Factbox-US companies face rise in cyber attacks
Figurines with computers and smartphones are seen in front of the words "Cyber Attack" in this illustration taken, February 19, 2024. REUTERS/Dado Ruvic/Illustration
Sept 4 (Reuters) - Companies worldwide are grappling with a surge in AI-driven cyberattacks and ransomware that steal sensitive data and disrupt operations.
The White House in July said it was launching a coordination group for AI developers and critical infrastructure operators to share information on cybersecurity vulnerabilities identified by AI systems. But it has released no details since, despite recent hacks by OpenAI and Anthropic AI agents.
Here is a list of U.S. companies that have reported or been affected by cyber incidents this year.
Date Company Details
January 26 Nike Ransomware group
World Leaks said
on its website
that it had
published 1.4
terabytes of data
from Nike. The
company declined
to comment on the
specifics of its
investigation or
on whether any
ransom was paid.
January 28 Bumble, Match Cyberattacks hit
Group, Crunchbase Bumble, Match
and Panera Bread Group and
Crunchbase,
Bloomberg News
reported, while
Panera Bread
disclosed an
incident involving
contact
information and
notified
authorities.
February 24 Wynn Resorts Hackers obtained
employee data, the
company said,
prompting an
investigation,
while the
attackers demanded
the equivalent of
about $1.5 million
in bitcoin.
March 11 Stryker An Iranian-linked
hacking group
claimed
responsibility for
a cyberattack on
Stryker that
disrupted order
processing,
manufacturing and
shipments
globally, wiping
remote devices
running the
Windows operating
system, though the
medical device
maker said patient
services and
connected medical
products remained
unaffected.
March 12 Crunchyroll Hackers claimed
they stole
personal data and
8 million of the
subscription-based
anime streaming
service's support
ticket records,
including 6.8
million unique
email addresses,
BleepingComputer
reported.
March 28 Hasbro The toymaker said
it was
investigating a
cybersecurity
incident that
involved
unauthorized
access to its
network, took some
systems offline,
and warned the
disruption could
cause order
fulfillment delays
for several weeks.
April 10 OpenAI OpenAI said it
identified a
security issue
after a
third-party
developer tool
called Axios
caused a GitHub
workflow to
download and
execute a
malicious version
of Axios, but said
it found no
evidence that user
data, systems or
intellectual
property were
compromised.
April 13 Take-Two The ShinyHunters
Interactive's hacking group
Rockstar Games claimed it stole
nearly 80 million
Rockstar Games
business records
by exploiting a
third-party breach
involving
analytics provider
Anodot. Rockstar
said only a
limited amount of
non-material
company
information was
accessed.
May 4 West The medical
Pharmaceutical equipment
Services maker said a
cyberattack
involving data
theft and system
lockups disrupted
manufacturing and
logistics
operations
globally,
prompting it to
take systems
offline before
restoring
operations across
its manufacturing,
supply chain and
commercial sites.
May 11 Instructure/Canvas Instructure, the
developer of
Canvas, a widely
used educational
learning
management system,
said a
ShinyHunters-linke
d hack disrupted
access and exposed
student and school
data from nearly
9,000
institutions,
before reaching an
agreement under
which the group
said the stolen
data was deleted
and customers
would not be
extorted.
May 21 Blank Rome The law firm said
a cybercriminal
group posing as
the firm’s IT
department tricked
an attorney into
uploading files,
exposing personal
information of
57,554 current,
former and
prospective
clients, according
to a proposed
class action
lawsuit.
May 27 Carnival The cruise
operator said a
social-engineering
attack compromised
an employee
account, exposing
personal
information
including names,
addresses and
government-issued
identification
numbers, before
the company
blocked the
unauthorized
access and
notified affected
individuals.
June 11 Novo Nordisk The Wegovy maker
said unauthorized
actors copied
information from
its internal IT
systems, including
limited clinical
trial patient
data, prompting an
investigation and
the temporary
shutdown of
certain internal
systems, though it
said core
operations were
unaffected.
June 15 iRhythm Holdings The medtech firm
said a threat
actor obtained
potentially
sensitive data,
including
proprietary
information and
patient health
information,
through a
social-engineering
attack on
third-party-hosted
business
applications and
later issued a
payment demand,
while the company
said patient care,
medical device
systems and
operations were
unaffected.
