March 2025 has proven to be a stark reminder of the escalating cyber threats facing organizations across diverse sectors, from education and finance to healthcare and technology. This month’s data breach report reveals a series of alarming incidents. Each one highlights the vulnerabilities inherent in our increasingly interconnected digital landscape. They range from the massive exposure of applicant data at New York University to the alleged compromise of Oracle Cloud’s legacy systems, and the ransomware attacks targeting Jaguar Land Rover and the Pennsylvania State Education Association. The sheer scale and sensitivity of the data compromised underscore the urgent need for enhanced cybersecurity measures.
New York University
On March 22, 2025, New York University (NYU) experienced a significant data breach. A hacker redirected the university’s website and exposed the personal information of over 3 million applicants dating back to 1989.
- Scale of the Breach: The breach exposed the personal information of over 3 million applicants to NYU. This includes both accepted and rejected students.
- Type of Data Exposed: A wide range of sensitive personal details was compromised. That included names, test scores (SAT/ACT), GPAs, intended majors, demographic information, family backgrounds, and financial aid details.
- Cause of the Breach: The breach occurred due to unauthorized access to NYU’s IT systems. That allowed a hacker to redirect web traffic and access underlying databases containing applicant information
Oracle Cloud
The alleged Oracle Cloud data breach in March 2025 involved a significant cybersecurity incident. A threat actor claimed to have compromised approximately 6 million records from Oracle Cloud’s systems.
Oracle initially denied any compromise of its core Oracle Cloud infrastructure. But later reports indicate that Oracle has privately acknowledged to certain customers that a breach did occur, albeit affecting older “legacy environments.”
- Scale of the Breach: The threat actor claims to have compromised approximately 6 million records, potentially affecting over 140,000 Oracle Cloud tenants. That indicates a very broad impact.
- Type of Data Exposed: Highly sensitive credentials were reportedly exposed. These included Java KeyStore (JKS) files, encrypted passwords and password hashes, key files, and Java Process Status (JPS) keys. All of them could allow for significant unauthorized access.
- Cause of the Breach: There are conflicting reports. But evidence points to the exploitation of vulnerabilities within Oracle’s systems, possibly related to older “legacy enviroments” of Oracle cloud. It is potentially related to vulnerabilities within Oracle Fusion Middleware instances that could allow unauthorized access via Oracle Access Manager.
Jaguar Land Rover (JLR)
Jaguar Land Rover (JLR) experienced a significant data breach in March 2025, attributed to the HELLCAT ransomware group. It resulted in the exposure of internal documents, source code, tracking data, and employee credentials. The breach was facilitated by compromised login information, including credentials from an LG Electronics employee. That highlights the interconnectedness of supply chain vulnerabilities.
- Scale of the Breach: The breach involved the exfiltration of 700 documents in the first wave and 350 gigabytes of data in the second wave. It impacted internal operations and potentially compromised sensitive information.
- Type of Data Exposed: Compromised data included internal documents, source code, tracking data, and employee credentials. That poses risks to intellectual property and employee privacy.
- Cause of the Breach: The breach was caused by the exploitation of compromised credentials, including those obtained through infostealer malware. The HELLCAT ransomware group then used those credentials to gain access to JLR’s systems.
SpyX Stalkerware App
The SpyX stalkerware app data breach in March 2025 exposed highly sensitive personal information of nearly 2 million individuals. It raises serious privacy and safety concerns.
- Scale of the Breach: Nearly 2 million individuals were affected. That indicates a massive exposure of personal data from users of the SpyX stalkerware application.
- Type of Data Exposed: Highly sensitive data was exposed. It included iCloud usernames and passwords (in plaintext), email addresses, IP addresses, device information, and potentially messages and photos. That poses a significant risk to user privacy and security.
- Cause of the Breach: The breach resulted from a severe security lapse. Specifically, the app’s user database lacked proper authentication and protection. That made it easily accessible to unauthorized individuals.
