Informa TechTarget
|
Cybersecurity Dive
InformationWeek
Channel Dive
TechTarget:网络安全
探索我们的品牌
Dark Reading 资源库
Black Hat 新闻
Omdia 网络安全
广告合作
通讯订阅
网络安全主题
世界
边缘计算
DR Technology
活动
资源
网络攻击与数据泄露
网络风险
威胁情报
ICS/OT 安全
新闻
网络安全深度报道:关于安全战略、最新趋势和关键人物的特写文章。
定义2026年夏天的三大网络威胁
本期《记者笔记》视频系列讨论了AI代理入侵Hugging Face、Fairlife遭遇勒索软件攻击,以及与伊朗有关联的威胁行为者攻破美国十二个水务系统的影响。这是一个繁忙的夏天。
Arielle Waldman,《Dark Reading》特写作家
2026年9月24日
来源:DARK READING
2026年夏天以一系列从根本上改变企业防御者对当前威胁态势看法的网络威胁为标志,但有三起事件尤为突出:勒索软件导致可口可乐子公司Fairlife的生产停滞,协调一致的威胁行为者攻破了12个美国水务设施,而OpenAI的人工智能(AI)代理入侵了Hugging Face——在数天内未被发现,且未有人类知情或干预。
在9月份的《记者笔记》中,《Dark Reading》的Arielle Waldman、Cybersecurity Dive的David Jones以及TechTarget网络安全部的Richard Livingston讨论了定义2026年夏天的三大网络威胁。对话以如今臭名昭著的OpenAI与Hugging Face事件开始,自7月初披露以来,该事件已有多个重大进展。新闻报道暗示Hugging Face可能并非OpenAI的第一个受害者。对这些自主代理日益加剧的担忧促使Anthropic首席执行官Dario Amodei呼吁放缓AI发展步伐,以便监管和保障措施能跟上开发速度。
相关报道:当AI代理失控时谁该负责?Hugging Face泄露引发严峻问题
与代理对毫无防备的公司发起协调一致的自主攻击相比,记者们还讨论了乳制品公司Fairlife遭遇的勒索软件攻击,该攻击迫使美国生产设施停机11天。一个可能与俄罗斯有关联的威胁组织Anubis声称对该攻击负责,并表示窃取了1TB的数据。记者们讨论了Fairface对泄露事件的迅速响应、是否支付了赎金,以及企业现在必须将重点放在连续性和韧性上,而不仅仅是攻击响应。
Jones以对美国水务设施攻击的分析结束了对话。涉嫌与伊朗有关联的威胁组织针对可编程逻辑控制器(PLC)设备发动了攻击,这些设备因安全控制薄弱却连接互联网而闻名。这些攻击不仅破坏了运营技术系统,还削弱了公众对关键基础设施的信任。现在,它们引发了一个基本问题:美国能否有效管理这些关键系统的安全。
在视频中了解更多内容,并查看其他《记者笔记》剧集(可在此处获取),以了解Informa TechTarget旗下网络安全姊妹网站网络的见解和报道。
Arielle Waldman、David Jones 和 Richard Livingston:完整视频文字稿
本文字稿已由Informa TechTarget的内部AI助手编辑,以提高清晰度和缩短篇幅。如需完整体验,请观看视频。
相关报道:教育科技攻击者从学校转向其软件供应商
《Dark Reading》的Arielle Waldman:大家好,我是Arielle Waldman,《Dark Reading》的特写作家,欢迎收看新一期的《记者笔记》。我和Dave以及Richard在这里。你们想先自我介绍一下吗?然后我将进入今天的主题?
