Attacks on US firms have moved from stealing data to stopping production

Reuters’ running tally of US corporate cyber attacks in 2026 shows social engineering, contractor accounts and healthcare targets recurring.


Cyber attack pixel art. Anonymous hacker with laptop, 8-bit error warning and virus danger alert signs on digital dithering texture. Data breach, system intrusion and cybercrime vector illustration

US corporate cyber attacks in 2026.

Image Credits Credit: fim.design via Shutterstock

Reuters has been keeping a running tally of American companies breached during 2026, and read end to end, it is more instructive than any single entry in it.

The names run from Nike and Coca-Cola to Novo Nordisk and Abbott Laboratories, and almost none of the incidents involve the kind of exotic technique that Google’s discovery of an AI-developed zero-day made everyone worry about.

What recurs instead is social engineering, usually aimed at a third party. Carnival, Clover Health, iRhythm, and AdaptHealth were all reached that way, in several cases through contractor accounts rather than the companies’ own staff.

That is the vulnerability the industry has been slowest to close, because it does not sit inside anyone’s perimeter. A supplier with access to your systems is a security dependency you cannot patch, and the attacker only has to be convincing on the phone.

One group appears repeatedly. ShinyHunters claimed 80 million business records from Take-Two Interactive and Rockstar Games in April, then breached Instructure’s Canvas platform in May in an incident affecting close to 9,000 institutions.

The second of those matters more than the record count suggests. Canvas is the learning platform a large share of American universities run on, so a single compromise reached student data across thousands of separate organisations that had each done nothing wrong themselves.

Healthcare and pharmaceuticals appear more often than any other sector. Stryker, West Pharmaceutical Services, Novo Nordisk, iRhythm, AdaptHealth, and Abbott all feature, which is consistent with a pattern of medical data being both valuable and comparatively poorly defended, as a breach exposing 1.8 million people’s records, including fingerprints demonstrated separately this year.

The more consequential shift is from theft to stoppage. Stryker had order processing, manufacturing, and shipments disrupted globally by an Iranian-linked group, West Pharmaceutical reported system lockups halting operations, Hasbro warned of fulfilment delays lasting weeks, and Coca-Cola’s fairlife division suspended production outright.

An attack that stops a production line is a different proposition to one that copies a database. It creates immediate revenue loss and a public consequence, which is also why it commands a higher ransom.

Consumer brands dominate the headlines and tell you the least. Nike had 1.4 terabytes published by a group calling itself World Leaks, Wynn Resorts faced a demand worth about $1.5mn in bitcoin, and Crunchyroll lost eight million support records, all of which is embarrassing and none of which stops anything.

Some entries are not companies at all. A campaign against Fortinet compromised roughly 75,000 firewall and VPN devices worldwide, which is an attack on the equipment organisations bought specifically to prevent this.

Running through nearly every disclosure is the same phrase about no material impact on operations. That formulation is doing considerable work, because it is a securities-disclosure judgement about financial materiality rather than a statement about whether anyone’s data is now for sale.

Size is no protection either, and may be the wrong variable entirely. Research has found mid-sized businesses losing more to cybercrime than either large or small ones, caught between having assets worth stealing and lacking the security budget of a multinational.

The contrast with Europe is instructive on attribution. German industry association Bitkom, working with the country’s domestic intelligence service, attributes 46% of externally identified attacks each to Russia and China, whereas the American list is dominated by named criminal crews with one Iranian-linked exception.

That difference probably says more about who is doing the attributing than about who is attacking. Criminal groups claim their work publicly because publicity is part of the extortion, while state operations are identified by intelligence services or not at all.

The White House has set up a coordination group on vulnerabilities identified by AI systems, without much detail on how it will work.

Whether that addresses a list dominated by phone calls to contractors is a fair question, and one the governance-first approach to security AI is at least asking.

Get the TNW newsletter

Get the most important tech news in your inbox each week.