Companies in the United States are confronting a notable uptick in cyberattacks this year, many of them leveraging artificial intelligence tools or seeking ransom through data theft and system disruption. In July, the White House said it had launched a coordination group intended to connect AI developers with operators of critical infrastructure so they can share information about cybersecurity vulnerabilities identified by AI systems. To date, officials have not published further details about the group’s work, even as high-profile incidents involving AI agents have been reported.
The list below compiles U.S. companies that have publicly reported cyber incidents in 2024, organized by the dates the companies disclosed the events or were reported to have been affected.
Incident log
-
January 26 - Nike
A ransomware group calling itself World Leaks said on its website that it had published 1.4 terabytes of Nike data. The company declined to comment on specifics of its investigation or whether a ransom payment had been made.
-
January 28 - Bumble, Match, Panera Bread Group, Crunchbase
Cyberattacks were reported to have affected Bumble and Match, while Panera Bread disclosed an incident involving customer contact information and notified authorities. Crunchbase also reported being hit, according to media reports.
-
February 24 - Wynn Resorts
Wynn said hackers obtained employee data, which prompted an investigation. The attackers demanded what the company reported as the equivalent of about $1.5 million in bitcoin.
-
March 11 - Stryker
An Iranian-linked hacking group claimed responsibility for a cyberattack that disrupted Stryker’s order processing, manufacturing and shipments worldwide. The group said it wiped remote devices running the Windows operating system. The medical device maker said services for patients and connected medical products remained unaffected.
-
March 12 - Crunchyroll
Hackers asserted they stole personal data and 8 million support ticket records from the subscription-based anime streaming service, including 6.8 million unique email addresses, according to reporting.
-
March 28 - Hasbro
The toymaker said it was investigating unauthorized access to its network that took some systems offline and warned the disruption could lead to order fulfillment delays lasting several weeks.
-
April 10 - OpenAI
OpenAI identified a security issue after a third-party developer tool called Axios caused a GitHub workflow to download and execute a malicious version of Axios. OpenAI said it found no evidence that user data, systems or intellectual property were compromised.
-
April 13 - Take-Two
The ShinyHunters group claimed to have stolen nearly 80 million Rockstar Games business records by exploiting a third-party breach involving analytics provider Anodot. Take-Two said only a limited amount of non-material company information was accessed.
-
May 4 - West Pharmaceutical Services
West said a cyberattack that involved data theft and system lockups disrupted manufacturing and logistics operations globally. The company reported taking systems offline and later restoring operations across manufacturing, supply chain and commercial sites.
-
May 11 - Instructure/Canvas
Instructure, the developer of the Canvas learning management system, reported a ShinyHunters-linked hack that disrupted access and exposed student and school data from nearly 9,000 institutions. The company said an agreement was reached under which the hacking group claimed the stolen data was deleted and that customers would not be extorted.
-
May 21 - Blank Rome
The law firm said a cybercriminal group posing as the firm’s IT department tricked an attorney into uploading files, exposing personal information for 57,554 current, former and prospective clients, according to a proposed class action lawsuit.
-
May 27 - Carnival
The cruise operator disclosed a social-engineering attack that compromised an employee account and exposed personal information including names, addresses and government-issued identification numbers. The company said it blocked unauthorized access and notified affected individuals.
-
June 11 - Novo Nordisk
The maker of Wegovy said unauthorized actors copied information from its internal IT systems, including limited clinical trial patient data. The incident prompted an investigation and temporary shutdown of certain internal systems, and the company said core operations were unaffected.
-
June 15 - iRhythm Holdings
iRhythm said a threat actor obtained potentially sensitive data, including proprietary information and patient health information, after a social-engineering attack on third-party-hosted business applications. The company said it received a payment demand but that patient care, medical device systems and operations were unaffected.
-
June 15 - AdaptHealth
AdaptHealth reported a social-engineering attack that compromised a third-party contractor’s account, enabling a threat actor to access cloud-based business applications and internal patient management systems and to steal patient information and insurance billing passwords.
-
June 17 - Fortinet
Researchers reported a large-scale campaign targeting Fortinet firewall and VPN devices that compromised about 75,000 systems globally. The campaign was linked to password theft at Fortune 500 companies and government agencies across more than 15 countries.
-
July 16 - Coca-Cola Co (fairlife)
Coca-Cola said fairlife temporarily suspended U.S. production operations after unauthorized access to parts of its systems, including production-related systems. On July 27, Coca-Cola said fairlife had resumed most production at four U.S. facilities while efforts to restore affected operations continued.
