CYBERATTACKS ON THE RISE
Companies grappling with data breaches as AI empowers hackers
Companies worldwide are grappling with a surge in artificial intelligence-driven cyberattacks and ransomware that steal sensitive data and disrupt operations.
The White House said it would launch a group of AI developers and critical infrastructure operators to share information on cybersecurity vulnerabilities and coordinate responses.
Here is a list of reported incidents this year:
Jan. 26
Ransomware group World Leaks said on its website that it published 1.4 terabytes of data from Nike, which declined to comment on the specifics of its investigation or whether it paid a ransom.
Jan. 28
Cyberattacks hit Bumble, Match Group and Crunchbase, Bloomberg News reported, while Panera Bread disclosed an incident involving contact information and notified authorities.
Feb. 24
Hackers obtained employee data, Wynn Resorts said, prompting an investigation; the attackers demanded the equivalent of about $1.5 million in bitcoin.
March 11
An Iranian-linked hacking group claimed responsibility for a cyberattack on Stryker that disrupted order processing, manufacturing and shipments globally, wiping remote devices running the Windows operating system, though the medical device maker said patient services and connected medical products were unaffected.
March 12
Hackers claimed they stole personal data and 8 million support ticket records of the subscription-based anime streaming service Crunchyroll, BleepingComputer reported.
March 28
The toymaker Hasbro said it was investigating a cybersecurity incident that involved unauthorized access to its network, took some systems offline and warned the disruption could cause order fulfillment delays.
April 10
OpenAI said it identified a security issue after a third-party developer tool called Axios caused a GitHub workflow to download and execute a malicious version of Axios, but said it found no evidence that user data, systems or intellectual property were compromised.
April 13
The ShinyHunters hacking group claimed it stole nearly 80 million business records from Take-Two Interactive's Rockstar Games by exploiting a third-party breach involving analytics provider Anodot. Rockstar said only a limited amount of non-material company information was accessed.
May 4
Medical equipment maker West Pharmaceutical Services said a cyberattack involving data theft and system lockups disrupted manufacturing and logistics operations globally, and it temporarily took systems offline.
May 11
Instructure, the developer of educational learning management system Canvas, said a ShinyHunters-linked hack disrupted access and exposed student and school data from almost 9,000 institutions. In an agreement, the group said the stolen data was deleted and customers would not be extorted.
May 21
Law firm Blank Rome said a cybercriminal group tricked an attorney into uploading files, exposing personal information of 57,554 current, former and prospective clients, according to a proposed class-action lawsuit.
May 27
Carnival said a social-engineering attack compromised an employee account, exposing personal information including names, addresses and government-issued identification numbers, before the cruise operator blocked the unauthorized access.
June 11
Drugmaker Novo Nordisk said unauthorized actors copied information from its internal IT systems, including limited clinical trial patient data, prompting an investigation and the temporary shutdown of certain internal systems; it said core operations were unaffected.
June 15
The medtech firm iRhythm Holdings said a threat actor obtained potentially sensitive data, including proprietary and patient health information, through a social-engineering attack on third-party-hosted business applications and issued a payment demand.
June 15
AdaptHealth said a "threat actor" stole patient information and insurance billing passwords after a social-engineering attack compromised a third-party contractor's account, gaining access to cloud-based business applications and internal patient management systems.
June 17
Researchers said a hacking campaign targeting Fortinet firewall and VPN devices compromised about 75,000 systems worldwide, leading to password theft at Fortune 500 companies and government agencies in more than 15 countries.
July 16
The beverages giant Coca-Cola Co. said its dairy company Fairlife temporarily suspended U.S. production operations after unauthorized access to parts of its systems.
July 17
The health insurer Clover Health Investments said a hacker used social engineering to access three employee accounts, potentially exposing some personal and protected health information. Healthcare firm Abbott Laboratories said it was investigating unauthorized access to some internal systems in its cancer diagnostics business and a potential breach of its LabCentral portal.


