Stock Markets August 26, 2026 07:42 AM

U.S. Firms Report Growing Wave of AI-Linked Cyber Intrusions and Ransomware

From apparel and healthcare to finance and industrials, companies report breaches tied to sophisticated tools and social-engineering campaigns

By Derek Hwang
Share
Twitter Reddit Facebook LinkedIn
NKE BMBL MTCH WYNN

Companies across multiple U.S. sectors have disclosed a steady stream of cyber incidents this year, many involving AI-driven tools, ransomware groups or social-engineering attacks. The White House has said it launched a coordination group last month to help AI developers and critical infrastructure operators share vulnerability information, but it has provided no further details. The incidents listed below — spanning from January through late August — include data theft, operational disruptions and extortion demands, affecting businesses in retail, healthcare, leisure, finance and manufacturing.

U.S. Firms Report Growing Wave of AI-Linked Cyber Intrusions and Ransomware
NKE BMBL MTCH WYNN
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • A wide variety of U.S. companies have disclosed cyber incidents this year, including data theft, ransomware and operational disruptions.
  • Reported attacks have used multiple vectors, including exploitation of third-party tools and social-engineering schemes that compromise employee accounts.
  • The incidents affect many sectors, notably healthcare, consumer goods, financial services, industrials and technology, showing the broad market exposure to cyber risk.

Companies in the United States are reporting an escalating cadence of cyberattacks this year, with incidents ranging from ransomware and data theft to intrusions that temporarily disrupted manufacturing and order processing. Federal officials announced last month that the White House had formed a coordination group intended to facilitate information sharing between AI developers and critical infrastructure operators about cybersecurity vulnerabilities identified by AI systems. No further details about that group have been disclosed publicly since the announcement, even as hacks affecting AI agents developed by OpenAI and Anthropic have been reported.

Below is a chronological compilation of U.S. companies that have publicly reported cyber incidents so far this year, along with the details each company provided.


January

  • Jan. 26 - Nike - A ransomware organization named World Leaks said on its website that it had published 1.4 terabytes of data taken from Nike. Nike declined to comment on specifics of the investigation or whether any ransom payment was made.
  • Jan. 28 - Bumble, Match, Panera Bread Group, Crunchbase - Media reports indicated cyberattacks affecting Bumble and Match Group and also naming Panera Bread Group and Crunchbase. Panera Bread publicly disclosed an incident that involved contact information and said it had notified authorities.

February

  • Feb. 24 - Wynn Resorts - The company said hackers gained access to employee data and that an investigation was underway. Attackers reportedly demanded the equivalent of about $1.5 million in bitcoin.

March

  • March 11 - Stryker - A group with links to Iran claimed responsibility for an attack that disrupted order processing, manufacturing and shipments worldwide. The company said the incident wiped remote devices running the Windows operating system but that patient services and connected medical products were unaffected.
  • March 12 - Crunchyroll - Hackers claimed to have stolen personal data and 8 million support ticket records from the anime streaming service, including 6.8 million unique email addresses, according to reporting cited by cybersecurity outlets.
  • March 28 - Hasbro - The toymaker reported unauthorized access to its network that took some systems offline. Hasbro warned the disruption could cause order fulfillment delays lasting several weeks as it investigated the incident.

April

  • April 10 - OpenAI - OpenAI said it identified a security issue after a third-party developer tool caused a GitHub workflow to download and execute a malicious version of a popular library. The company said it found no evidence that user data, systems or intellectual property were compromised.
  • April 13 - Take-Two - The ShinyHunters hacking group claimed it stole nearly 80 million records tied to Rockstar Games by exploiting a third-party breach involving an analytics provider. Rockstar said only a limited amount of non-material company information was accessed.

May

  • May 4 - West Pharmaceutical Services - The medical equipment maker reported a cyberattack involving data theft and system lockups that disrupted manufacturing and logistics operations globally. The company took systems offline and later restored operations across manufacturing, supply chain and commercial sites.
  • May 11 - Instructure/Canvas - Instructure, developer of the Canvas learning management system used by many schools, said an attack linked to the ShinyHunters group disrupted access and exposed student and school data from nearly 9,000 institutions. The company said it reached an agreement in which the attacking group claimed the stolen data was deleted and customers would not be extorted.
  • May 21 - Blank Rome - The law firm said a cybercriminal group that impersonated its IT department tricked an attorney into uploading files, exposing personal information for 57,554 current, former and prospective clients, according to a proposed class action lawsuit.
  • May 27 - Carnival - The cruise operator said a social-engineering attack compromised an employee account and exposed personal data including names, addresses and government identification numbers. Carnival said it blocked the unauthorized access and notified affected individuals.

