Key facts
- Nike reported a ransomware group published 1.4 terabytes of data.
- Bumble, Match Group, and Crunchbase were hit by cyberattacks.
- Wynn Resorts disclosed hackers obtained employee data and demanded $1.5 million in bitcoin.
- Stryker experienced a cyberattack disrupting global operations, claimed by an Iranian-linked group.
- Hasbro is investigating a cybersecurity incident that took some systems offline.
- OpenAI identified a security issue after a third-party developer tool executed a malicious version of itself.
Companies worldwide are facing an escalating threat from AI-driven cyberattacks and ransomware, which are increasingly used to steal sensitive data and disrupt operations. The White House announced in July the formation of a coordination group involving AI developers and critical infrastructure operators to share information on cybersecurity vulnerabilities identified by AI systems, though specific details of this initiative have not yet been released.
Several U.S. companies have reported significant cyber incidents this year. In January, Nike disclosed that the ransomware group World Leaks published 1.4 terabytes of its data, with the company declining to comment on specifics or ransom payments. Also in January, Bloomberg News reported cyberattacks affecting Bumble, Match Group, and Crunchbase, while Panera Bread notified authorities of an incident involving contact information.
February saw Wynn Resorts report that hackers obtained employee data and demanded approximately $1.5 million in bitcoin. In March, an Iranian-linked hacking group claimed responsibility for an attack on Stryker that disrupted global order processing, manufacturing, and shipments, though the company stated patient services remained unaffected. Crunchyroll reported that hackers stole personal data and 8 million support ticket records, including 6.8 million email addresses. Hasbro began investigating a cybersecurity incident that led to unauthorized network access and system outages, warning of potential order fulfillment delays.
In April, OpenAI identified a security issue stemming from a malicious third-party developer tool, but found no evidence of compromised user data. Take-Two Interactive's Rockstar Games unit was targeted by the ShinyHunters group, which claimed to have stolen nearly 80 million business records by exploiting a third-party breach; Rockstar stated only a limited amount of non-material company information was accessed.
May saw West Pharmaceutical Services report a cyberattack involving data theft and system lockups that disrupted global manufacturing and logistics. Instructure, the developer of the Canvas learning management system, disclosed a hack that exposed student and school data from thousands of institutions, but later reached an agreement with the hacking group to delete the data without extortion. Law firm Blank Rome reported that a cybercriminal group tricked an attorney into uploading files, exposing personal information of over 57,000 clients. Carnival disclosed a social-engineering attack that compromised an employee account, exposing personal information.
In June, Novo Nordisk reported unauthorized actors copied information from its internal IT systems, including limited clinical trial patient data. Medtech firm iRhythm Holdings stated a threat actor obtained sensitive data through a social-engineering attack on third-party applications, later issuing a payment demand. AdaptHealth reported a threat actor stole patient information and insurance billing passwords after compromising a third-party contractor's account. Researchers also noted a large-scale hacking campaign targeting Fortinet firewall and VPN devices, compromising approximately 75,000 systems worldwide.
July incidents included Coca-Cola's fairlife subsidiary temporarily suspending U.S. production due to unauthorized system access, though most production later resumed. Health insurer Clover Health Investments reported a hacker accessed employee accounts, potentially exposing personal health information. Abbott Laboratories is investigating unauthorized access to internal systems in its cancer diagnostics business, expecting no material impact.
In August, Levi Strauss reported unauthorized third-party access to corporate information without disrupting business operations. Uber's Uber Freight unit is investigating a data security incident involving unauthorized access to a portion of its systems, with a spokesperson stating business operations remain unaffected.
