Key facts
- Companies globally are facing a surge in AI-driven cyberattacks and ransomware.
- The White House is coordinating AI developers and critical infrastructure operators on cybersecurity vulnerabilities.
- Numerous US companies, including Nike, Bumble, Match Group, Wynn Resorts, Stryker, Hasbro, and Coca-Cola's fairlife, have reported cyber incidents this year.
- Attacks have involved data theft, system disruptions, and ransom demands.
- Some companies have taken systems offline or suspended operations due to these incidents.
Companies worldwide are facing a significant increase in AI-driven cyberattacks and ransomware incidents that compromise sensitive data and disrupt operations. In response, the White House announced in July the formation of a coordination group involving AI developers and critical infrastructure operators to share information on cybersecurity vulnerabilities identified by AI systems, though specific details have yet to be released.
Numerous U.S. companies have reported cyber incidents throughout the year. In January, Nike disclosed a ransomware attack where a group claimed to have published 1.4 terabytes of data. Bumble, Match Group, and Crunchbase were also hit by cyberattacks, while Panera Bread notified authorities of an incident involving contact information. Wynn Resorts reported a hack that obtained employee data, with attackers demanding approximately $1.5 million in bitcoin.
In March, Stryker experienced a cyberattack claimed by an Iranian-linked group that disrupted its global operations, and Crunchyroll reported the theft of personal data and millions of support ticket records. Hasbro investigated a cybersecurity incident that led to unauthorized network access and system outages, warning of potential order fulfillment delays. OpenAI identified a security issue stemming from a third-party developer tool but found no evidence of compromised user data. Take-Two Interactive's Rockstar Games reported the theft of nearly 80 million business records.
May saw several incidents, including West Pharmaceutical Services facing a cyberattack that disrupted manufacturing and logistics, and Instructure/Canvas reporting a hack that exposed student and school data from thousands of institutions. The law firm Blank Rome disclosed a data exposure affecting over 57,000 clients, and Carnival experienced a social-engineering attack that compromised an employee account. Novo Nordisk reported unauthorized actors copied information from its internal IT systems, including limited clinical trial patient data.
Further incidents in June included iRhythm Holdings reporting the theft of sensitive data and AdaptHealth stating patient information and passwords were stolen after a third-party contractor's account was compromised. Researchers noted a large-scale hacking campaign targeting Fortinet devices compromised approximately 75,000 systems globally. In July, Coca-Cola's subsidiary fairlife temporarily suspended U.S. production due to unauthorized system access, and Clover Health Investments reported a hacker accessed employee accounts. Abbott Laboratories is investigating unauthorized access to internal systems in its cancer diagnostics business. In August, Levi Strauss reported unauthorized access and extraction of corporate information, and Uber's Freight unit is investigating a data security incident.
