Assaults on US companies have shifted from data theft to halting production.

Assaults on US companies have shifted from data theft to halting production.

      Reuters has been tracking American companies that experienced breaches throughout 2026, and when examined in its entirety, the data is more enlightening than any individual incident.

      The list includes names like Nike, Coca-Cola, Novo Nordisk, and Abbott Laboratories, and very few incidents involve the kind of unconventional techniques that people feared after Google unveiled an AI-generated zero-day vulnerability. Instead, social engineering is the common tactic employed, usually targeting third parties. Companies such as Carnival, Clover Health, iRhythm, and AdaptHealth were compromised this way, often via contractor accounts rather than directly through their own employees.

      This represents a vulnerability that the industry has been slow to address since it lies outside of any company’s direct control. A supplier granted access to your systems presents a security risk that cannot be easily mitigated, as attackers only need to be persuasive over the phone.

      One particular group frequently appears in these breaches. ShinyHunters claimed to have obtained 80 million business records from Take-Two Interactive and Rockstar Games in April and then compromised Instructure’s Canvas platform in May, impacting nearly 9,000 institutions. The latter incident is particularly significant because Canvas serves as the learning platform for a large number of American universities, meaning a single breach could expose student data across many separate organizations that had done nothing wrong.

      The healthcare and pharmaceutical sectors show up more often than others. Stryker, West Pharmaceutical Services, Novo Nordisk, iRhythm, AdaptHealth, and Abbott are all included, reinforcing a trend of medical data being both highly valuable and relatively poorly protected, as exemplified by a breach revealing the records of 1.8 million individuals, including fingerprints, earlier this year.

      A noteworthy trend is the shift from data theft to operational disruption. Stryker faced global interruptions in order processing, manufacturing, and shipments due to an Iranian-linked group, while West Pharmaceutical reported system lockups that halted operations. Hasbro warned of fulfillment delays lasting weeks, and Coca-Cola’s fairlife division even ceased production altogether. An attack that halts production is fundamentally different from one that simply copies data; it results in immediate revenue loss and public ramifications, which is also why it typically demands a higher ransom.

      Consumer brands tend to dominate the headlines while providing the least insight. Nike had 1.4 terabytes of data leaked by a group called World Leaks, Wynn Resorts was faced with a demand for approximately $1.5 million in bitcoin, and Crunchyroll lost eight million support records. While these incidents are distressing, they do not directly affect operations.

      Some entries in the report do not even concern companies. A campaign against Fortinet compromised around 75,000 firewall and VPN devices globally, which is an attack on the very equipment organizations purchase to prevent such breaches.

      Most disclosures contain the same phrase about having no material impact on operations. This wording carries significant weight, as it reflects a securities-disclosure judgement regarding financial materiality, rather than indicating whether anyone’s data is available for sale.

      Size offers no immunity, and may even be an inaccurate parameter. Research indicates that mid-sized companies suffer greater losses from cybercrime than both large and small firms, as they are caught in a situation where they possess valuable assets to steal but lack the security budgets of larger multinationals.

      The contrast with Europe provides insight into attribution. According to German industry association Bitkom, in collaboration with the country’s domestic intelligence service, 46% of externally identified attacks are attributed to Russia and China, while the American list is mainly composed of named criminal groups, with one notable Iranian-linked exception.

      This disparity likely reflects more about the entities doing the attributing than the attackers themselves. Criminal organizations often announce their activities publicly as part of their extortion strategy, while state-sponsored operations are typically identified by intelligence agencies or remain completely unacknowledged.

      The White House has established a coordination group to address vulnerabilities identified by AI systems, though details on its operation remain sparse.

      It raises a valid question as to whether this initiative will tackle a list predominantly characterized by phone-based exploits targeting contractors, which is something that the governance-first approach to security AI is beginning to question.

Other articles

Game of Thrones: War for Westeros places the destiny of the Iron Throne in your control. Game of Thrones: War for Westeros places the destiny of the Iron Throne in your control. PlaySide Studios unveiled the initial gameplay trailer for Game of Thrones: War for Westeros at Gamescom 2026. This officially licensed real-time strategy game is set to launch on PC through Steam in early 2027. Alabama is requesting the identities of all individuals at OpenAI who expressed safety concerns. Alabama is requesting the identities of all individuals at OpenAI who expressed safety concerns. The subpoena from Alabama, which contains 16 requests, seeks all safety concerns that staff have ever reported regarding any model test, as indicated in the document. A law enacted in 1634 is the reason Europeans are unable to collectively sue Big Tech companies. A law enacted in 1634 is the reason Europeans are unable to collectively sue Big Tech companies. According to Politico, Ireland prohibits third-party litigation funding as per a statute from 1634, and to date, only a single collective action against Big Tech has been initiated in the country. Attacks on American companies have shifted from data theft to disrupting production. Attacks on American companies have shifted from data theft to disrupting production. Reuters' ongoing count of corporate cyber attacks in the US for 2026 indicates that social engineering, contractor accounts, and healthcare targets are frequently involved. The stealth model that surpassed DeepSeek is from Zhipu. The stealth model that surpassed DeepSeek is from Zhipu. According to Bloomberg, Zhipu has verified that Ox Alpha is a new GLM model, after researchers analyzed its fingerprints and discovered that censorship is focused on seven specific topics. The new shooter from PUBG appears completely wild, and I must admit, I'm somewhat fond of it. The new shooter from PUBG appears completely wild, and I must admit, I'm somewhat fond of it. PUBG Studios has announced DED.NET, a new multiplayer first-person shooter that blends shooting gameplay with roguelite advancement in an unusual 1990s Cascadia environment.

Assaults on US companies have shifted from data theft to halting production.

Reuters' ongoing count of US corporate cyber attacks in 2026 indicates that social engineering, contractor accounts, and healthcare targets are frequently occurring.