U.S. companies spanning retail, healthcare, technology, and financial services have faced a wave of cyberattacks in 2024, with incidents ranging from ransomware deployments to data theft and operational disruptions.
Nike disclosed a January attack by the World Leaks ransomware group, which published 1.4 terabytes of company data. On January 28, Bumble, Match Group, Crunchbase, and Panera Bread reported breaches, while Wynn Resorts confirmed a February incident where hackers demanded $1.5 million in bitcoin for employee data. Medical device maker Stryker faced a March attack by an Iranian-linked group that disrupted global order processing and manufacturing, though patient services remained unaffected.
The healthcare sector has been particularly targeted. Crunchyroll reported the theft of 8 million subscription records, including 6.8 million unique email addresses, in a March breach. West Pharmaceutical Services experienced a May attack that forced a global shutdown of manufacturing and logistics systems before restoration. In June, Novo Nordisk and iRhythm Holdings both reported unauthorized access to internal systems, with the latter facing a ransom demand following a social-engineering attack on a third-party vendor.
Educational technology firm Instructure’s Canvas platform was disrupted in May after a ShinyHunters-linked hack exposed data from nearly 9,000 institutions, though the group later claimed the stolen data was deleted. Law firm Blank Rome reported a May breach exposing personal information of 57,554 clients, while cruise operator Carnival disclosed a social-engineering attack compromising employee accounts.
Corporate targets have included Coca-Cola’s fairlife subsidiary, which suspended U.S. production in July before resuming operations across four facilities. Clover Health Investments and Abbott Laboratories also reported breaches in July, with the latter investigating unauthorized access to its cancer diagnostics systems. Consumer goods giant Levi Strauss confirmed a July breach where hackers extracted corporate data without disrupting operations.
Financial services and technology firms have not been spared. Uber’s Freight unit reported a data security incident in August, while GE and Fiserv were among nearly 50 global companies targeted by a hacking group exploiting software vulnerabilities. Apollo Global Management disclosed a breach in August, with unauthorized access to cloud platforms detected between July 6 and July 10.
Security researchers also identified a large-scale campaign in June targeting Fortinet firewall and VPN devices, compromising approximately 75,000 systems worldwide and leading to password theft at Fortune 500 companies and government agencies across more than 15 countries.
The White House announced plans in April to establish a coordination group for AI developers and critical infrastructure operators to address cybersecurity vulnerabilities, though no further details have been released.