TechTarget网络安全部的理查德·利文斯顿:大家好,我是理查德·利文斯顿。我是TechTarget网络安全部的编辑兼撰稿人。很高兴来到这里。
Cybersecurity Dive的戴维·琼斯:我是戴维·琼斯,是Cybersecurity Dive的记者。
DR的阿里埃尔·沃尔德曼:今天,我们将讨论定义2026年夏季的网络威胁。我们将其缩小到三个范围:OpenAI和Hugging Face事件、针对可口可乐(Coca-Cola)和Fairlife的入侵,以及针对美国供水设施的攻击。
当我们首次提出这个话题时,有一个点立刻凸显出来:那就是OpenAI和Hugging Face事件。但在过去一周里,又有更多内幕被揭露。如果你还没听说过或需要回顾一下,今年7月我们获悉,OpenAI的智能体自行突破了测试沙箱,获得了互联网访问权限,随后开始攻击Hugging Face,后者是机器学习和人工智能领域的开源中央存储库。
相关报道:流程与文化是数据泄露背后的主要原因
这些失控的智能体最终突破了Hugging Face的生产基础设施,引发了一连串的连锁反应。Anthropic目睹了这一切,因此审查了其评估运行以查找类似问题,结果发现其前沿AI模型Claude也发生了突破并访问了互联网。该模型原本旨在进行夺旗(capture-the-flag)演练,以寻找虚构公司中的漏洞,但智能体却失控并对真实公司发起了攻击。
这些事件重新点燃了关于“护栏”机制的辩论,尽管这或许已不再是一场真正的辩论。在OpenAI的案例中,该公司曾关闭了一些安全措施以测试进攻能力。但正如我们所见,结果并不理想。
在对Hugging Face入侵事件的调查后,我们发现这些智能体实际上是协同工作的。它们通过留言板进行交流,在其中发布凭据和其他敏感信息。它们执行了权限提升、横向移动,甚至利用了一个零日漏洞(zero-day vulnerability),其行为与攻击者如出一辙。目前相关报道陆续出炉。Hugging Face可能并非首个受害者。
继7月事件之后,OpenAI、Anthropic、Google、Microsoft以及100多家其他行业领袖发表了一封联名信,呼吁在网络安全防御方面采取集体行动,以应对他们所目睹的一系列问题。而在更近的时候,Anthropic首席执行官达里奥·阿莫代伊(Dario Amodei)表示,AI的进步需要放缓。他在信中写道:
“我们必须放慢提升AI模型能力的速度。进展看起来仍然会很快,我们必须明智地利用我们争取到的时间。”
他将OpenAI和Hugging Face事件归为促使发出这封信的两个担忧之一。现在我很想知道,我们是否会看到更多的监管措施,或者接下来会发生什么。你们对此有何看法?是什么引发了这些变化?
TTC的理查德·利文斯顿:Anthropic关于放缓开发速度的说法很有趣。但我认为没有人会自愿这样做。从地缘政治角度来看不合逻辑,从商业角度来看也不合逻辑。我认为,而且我从某些渠道听到过这种观点,行业真正需要做的其实是组建一个跨职能小组。
来自人工智能行业各个领域的声音表明,自我监管将是一个关键方向,毕竟没有人会给自己批改作业。届时,将有一批同行审视即将推出的平台,希望在部署之前对其进行审查,并建立合理的护栏,基本上确保这些产品能够安全地推向市场。最后,我想到的最有趣的一点是,我认为这方面确实已有相关立法,即任何前沿人工智能开发者在构建模型时,必须内置一个“紧急停止开关”,以便在模型开始表现出意外行为时,能够立即切断电源。
CD的戴维·琼斯:关于这一切,存在更多的不确定性,因为我认为出现了一些问题。首先想到的一个问题是在此次事件之前,围绕为何人工智能行业似乎反对任何形式的监管或监督进行了大量辩论。中国显然是一个主要的地缘战略竞争对手。但中国也对人工智能失控感到担忧。
我们可以从威权政府的角度来思考这个问题。中国可能担心人工智能是否会释放出能够颠覆其整个政府的力量。因此,他们有动力确保有一种方式来管理,至少在某种程度上控制人工智能的能力范围。
所以,中国并非愿意放任任何事情发生。他们只是在努力确保其人工智能所拥有的任何能力都符合其自身利益。因此,我并不认为单纯放任人工智能自行其是是一种策略。我认为需要展开对话的核心问题是:
如果那些创造人工智能的人突然说“请监管我们”,这从任何角度来看都显得有些反常。这不仅是因为他们起初不愿接受监管,而现在却恳求监管,让人们不禁怀疑:他们是否知道一些我们尚未被告知的信息?是否在幕后,他们看到了某种无法控制的风险?
