It used to be rare to see news stories about cyberattacks. These are now happening once a week. In 2026, dozens of large US businesses have disclosed hacks that have compromised customer information to stocked shutdowns. These are the guys who are quicker. The tools are "smarter. The spread is happening in all sectors, including hospitals, and toy manufacturers.
AI Is Changing How Cyberattacks Happen
A new twist to the rise of cyberattacks this year. AI is now being applied in every facet of the battle. The change has been recognized by federal officials, who have suggested a coordination group to enable AI infrastructure operators and developers to exchange information on vulnerabilities AI systems discover. Although the concept is good, the specifics are not yet clear even as incidents involving AI agents have already emerged.
For businesses, it's clear cut. The traditional approach of using firewalls and password schemes is not sufficient anymore. The attackers are advancing at a quicker pace than the security teams can keep up, using automation to identify vulnerabilities.
Ransomware Keeps Stealing Sensitive Data
Ransomware is still the most prevalent and expensive threat. But Nike got hit early in the year, when a ransomware organization posted over a terabyte of data from the company online. Hasbro was the victim of intrusions that could have delayed the fulfillment of orders for weeks. When a leak caused a disruption in its manufacturing processes, Boston Scientific had to stop shipments but later restarted at its largest distribution points.
In these cases there is a pattern. No longer are ransomware groups merely encrypting files. They reportedly take the sensitive information and then demand ransom or they purport to divulge it if it is not paid. That is why it is better for many businesses to come up with a deal without filing a lawsuit.
Social Engineering Is the Weak Link
Not everything is always technology! People are. Some of this year's largest data leaks began with a phone call or an email that fooled the recipient into clicking a link. Personal information such as government ID numbers was lost because an employee's account was compromised via social engineering during Carnival. Three employee accounts were used in the same manner by Clover Health. Both AdaptHealth and iRhythm Holdings highlighted approaches to access third-party enterprise applications that store patient information.
The incident at Astrana Health was similar in September. Attacks came via spoofed phone numbers and employees were fooled into allowing access. A good lie can't be stopped with a firewall. This is why security teams are allocating more resources to training their employees to identify manipulation in addition to using only technical defenses.
Healthcare and Manufacturing Are Taking the Hardest Hits
In fact, two sectors are prominent this year. Healthcare businesses are usually the victim of massive amounts of sensitive patient information, making them constant targets. Novo Nordisk, Abbott Laboratories, NovoCure and AdaptHealth were all found to have had events involving patient or clinical information. A new pressure has been placed on manufacturing. A hacking group wiped devices running Windows from all over the world disrupting Stryker's operations. An attack caused West Pharmaceutical Services to have to take systems offline, impacting parts of its supply chain.
Common denominator = disruption of operations. A data breach is bad enough on its own. If it does the same to halt shipments or production lines, then the effects on the money quickly multiply.
Third-Party Vendors Are the Hidden Risk
There were multiple breaches this year that were not initiated inside the target company. Rockstar Games suffered a loss of business records from an outside analytics company. Google's threat intelligence teams identified dozens of businesses that were attacked using social engineering via phone calls, including Levi Strauss. Fortinet's firewall and VPN devices were targeted in a massive-scale attack on some 75000 systems worldwide, including Fortune 500 companies and government agencies.
The reality for most businesses today. It is possible for a company to secure its own network and be breached via a vendor, a contractor or a piece of hardware it trusted.
What Companies Can Do Right Now
But that doesn't mean businesses are helpless. There were a number of common traits among these fastest-claiming companies. They were prepared for an attack with incident response plans in place. They restricted access of any individual employee or vendor to sensitive systems. They also conducted regular training for their employees to detect social engineering attacks through damage.
Securing the internet in 2026 isn't a question of whether you can construct one wall that is completely impenetrable. It's about expecting the attack and ensuring it is dealt with in a timely way if it should occur. The fastest bounce-back firms on this list were those that had already made contingency plans.
