Key facts
- Companies globally are facing an increasing number of AI-driven cyberattacks and ransomware incidents.
- The White House is coordinating efforts between AI developers and critical infrastructure operators to share cybersecurity vulnerability information.
- Numerous U.S. companies, including Nike, Bumble, Match Group, Wynn Resorts, Stryker, Hasbro, and Coca-Cola's fairlife, have reported cyber incidents this year.
- Attacks have resulted in data theft, disruption of operations, and demands for ransom.
- Some companies have taken systems offline and are investigating breaches, while others report no material impact on operations.
Companies across the United States are increasingly falling victim to sophisticated cyberattacks, including ransomware and data theft, often amplified by artificial intelligence. The White House has acknowledged the growing threat and stated it is coordinating efforts between AI developers and critical infrastructure operators to share information on cybersecurity vulnerabilities, though specific details have yet to be released.
Numerous U.S. companies have reported significant cyber incidents throughout the year. In January, Nike disclosed that a ransomware group published 1.4 terabytes of its data. Bumble, Match Group, Crunchbase, and Panera Bread also experienced cyberattacks, with Panera Bread notifying authorities about an incident involving contact information. Wynn Resorts reported a hack that compromised employee data and led to a ransom demand of approximately $1.5 million in bitcoin.
Further incidents include an attack on medical device maker Stryker in February, claimed by an Iranian-linked group, which disrupted global operations. In March, Crunchyroll reported the theft of personal data and millions of support ticket records, while toymaker Hasbro investigated unauthorized network access that caused system disruptions. Rockstar Games, a subsidiary of Take-Two Interactive, confirmed a breach involving stolen business records due to a third-party exploit.
In May, West Pharmaceutical Services experienced a cyberattack that disrupted manufacturing and logistics. Instructure, the developer of the Canvas learning management system, reported a hack exposing student and school data from thousands of institutions. Law firm Blank Rome disclosed a breach affecting client information, and cruise operator Carnival reported a social-engineering attack that compromised an employee account.
More recent incidents include Novo Nordisk reporting unauthorized access to internal systems containing limited clinical trial patient data, and iRhythm Holdings and AdaptHealth reporting data theft through social-engineering attacks. Researchers also identified a large-scale campaign targeting Fortinet devices, impacting thousands of systems globally. Coca-Cola's subsidiary fairlife temporarily halted U.S. production due to unauthorized system access. Health insurer Clover Health Investments and healthcare firm Abbott Laboratories are investigating breaches, while denim maker Levi Strauss reported corporate information extraction without operational disruption.
