Attacks on US Firms Evolve: From Data Theft to Production Disruption
Reuters’ running tally of US corporate cyber attacks in 2026 reveals a shift from data theft to stopping production. The common themes include social engineering, contractor accounts, and healthcare targets.
Recurring Issues
- Social Engineering: Targeting third parties, including contractors, is a prevalent tactic. Companies like Carnival, Clover Health, iRhythm, and AdaptHealth fell victim to this.
- Contractor Accounts: Access by suppliers poses significant security risks as they are beyond the company’s perimeter.
- Healthcare Sector: Industries such as healthcare and pharmaceuticals appear frequently on the list, with examples including Stryker, West Pharmaceutical Services, Novo Nordisk, and Abbott Laboratories.
Notable Incidents
- ShinyHunters: Breached Take-Two Interactive and Rockstar Games in April, followed by Instructure’s Canvas platform in May, impacting thousands of institutions.
- Stryker: Suffered disruptions in order processing, manufacturing, and shipments globally due to an Iranian-linked group.
- West Pharmaceutical Services: Reported system lockups halting operations.
- Hasbro: Faced fulfilment delays lasting weeks.
- Coca-Cola (fairlife division): Suspended production outright.
Shift from Theft to Disruption
The more significant trend is the shift from stealing data to stopping production lines, leading to immediate revenue loss and public consequences. Examples include:
- Nike: Leaked 1.4 terabytes of data by a group called World Leaks.
- Wynn Resorts: Faced a ransom demand of approximately $1.5 million in bitcoin.
- Crunchyroll: Lost eight million support records.
Broader Impact
Some incidents involve non-company targets, such as a campaign against Fortinet that compromised 75,000 firewall and VPN devices worldwide. Despite many disclosures stating no material impact on operations, data breaches can have significant financial and reputational consequences.
Size doesn’t offer protection, and the definition of "materiality" in cybersecurity disclosures often focuses on financial impact rather than data exposure.