June

  • June 11 - Novo Nordisk - The maker of Wegovy said unauthorized actors copied information from internal IT systems, including limited clinical trial patient data. Novo Nordisk launched an investigation and temporarily shut down certain internal systems but said core operations were unaffected.
  • June 15 - iRhythm Holdings - The medtech company said a threat actor acquired potentially sensitive data, including proprietary information and patient health information, following a social-engineering attack on third-party-hosted business applications, and later issued a payment demand. The company said patient care, medical device systems and operations were unaffected.
  • June 15 - AdaptHealth - The company reported that a threat actor stole patient information and insurance billing passwords after compromising a third-party contractor account via social engineering, which allowed access to cloud-based business applications and internal patient management systems.
  • June 17 - Fortinet - Researchers reported a wide-ranging campaign that targeted Fortinet firewall and VPN devices, compromising roughly 75,000 systems worldwide. The campaign reportedly led to password theft at Fortune 500 companies and government agencies across more than 15 countries.

July

  • July 16 - Coca-Cola Co (fairlife) - Coca-Cola said that its fairlife business temporarily suspended U.S. production operations after unauthorized access to parts of its systems, including production-related systems. By July 27, Coca-Cola said fairlife had resumed most production at four U.S. facilities while restoration efforts continued.
  • July 17 - Clover Health - The insurer said a hacker used social engineering to access three employee accounts, potentially exposing some personal and protected health information. The company said it does not expect a material operational impact.
  • July 17 - Abbott Laboratories - Abbott reported it was investigating unauthorized access to a limited number of internal systems within its cancer diagnostics business and a possible breach of its LabCentral portal, and said it expected no material impact on operations, customers or financial results.

August

  • Aug. 7 - Levi Strauss - The apparel maker said an unauthorized third party gained access to its systems and exfiltrated certain corporate information. Levi said business operations were not disrupted and it expected no material impact. The company was listed among dozens of financial institutions and other firms targeted in July by ransom-seeking attackers using phone calls to compromise victims, according to reporting that cited internet intelligence data.
  • Aug. 11 - Uber - Uber said its Uber Freight unit was investigating a data security incident involving unauthorized access to part of its systems and repositories. A company spokesperson said there was no impact to Uber Freight’s business operations and that systems were secure and fully operational.
  • Aug. 13 - GE, Fiserv and others - A prolific hacking group that exploits software vulnerabilities claimed it had stolen large volumes of data from nearly 50 companies worldwide, naming targets including Philips, Shell, Fiserv and General Electric.
  • Aug. 21 - Apollo Global Management - The asset manager said it suffered a data breach in which hackers stole some personal information. Apollo reported unauthorized access to certain cloud platforms between July 6 and July 10, notified law enforcement and engaged outside cybersecurity and forensic experts.
  • Aug. 26 - Boston Scientific - Boston Scientific said it detected a cybersecurity incident on Aug. 25 that disrupted global operations, including information systems used to process and ship customer orders. The company said it activated incident-response procedures and was working with third-party cybersecurity specialists to investigate and contain the threat.

The incidents documented above illustrate a range of attack vectors, from exploitation of third-party software and analytics providers to social-engineering schemes that compromise employee credentials. In several cases companies emphasized that critical operations or patient services were not affected, while others reported temporary suspension of production or shipping delays. A number of the breaches resulted in reported theft or publication of corporate or customer data.

Many affected firms said they notified authorities, engaged external cybersecurity and forensic experts, and took steps to restore systems and contain the incidents. Some companies reported extortion demands or publication of stolen files by criminal groups. In at least one instance, a company reported attackers sought payment in cryptocurrency.

Federal efforts to coordinate information sharing around AI-discovered vulnerabilities were announced but remain opaque in their public disclosures. The White House said it had launched a coordination group for AI developers and critical infrastructure operators, but no further public details have been provided, even as incidents involving AI agents have been reported.

As companies continue to disclose incidents through the year, the reported cases span a broad cross-section of the economy: retail and consumer brands, healthcare and medical device makers, software and platform providers, law firms and financial services, travel and leisure operators, and industrial and manufacturing firms. The breadth of affected sectors underscores the interconnected nature of modern corporate IT environments and supply chains.

Risks

  • Operational disruption - Several companies reported halted production, disrupted manufacturing or shipping delays, which could affect supply chains in industrials and consumer sectors.
  • Data exposure and extortion - Multiple incidents involved theft of corporate or personal data and subsequent extortion demands, posing legal, regulatory and reputational risks for firms in healthcare, financial services and professional services.
  • Third-party dependencies - Several breaches exploited third-party developer tools or contractor accounts, highlighting ongoing vulnerabilities in supply-chain and vendor relationships across technology and service providers.

More from Stock Markets

Kohl’s Shares Drop After Q2 Results Show Continued Sales Weakness Despite EPS Beat Aug 26, 2026 Kohl’s Falls Short on Quarterly Sales as Consumers Trim Discretionary Spending Aug 26, 2026 Spanish Airbus Employees Restart Indefinite Strike After Rejecting Pay and Conditions Offer Aug 26, 2026 Target Hospitality Stock Jumps After Win With Major Hyperscaler for West Texas Data Center Aug 26, 2026 Spyre Therapeutics Shares Plunge After RA Sub-Study Falls Short of Internal Threshold Aug 26, 2026