cyberspace operations.

🔹 U.S. Army Chief Warrant Officer 4, Signals Intelligence Analysis Technician (Retired) — Thirty years of service across intelligence and cyberspace operations disciplines.

Execution & Customer Focus:

⚙️ Owns the problem, not the ticket — Takes a customer requirement from first conversation to working capability without handing it off at the seams.

⚙️ Present with the customer, not behind them — Sits in the room, runs the demonstration, absorbs the hard questions directly, and brings the answer back into the product.

⚙️ Bias toward delivered work — Converts ambiguity into something concrete fast, then refines against real feedback rather than waiting for a perfect requirement.

⚙️ Closes the loop — Follows engagements through adoption and renewal, so what was promised in a demonstration is what the customer actually operates.

Education:

Defense Language Institute Foreign Language Center Bachelor of Arts, Foreign Language, Chinese Mandarin

Among the first graduates in DLIFLC history to receive the Bachelor of Arts in Foreign Language, and the first Soldier in the U.S. Army conferred the degree.

Greg Bew

CEO

CEO | Data Architecture & AI Strategy Leader | Cyber Operations & Decision Advantage Expert

Greg Bew is a technology and transformation leader with deep expertise in data architecture, cyber operations, and large-scale enterprise modernization. With over two decades of experience spanning military service and industry, Greg has led the design and implementation of mission-critical data platforms, advanced analytics capabilities, and AI-driven decision systems supporting national security and defense operations.

A retired U.S. Army Lieutenant Colonel, Greg served in key leadership roles across cyber and intelligence organizations, culminating as a Senior Advisor to the Commander of DoD Cyber Defense Command and the Director of DISA for Data, Analytics, and AI. In these roles, he helped shape the Joint Cyber Warfighting Architecture (JCWA), driving the transition toward data-centric operations and enabling decision advantage across distributed, contested environments.

As the Founder & CEO of Veritech Consulting, Greg applies this experience to help government and enterprise organizations design and operationalize modern data architectures. His work focuses on integrating cloud, AI/ML, and distributed data systems into cohesive, mission-aligned platforms that prioritize governance, scalability, and real-world operational impact.

Key Expertise & Accomplishments:

Data Architecture & Platform Engineering – Designed and led enterprise-scale data platforms enabling distributed analytics, AI integration, and real-time decision support across multi-domain environments.

Cyber Operations & Intelligence Integration – Extensive experience aligning data, analytics, and operational workflows to support cyber defense, intelligence fusion, and mission execution.

AI & Advanced Analytics Enablement – Spearheaded initiatives to operationalize AI/ML within secure environments, integrating model deployment, governance, and data pipelines at scale.

Strategic Leadership & Advisory – Served as a senior advisor to three-star leadership, shaping enterprise data strategy, governance models, and cross-organizational integration efforts.

Cloud & Distributed Systems Modernization – Led transitions from legacy architectures to cloud-native and federated data environments, emphasizing resilience, sovereignty, and performance.

Career Highlights:

🔹 Senior Advisor, DoD Cyber Defense Command & DISA – Guided enterprise data and AI strategy supporting the Joint Cyber Warfighting Architecture and global cyber operations.

🔹 Senior Principal Data Platform Engineer, Leidos – Delivered advanced data solutions and modernization strategies across defense and federal customers.

🔹 U.S. Army Lieutenant Colonel (Retired) – Led cyber, intelligence, and data-focused units, driving innovation in operational analytics and mission systems.

Thought Leadership & Innovation:

📘 Author of Sky Computing: The Architecture of Data Sovereignty, introducing a new model for governing data, authority, and computation in distributed environments.

🚀 Creator of frameworks and platforms focused on data sovereignty, federated control, and AI-enabled decision advantage.

📊 Advocate for data-centric operations, emphasizing the alignment of technology, governance, and mission outcomes.


Greg Bew continues to lead Veritech Consulting with a focus on delivering practical, high-impact solutions that help organizations navigate complex technology landscapes and achieve decisive advantage through data.

