[Risk Nodus] Weekly Intelligence Brief: March 16, 2026


As an antidote to historical siloed risk management methods, we investigate the Ten Domains of Risk framework, which all organizations should consider incorporating into their risk management plans.

Risk Nodus Weekly Intelligence Brief

ShinyHunters Claims Near-Petabyte Haul from Telus Digital

Telus Digital confirmed on March 12, 2026, that attackers gained unauthorized access to a limited number of systems, after ShinyHunters claimed to have stolen nearly 1 petabyte of data in a months-long intrusion. The group alleges it used Google Cloud Platform credentials exposed in the earlier Salesloft Drift breach to access BigQuery and pivot across Telus environments, affecting BPO customer data, call records, source code, and voice recordings. Telus says operations remain unaffected; forensic experts and law enforcement are engaged, and impacted customers are being notified as the investigation continues.

Guard Deflects Point-Blank Shot at Former Chief Minister Farooq Abdullah

President of the Jammu and Kashmir National Conference and former Minister of New and Renewable Energy of India, Farooq Abdullah, survived an apparent assassination attempt on Wednesday evening at a wedding in Jammu city, where CCTV footage showed a gunman firing at point-blank range and being deflected by a close-protection guard. Police said the suspect, Kamal Singh Jamwal, is in custody and the case remains under investigation. The incident raises acute concerns over political violence and protective failures, as Abdullah is covered by India’s top-tier Z+ security detail. His son, current chief minister Omar Abdullah, publicly questioned how an armed attacker reached such close proximity.

Atlassian Cuts 1,600 Jobs and Replaces CTO under AI-Driven Restructure

Atlassian announced on 11 March 2026 that it will cut about 1,600 jobs, roughly 10% of its workforce, as part of a restructuring to expand artificial intelligence and enterprise sales capabilities. More than 900 affected roles are in software research and development, with layoffs concentrated in North America, Australia, and India. The company also said CTO Rajeev Rajan will step down at the end of March. While management said AI is not directly replacing staff, it acknowledged automation is changing skill requirements as Atlassian seeks to reduce losses and accelerate its path to breakeven.

PhantomRaven Returns: Malicious npm Packages Deploy Credential-Stealing Malware

Researchers reported on 12 March 2026 that the PhantomRaven software supply-chain campaign has resurfaced on npm with 88 malicious packages published between November 2025 and February 2026, 81 of which remained live at the time of reporting. The operation uses remote dynamic dependencies to fetch credential-stealing malware from attacker-controlled servers during installation, bypassing standard package scans. Endor Labs said the malware targets developer and CI/CD credentials across platforms, including GitHub Actions, GitLab CI, Jenkins, and CircleCI, while active command-and-control infrastructure and exfiltration routines undermine claims that the packages were merely research artifacts.

Two Dead in French Listeria Outbreak Traced to Tradition Charcuterie

French authorities reported on 13 March 2026 that a Listeria outbreak linked to meat products from Drôme Ardèche Tradition caused 12 confirmed illnesses and two deaths. Positive samples were collected between mid-September 2025 and 23 January 2026, and no new cases have been reported since mid-February. All patients were hospitalized, and 11 were aged 65 or older, with a median age of 81. Epidemiological and traceability investigations linked several cases to pâté en croûte, while the Institut Pasteur confirmed a genetic match between patient samples and products from the company’s Bourg-de-Péage site, bringing about a full product recall and a plant suspension.

Luxembourg Court Voids €746M GDPR Fine Against Amazon

Amazon won a substantial legal reprieve on 13 March 2026 after a Luxembourg court annulled the record €746 million ($854.4 million) GDPR fine imposed by the country’s privacy regulator in 2021 over online behavioral advertising practices. The court held that the National Commission for Data Protection had not properly assessed whether Amazon’s conduct was intentional or negligent and had failed to evaluate alternative sanctions before issuing the penalty. The regulator must now reassess the case, leaving Amazon’s compliance position improved for now but preserving regulatory uncertainty around any revised enforcement outcome.

Wiper Attack on Stryker Marks Iran's First Confirmed Strike on a U.S. Company

Stryker disclosed on 12 March 2026 that a cyberattack disrupted its global Microsoft environment, in what appears to be the first significant Iran-linked attack on a U.S. company since the start of the current conflict. The Iran-associated Handala Team claimed responsibility, and available evidence suggests the attackers may have accessed Microsoft Intune to remotely wipe employee devices, including work phones, resulting in operational and communications disruption. Stryker said the incident was contained, with no ransomware detected and no direct compromise of its core systems, but the event signals a sharper escalation in retaliatory cyber activity.

