IndiaFocal.

India, in focus.

Business

Representative image · Photo: IndiaFocal
Representative image · Photo: IndiaFocal

US Firms Battle Surge in Cyberattacks as White House Plan Stalls

US companies face a wave of cyberattacks in 2025, from ransomware to data theft, as the White House's AI security coordination plan remains stalled.

American businesses are navigating a turbulent cybersecurity landscape this year, marked by a rise in AI-driven attacks and ransomware incidents that have disrupted operations and compromised sensitive data.

The White House announced last month an initiative to coordinate information sharing between AI developers and operators of critical infrastructure, aiming to address vulnerabilities identified by AI systems. However, no further details have been released, even as recent attacks have targeted AI firms like OpenAI and Anthropic.

A look at notable incidents reported by U.S. companies in 2025 reveals the breadth of the threat:

January saw the ransomware group World Leaks claim it published 1.4 terabytes of data from sportswear giant Nike. The company declined to comment on specifics or whether a ransom was paid. The same month, dating apps Bumble and Match Group, along with Crunchbase and Panera Bread, were hit by cyberattacks. Panera disclosed an incident involving contact information and notified authorities.

In February, casino operator Wynn Resorts reported that hackers obtained employee data and demanded around $1.5 million in bitcoin.

March brought a significant attack on medical device maker Stryker, claimed by an Iranian-linked hacking group. The attack disrupted order processing, manufacturing, and shipments globally, wiping remote Windows devices, though patient services remained unaffected. Separately, anime streaming service Crunchyroll saw hackers claim to have stolen personal data and 8 million support ticket records, including 6.8 million unique email addresses.

Toymaker Hasbro said in late March it was investigating unauthorized network access that forced some systems offline and warned of potential order fulfillment delays.

In April, OpenAI identified a security issue stemming from a third-party developer tool that executed a malicious version of Axios, but found no evidence of user data compromise. The same month, the ShinyHunters hacking group claimed to have stolen nearly 80 million business records from Rockstar Games, though the company said only a limited amount of non-material information was accessed.

Most recently, in May, medical equipment maker West Pharmaceutical Services reported a cyberattack involving data theft and system lockups that disrupted its manufacturing and logistics operations.