Have I Been Pwned: haveibeenpwned.com
Angel One
Angel One is a major Indian stock brokerage firm. It disclosed a data breach in March 2025, revealing unauthorized access to client information stored in its Amazon Web Services (AWS) account. Angel One assured clients that their funds and securities remained secure. But the incident raised concerns about cybersecurity practices within the financial sector, and impacted the company’s stock value.
- Scale of the Breach: The scale of the breach involved the compromise of client information stored within Angel One’s AWS environment. The precise number of affected clients has not been publicly released.
- Type of Data Exposed: The exposed data consisted of client information held within the company’s AWS account. Angel one has not released the type of data. It is assumed to be contact information, and potentially financial information.
- Cause of the Breach: The breach resulted from unauthorized access to Angel One’s AWS account. The specific vulnerability exploited is still under investigation. But it shows a weakness within the security of their cloud storage.
Western Alliance Bank
Western Alliance Bank experienced a data breach in March 2025. It stemmed from the exploitation of a zero-day vulnerability in a third-party secure file transfer tool provided by Cleo. The Clop ransomware group gained unauthorized access, compromising the sensitive personal information of approximately 22,000 customers. The breach occurred in October 2024 but was disclosed in March 2025.
- Scale of the Breach: Approximately 22,000 customers’ personal information was compromised. That indicates a significant exposure of sensitive financial and personal data.
- Type of Data Exposed: The exposed data included highly sensitive information such as names, Social Security numbers, dates of birth, financial account numbers, driver’s license numbers, tax identification numbers, and passport information. That creates a substantial risk of identity theft.
- Cause of the Breach: The breach was caused by the exploitation of a zero-day vulnerability in a third-party secure file transfer tool provided by Cleo. That allowed the Clop ransomware group to gain unauthorized access to Western Alliance Bank’s systems.
Pennsylvania State Education Association
The Pennsylvania State Education Association (PSEA) is a labor union representing public school employees. It experienced a significant data breach in March 2025, impacting over 500,000 individuals. The Rhysida ransomware group claimed responsibility for the attack. It resulted in the exposure of highly sensitive personal information.
- Scale of the Breach: Over 500,000 individuals were affected. That includes current and former members and their dependents, making it a very large scale data breach.
- Type of Data Exposed: The compromised data included highly sensitive information such as Social Security numbers, driver’s license and state ID numbers, financial account information, payment card details, passport numbers, medical information, and taxpayer ID numbers. That significantly increases the risk of identity theft.
- Cause of the Breach: The breach was caused by a ransomware attack carried out by the Rhysida ransomware group. They gained unauthorized access to PSEA’s systems and exfiltrated sensitive data.
California Cryobank
California Cryobank (CCB) is a company specializing in sperm and egg donation services. It experienced a data breach in March 2025, revealing unauthorized access to customer data from April 2024. The breach was discovered in October 2024. CCB began sending out data breach notification letters to affected individuals in March 2025.
- Scale of the Breach: The scale of the breach involved the potential compromise of customer data stored within CCB’s IT environment, affecting individuals who have used their services.
- Type of Data Exposed: The exposed data included sensitive personal information such as names, driver’s license numbers, bank account and routing numbers, Social Security numbers (SSN), and health insurance information. That poses a significant risk of identity theft and privacy violations.
- Cause of the Breach: The breach was caused by unauthorized access to CCB’s IT environment. The specific vulnerability exploited is still under investigation. It resulted in the potential access and/or acquisition of files containing customer data.
Data Breach Notification: maine.gov
Numotion
Numotion is a provider of complex rehabilitation technology. It experienced a significant data breach in March 2025. The breach stemmed from unauthorized access to employee email accounts between September and November 2024.
- Scale of the Breach: Nearly half a million individuals were affected, demonstrating a large-scale exposure of sensitive data.
- Type of Data Exposed: The compromised data included full names, dates of birth, payment information, financial account information, product information, health insurance details, medical information, driver’s license numbers, and Social Security numbers. That encompasses a wide range of highly sensitive personal and medical data.
- Cause of the Breach: The breach resulted from unauthorized access to employee email accounts, likely due to phishing attacks. That allowed attackers to access and exfiltrate sensitive customer information.
Data Breach Notification: numotion.com
