Key facts
- Companies globally are experiencing a surge in AI-driven cyberattacks and ransomware.
- The White House is establishing a coordination group to address AI-identified cybersecurity vulnerabilities.
- Numerous US companies, including Nike, Bumble, Match Group, Wynn Resorts, Stryker, Hasbro, and Coca-Cola's fairlife, have reported cyber incidents this year.
- Attacks have involved data theft, system disruptions, ransomware demands, and exposure of sensitive personal and patient information.
- Some companies have taken systems offline or experienced production delays as a result of these incidents.
Companies worldwide are facing an escalating wave of AI-driven cyberattacks and ransomware incidents that are stealing sensitive data and disrupting business operations. In response, the White House has initiated a coordination group comprising AI developers and critical infrastructure operators to enhance information sharing on cybersecurity vulnerabilities and to coordinate responses.
This year has seen numerous U.S. companies report or be affected by cyber incidents. In January, Nike disclosed that a ransomware group published 1.4 terabytes of its data. The same month, Bumble, Match Group, and Crunchbase were reportedly hit by cyberattacks, while Panera Bread notified authorities of an incident involving contact information.
February saw Wynn Resorts report a hack that obtained employee data, with attackers demanding approximately $1.5 million in bitcoin. In March, Stryker experienced disruptions to its global operations, including order processing and manufacturing, following a cyberattack claimed by an Iranian-linked group. Crunchyroll reported that hackers stole personal data and millions of support ticket records. Hasbro investigated unauthorized access to its network, leading to system outages and potential order fulfillment delays.
OpenAI identified a security issue related to a third-party developer tool but stated no user data was compromised. Take-Two Interactive's Rockstar Games claimed hackers stole business records by exploiting a third-party breach. West Pharmaceutical Services faced disruptions to manufacturing and logistics due to a cyberattack involving data theft. Instructure, the developer of Canvas, reported a hack that exposed data from thousands of educational institutions.
In May, law firm Blank Rome disclosed that a cybercriminal group exposed personal information of over 57,000 clients. Carnival reported a social-engineering attack compromised an employee account, exposing personal details. Novo Nordisk stated unauthorized actors copied information from its internal IT systems, including limited clinical trial patient data. iRhythm Holdings and AdaptHealth also reported data theft and system compromises resulting from social-engineering attacks on third-party applications or contractors.
In June, researchers revealed a large-scale campaign targeting Fortinet devices compromised about 75,000 systems globally. Coca-Cola's subsidiary fairlife temporarily suspended U.S. production due to unauthorized system access, though most operations have since resumed. Clover Health Investments and Abbott Laboratories are investigating incidents involving unauthorized access to employee accounts and internal systems, respectively, with both expecting minimal operational impact.