-
July 17 - Clover Health
Clover reported that a hacker used social engineering to access three employee accounts, potentially exposing some personal and protected health information. The company said it did not expect a material impact on operations.
-
July 17 - Abbott Laboratories
Abbott said it was investigating unauthorized access to a limited number of internal systems in its cancer diagnostics business and a potential breach of its LabCentral portal, but it expected no material impact on operations, customers, or financial results.
-
August 7 - Levi Strauss
Levi Strauss said an unauthorized third party accessed its systems and extracted certain corporate information. The company said business operations were not disrupted and it expected no material impact. The denim maker was listed among dozens of U.S. financial institutions and other businesses targeted in July by ransom-seeking hackers who used phone calls to compromise victims, according to internet intelligence data reviewed by reporters.
-
August 11 - Uber (Uber Freight)
Uber said its Uber Freight unit was investigating a data security incident involving unauthorized access to parts of its systems and repositories. A spokesperson said there was no impact to Uber Freight’s business operations, which continued without disruption, and that its systems were secure and fully operational.
-
August 13 - GE, Fiserv and others
A prolific hacking group known for exploiting software vulnerabilities to attack multiple targets simultaneously claimed to have stolen large volumes of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv and GE.
-
August 21 - Apollo Global Management
Apollo said it suffered a data breach in which hackers stole some personal information. The firm said an investigation found unauthorized access to certain cloud platforms between July 6 and July 10, and that it had notified law enforcement and engaged outside cybersecurity and forensic experts.
-
August 26 - Boston Scientific
Boston Scientific detected a cybersecurity incident on August 25 that disrupted manufacturing and order shipments. In a September 3 update, the company said it had resumed shipping most products from major global distribution centers, though a backlog remained. The breach appeared limited to some internal IT systems with no known impact on implanted cardiac devices.
-
September 1 - NovoCure Limited
Novocure said it became aware of unauthorized access to some systems in mid-August. Exposed data included internal company ID numbers for more than 1,400 U.S. patient records, data for fewer than 50 other patients in the western U.S. that included additional identifying information, and general contact details for healthcare providers and Novocure.
Context and observations
The incidents cataloged here span multiple sectors - consumer brands, healthcare and medical devices, legal services, education technology, cruise and leisure, and transportation logistics. Many of the reported attacks involved social-engineering methods or exploited vulnerabilities in third-party software and services. Several resulted in temporary shutdowns of internal systems, disruption to manufacturing and shipping schedules, or exposure of personal and corporate data.
Federal coordination efforts announced in July aim to improve information sharing when AI systems surface cybersecurity vulnerabilities, but no operational details of the coordination group have been released publicly as of the latest company disclosures. The timeline of reported incidents suggests threat actors continue to find avenues into corporate systems, including third-party providers and cloud platforms.
Key points
- AI-related cybersecurity concerns prompted a White House coordination group announcement in July, but officials have not disclosed further details about the group’s activities.
- Companies from healthcare, consumer goods, manufacturing and services have all reported incidents this year, with several describing operational disruptions to manufacturing, logistics and order fulfillment.
- Many attacks involved social engineering or exploitation of third-party software and cloud platforms, highlighting vulnerabilities in vendor and supply chain technology relationships.
Risks and uncertainties
- Ongoing vulnerability of third-party providers and cloud platforms - several incidents traced back to third-party breaches or compromised contractor accounts, affecting multiple sectors including healthcare, education technology and manufacturing.
- Operational disruption risk for manufacturing and logistics - a number of companies reported manufacturing stoppages or temporary suspension of production and shipping, which can affect supply chains and downstream customers in retail and healthcare.
- Incomplete federal coordination details - while the White House announced a coordination group for AI and critical infrastructure cybersecurity, the lack of public detail leaves uncertainty about how effectively information will be shared and acted upon.
Conclusion
The string of cyber incidents disclosed by U.S. companies in 2024 illustrates the breadth of targets and tactics used by threat actors, from ransomware and data theft to social-engineering campaigns and exploitation of vulnerabilities in third-party services. Firms across multiple industries have reported disruptions to systems and operations, and many continue to investigate the full scope and impact of the intrusions. Federal efforts to coordinate information sharing between AI developers and infrastructure operators have been announced but remain unspecified publicly, even as incidents tied to AI-related tools and processes are reported.