China Is Shifting Entirely to Nuclear Submarine Construction

Rear Adm. Mike Brookes, the U.S. Navy’s intelligence director, said in testimony in early March 2026 that China is shifting from a diesel-electric submarine force toward increasingly nuclear-powered construction, marking a significant long-term change in PLA Navy force design. China currently operates more than 60 submarines, including at least 14 nuclear-powered boats, and U.S. projections indicate the fleet could reach about 70 by 2027 and around 80 by 2035, with roughly half nuclear-powered. The transition, supported by expanded shipyard capacity and new classes such as the Type 095 and Type 096, would materially extend China’s endurance, range, and strategic deterrent reach.

Nidec Chairman and CFO Resign as Accounting Scandal Spreads

Nidec said it may record ¥250 billion ($1.6 billion) in impairment charges as an accounting scandal widens, exposing at least 1,000 instances of improper accounting across its operations. The fallout has triggered the resignations of Chairman Hiroshi Kobe, CFO Akinobu Samura, and Executive Vice President Yoshihisa Kitao, while CEO Mitsuya Kishida has pledged governance reforms and salary forfeitures. The crisis, spanning subsidiaries in Italy, Switzerland, and China, and the automotive inverter business, has already delayed financial filings, prompted a Moody’s downgrade to junk, and raised the risk of delisting from the Tokyo Stock Exchange.

Russia Running a Campaign to Hijack Signal and WhatsApp Accounts of Officials

Dutch intelligence services MIVD and AIVD warned on 9 March 2026 that Russian state actors are running a large-scale global campaign targeting Signal and WhatsApp users, with a focus on government officials, military personnel, and journalists. Rather than using malware, the operators rely on phishing, fake support messages, malicious QR codes, and abuse of linked-device features to hijack accounts and monitor communications. In Signal cases, victims may regain access and wrongly assume nothing happened, while compromised WhatsApp accounts may remain silently accessible to attackers, raising persistent counterintelligence and operational security concerns.

Organizations must stay vigilant and adopt proactive methods to predict and manage risk across various domains. By understanding and addressing the Ten Domains of Risk, organizations can not only protect themselves from potential threats but also position themselves for growth and success in a competitive marketplace.

The Risk Nodus Pulse delivers cross-domain intelligence on emerging threats and strategic shifts. Speak with our team about how Presage Global leverages predictive risk intelligence services to help you expect the unexpected and make well-informed decisions. Contact us today.


Know someone who would be interested in subscribing to Risk Nodus? Forward this email and invite them to join.

Edward V. Marshall, Founder & CEO

Presage Global

600 1st Ave, Ste 330 PMB 92768, Seattle, WA 98104-2246
Unsubscribe · Preferences

Presage Global

For family office leaders and executive protection professionals committed to resilience. Subscribe for discreet insights, strategic risk guidance, and exclusive access to Presage Global’s intelligence-driven tools and programs.

Read more from Presage Global
Risk Nodus

As an antidote to historical siloed risk management methods, we investigate the Ten Domains of Risk framework, which all organizations should consider incorporating into their risk management plans. Risk Nodus Weekly Intelligence Brief AssuranceAmerica Breach Exposes 6.9M US Driver’s Licenses AssuranceAmerica revealed a major cyberattack that impacted approximately 6.99 million individuals, stating hackers gained access to customers’ names, contact information, driver’s license numbers,...

Risk Nodus

As an antidote to historical siloed risk management methods, we investigate the Ten Domains of Risk framework, which all organizations should consider incorporating into their risk management plans. Risk Nodus Weekly Intelligence Brief Third-Party Failure Puts 3.1M Texas License Holders at Identity-Risk The Texas Parks and Wildlife Department disclosed that a breach at an external licensing system vendor has exposed personal information of 3,087,721 hunting and fishing license customers....

Risk Nodus

As an antidote to historical siloed risk management methods, we investigate the Ten Domains of Risk framework, which all organizations should consider incorporating into their risk management plans. Risk Nodus Weekly Intelligence Brief Global Fortinet Credential Leak Creates Persistent Network Access Risk A large campaign called “FortiBleed” compromised the credentials of about 75,000 Fortinet FortiGate firewalls. The campaign targeted firewalls in 194 countries, with India, the U.S., and...