Knowledge

State of (in)security - Week 13, 2026

Take action: Treat AI browser extensions as extremely dangerous high-privilege agents. If you use the Claude Chrome Extension, make sure it's updated to version 1.0.41 or higher immediately! Older versions allow attackers to silently hijack your browser session and access your email, documents, and chat history without any clicks. Review what permissions the extension has and stay alert for suspicious sites that may have exploited this before the patch.


Learn More

In the week between March 23, 2026, midnight and March 30, 2026, midnight we witnessed a total of:

  • 16 advisory/vulnerability events
  • 32 incident/data breach events

Week over Week comparison of week 13 2026 vs week 12 2026

We also shared 3 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 14,620,622 impacted individuals across 10 incidents, with the largest breach being the Crunchyroll Supply Chain Breach: 100GB of Subscriber Data Allegedly Leaked via BPO Partner incident exposing 6,800,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks11
Third Party Compromise4
Software Vulnerability and SDLC Exploits3
Unauthorized access3
Social Engineering and Phishing2

Industry breakdown of incidents

IndustryNumber of incidents
Healthcare7
Government6
IT/Software/Technology4
Transport/Logistics3
Entertainment/Leisure3
Non-profit/Charity2
Education1
Insurance1
Consulting/Professional Services1
Retail1
Telecommunications1
Finance1
Automotive1

 

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 13, 2026