June 15 AdaptHealth The company said a
"threat actor"
stole patient
information and
insurance billing
passwords after a
social-engineering
attack compromised
a third-party
contractor’s
account, gaining
access to
cloud-based
business
applications and
internal patient
management
systems.
June 17 Fortinet Researchers said a
large-scale
hacking campaign
targeting Fortinet
firewall and VPN
devices
compromised about
75,000 systems
worldwide, leading
to password theft
at Fortune 500
companies and
government
agencies across
more than 15
countries.
July 16 Coca-Cola Co The beverages
giant said
fairlife had
temporarily
suspended U.S.
production
operations after
unauthorized
access to parts of
its systems,
including
production-related
systems. On July
27, Coca-Cola said
fairlife resumed
most of the
production at four
U.S. facilities,
while efforts to
restore affected
operations
continued.
July 17 Clover Health The health insurer
Investments said a hacker used
social engineering
to access three
employee accounts,
potentially
exposing some
personal and
protected health
information,
though it does not
expect a material
impact on
operations.
July 17 Abbott The healthcare
Laboratories firm said it is
investigating
unauthorized
access to a
limited number of
internal systems
in its cancer
diagnostics
business and a
potential breach
of its LabCentral
portal, but
expects no
material impact on
operations,
customers, or
financial results.
August 7 Levi Strauss The denim maker
said an
unauthorized third
party gained
access to its
systems and
extracted certain
corporate
information,
though the
incident did not
disrupt business
operations and the
company expected
no material
impact. The denim
maker was among
dozens of
prominent U.S.
financial
institutions and
other businesses
targeted in July
by ransom-seeking
hackers who use
phone calls to
compromise
victims, according
to Google and
internet
intelligence data
reviewed by
Reuters.
August 11 Uber The ride-hailing
firm said its Uber
Freight unit was
investigating a
data security
incident involving
unauthorized
access to a
portion of its
systems and
repositories.
There was "no
impact to Uber
Freight's business
operations, which
continue in the
normal course
without
disruption,"
spokesperson Sam
Hallock said,
adding its systems
were secure and
fully
operational.
August 13 GE, Fiserv A prolific hacking
group known for
exploiting
software
vulnerabilities to
attack multiple
targets
simultaneously
claimed it had
stolen large
volumes of data
from nearly 50
companies
worldwide,
including Philips,
Shell, Fiserv and
GE.
August 21 Apollo Global The asset manager
Management suffered a data
breach last month
in which hackers
stole some
personal
information,
according to a
letter, with its
investigation
finding there was
unauthorized
access to certain
cloud platforms
between July 6 and
July 10. The firm
said it notified
law enforcement
and engaged
outside
cybersecurity and
forensic experts
to investigate the
breach.
August 26 Boston Scientific The medical device
maker said a
cybersecurity
incident detected
on August 25 had
disrupted
manufacturing and
order shipments.
In a September 3
update, the
company said it
had resumed
shipping most
products from
major global
distribution
centers, though a
backlog remained.
The breach
appeared limited
to some internal
IT systems, with
no known impact on
implanted cardiac
devices.
September 1 NovoCure Limited The oncology
company said it
became aware of
unauthorized
access to some
systems in
mid-August.
Exposed data
included internal
company ID numbers
for over 1,400
U.S. patient
records, data for
fewer than 50
other patients in
the western U.S.
that included
additional
identifying
information and
general contact
details for
healthcare
providers and
Novocure.
(Reporting by Anhata Rooprai, Sanskriti Shekhar, Neil J Kanatt, Puyaan Singh, Sriparna Roy and Kunal Das in Bengaluru; Editing by Nivedita Bhattacharjee, Tasim Zahid, Maju Samuel and Jonathan Ananda)
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- Meta bull case increasingly playing out, Mizuho says
- Goldman: 'Our key conclusion is that AI is likely to be credit-positive for banks', 'Rearming Our Overweight Stance on Banks'
- Willdan to buy Mantis Innovation for $285M in cash
Create E-mail Alert Related Categories
ReutersRelated Entities
Hasbro, Earnings, BitcoinSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share