Liana Pannell

Director of Operations

Liana is a process-driven operations leader with nine years of experience in project management, technology program management, and business operations. She specializes in developing, scaling, and codifying workflows that drive efficiency, improve collaboration, and support long-term growth. Her expertise spans edtech, digital marketing solutions, and technology-driven initiatives, where she has played a key role in optimizing organizational processes and ensuring seamless execution.

With a keen eye for scalability and documentation, Liana has led initiatives that transform complex workflows into structured, repeatable, and efficient systems. She is passionate about creating well-documented frameworks that empower teams to work smarter, not harder—ensuring that operations run smoothly, even in fast-evolving environments.

Liana holds a Master of Science in Organizational Leadership with concentrations in Technology Management and Project Management from the University of Denver, as well as a Bachelor of Science from the United States Military Academy. Her strategic mindset and ability to bridge technology, operations, and leadership make her a driving force in operational excellence at VeriTech Consulting.

Keri Fischer

COO & Founder

Founder & COO | Cybersecurity & Data Analytics Expert | SIGINT & OSINT Specialist

Keri Fischer is a highly accomplished cybersecurity, data science, and intelligence expert with over 20 years of experience in Signals Intelligence (SIGINT), Open Source Intelligence (OSINT), and cyberspace operations. A proven leader and strategist, Keri has played a pivotal role in advancing big data analytics, cyber defense, and intelligence integration within the U.S. Army Cyber Command (ARCYBER) and beyond.

As the Founder & COO of VeriTech Consulting, Keri leverages extensive expertise in cloud computing, data analytics, DevOps, and secure cyber solutions to provide mission-critical guidance to government and defense organizations. She is also the Co-Founder of Code of Entry, a company dedicated to innovation in cybersecurity and intelligence.

Key Expertise & Accomplishments:

Cyber & Intelligence Leadership – Served as a Senior Technician at ARCYBER’s Technical Warfare Center, providing SME support on big data, OSINT, and SIGINT policies and TTPs, shaping future Army cyber operations.
Big Data & Advanced Analytics – Spearheaded ARCYBER’s Big Data Platform, enhancing cyber operations and intelligence fusion through cutting-edge data analytics.
Cybersecurity & Risk Mitigation – Excelled in identifying, assessing, and mitigating security vulnerabilities, ensuring mission-critical systems remain secure, scalable, and resilient.
Strategic Operations & Decision Support – Provided key intelligence support to Joint Force Headquarters-Cyber (JFHQ-C), Army Cyber Operations and Integration Center, and Theater Cyber Centers.
Education & Innovation – The first-ever 170A to graduate from George Mason University’s Data Analytics Engineering Master’s program, setting a new standard for data-driven military cyber operations.

Career Highlights:

🔹 Senior Data Scientist – Led groundbreaking all domain efforts in analytics, machine learning, and data-driven operational solutions.
🔹 Senior Technician, U.S. Army Cyber Command (ARCYBER) – Recognized as the #1 warrant officer in the command, driving big data analytics and cyber intelligence strategies.
🔹 Division Chief, G2 Single Source Element, ARCYBER – Directed 20+ analysts in SIGINT, OSINT, and cyber intelligence, influencing Army cyber policies and operational training.
🔹 Senior Intelligence Analyst, ARCYBER – Built the Army’s first OSINT training program, improving intelligence support for cyberspace operations.

Recognition & Leadership:

🛡️ Lauded as “the foremost expert in data analytics in the Army” by senior leadership.
📌 Key advisor to the ARCYBER Commanding General on all data science matters.
🚀 Led the development of ARCYBER’s first-ever OSINT program and cyber intelligence initiatives.

Keri Fischer is a visionary in cybersecurity, intelligence, and data science, continuously pushing the boundaries of technological innovation in defense and national security. Through her leadership at VeriTech Consulting, she remains dedicated to helping organizations navigate the complexities of emerging technologies and drive mission success in an evolving cyber landscape.

Education:

National Intelligence University Graphic

National Intelligence University

Master of Science – MS Strategic Intelligence

 – 

George Mason University Graphic

George Mason University

Master of Science – MS Data Analytics

 –