Massive Ransomware Attack Targets Critical Infrastructure in March 2026

Massive Ransomware Attack Targets Critical Infrastructure in March 2026

First seen 11 Mar 2026, 18:15 UTC Arstechnica 74.0

Article Content

Browse articles
ThreatCluster

In March 2026, a sophisticated ransomware attack impacted multiple critical infrastructure sectors, including energy and healthcare. The attack utilized a variant of the notorious 'LockBit' ransomware, exploiting vulnerabilities in outdated systems. Over 500 organizations were affected, leading to significant operational disruptions and data breaches. The attackers demanded ransoms totaling over $50 million, threatening to leak sensitive data if not paid. Security teams have identified CVE-2025-6789 as a key vulnerability exploited during the attack, prompting urgent patching efforts. The FBI has issued a warning, advising organizations to enhance their cybersecurity measures. As of now, many organizations are still recovering, with some systems remaining offline. The situation is evolving, with ongoing investigations into the attack's origin and the perpetrators.

Key Points: • Over 500 organizations in critical sectors affected by ransomware attack. • Attackers used LockBit ransomware, exploiting CVE-2025-6789. • FBI has issued warnings and organizations are urged to enhance cybersecurity.

Timeline

2026-03-01
Ransomware attack begins targeting critical infrastructure.
2026-03-05
FBI issues warning about the ongoing ransomware campaign.
2026-03-10
Organizations report significant operational disruptions.
2026-03-11
CVE-2025-6789 identified as a key vulnerability exploited.