我认为,从政策角度而言,我们需要做的是恢复信心,确保在我们允许这些模型继续开发时,掌舵的人不会将整个行业推向悬崖。因为他们似乎表明,他们并不一定相信自己能够控制自己的创造物。
因此,需要一定的透明度。显然,我们希望继续发展该技术,但必须就如何确保这种增长在某种形式的监督下进行展开公开对话,无论是通过行业模式,还是通过与政府的混合模式。必须进行一些讨论。
DR的阿里尔·瓦尔德曼:确实。是的。有很多不同的方面需要涵盖。但现在我将把话题交给理查德,让他谈谈可口可乐Fairlife勒索软件攻击事件。你能告诉我们那里发生了什么吗?
TTC的理查德·利文斯顿:Fairlife是可口可乐旗下公司,其数据泄露事件发生在2026年7月。Fairlife以其超滤牛奶产品、蛋白奶昔和营养产品而闻名。其规模并不小,年销售额约为30亿美元,并于2020年被可口可乐收购。
今年7月的这次数据泄露,在某种程度上属于常见的数据泄露和勒索软件攻击。但当我回顾这个夏天我最关注的几起网络攻击时,让我印象深刻的是,对于Fairlife可口可乐而言,这可谓是一记“双重打击”。
首先,威胁行为者成功访问了他们的系统,该事件被归咎于与俄罗斯有关联的“阿努比斯”(Anubis)组织。该组织活跃已有数年之久。这大概是可口可乐迄今为止遭遇的最大规模攻击。因此,他们首先像往常一样提出了勒索软件的要求。据称,他们窃取了一太字节(terabyte)的数据,并威胁称若不付款便将数据公开。
但另一方面,他们实际上还访问并加密了 Fairlife 的生产系统。至于他们会用这些数据做什么,目前尚不清楚,但我认为可口可乐在意识到系统遭到入侵后,做出了非常审慎的决定,主动采取了断网措施。在此期间,他们自愿停止了所有美国地区的生产活动。这一停摆持续了大约11天。
我认为这里的关键点在于,我们不仅面临传统的勒索软件要求,同时公司的产品产出能力也遭到了物理层面的阻断。因此,造成的损害相当严重。
关于此次数据泄露,我们仍有一些未知之处。我们不知道攻击者最初是如何获得访问权限的。我们也不知道是否实际支付了赎金。我们甚至不清楚他们是否真的获取了那太字节的数据。他们声称自己拿到了,但这究竟属实与否,仍是一个疑问。
但就我们所知的事实而言,对于可口可乐和 Fairlife 来说,这已演变为一项企业披露事项和声誉问题。我的意思是,他们的反应相当迅速。他们提交了向美国证券交易委员会(SEC)的8-K表格,即股东披露文件。他们聘请了外部网络安全法律顾问。他们还迅速联系了执法部门。
纵观全局,我认为对于可口可乐和 Fairlife 而言,这是一个堪称典范的成功处置案例。正如大家所料,作为一家底蕴深厚的企业,可口可乐显然制定了非常完善的应急响应计划。他们执行得相当出色,正因如此,才将受影响范围限制在了最小程度。
虽然他们不得不关闭所有美国地区的生产,但加拿大地区的生产仍在继续。此外,他们还拥有足够的库存,以确保零售商的需求得到满足。
我想给首席信息安全官(CISO)们的建议是,一定要制定好应急响应计划。确保该计划符合你们组织的实际情况,开展桌面推演,进行战争模拟演练。这样,当类似情况真的找上门时,你们才能做好准备。
DR的阿里埃尔·沃尔德曼(Arielle Waldman):是的。
CD的大卫·琼斯(David Jones):我想就此插话几句,因为我们对这一事件做了一些报道。其中涉及的一个问题是,监管机构、政府以及安全界在关注重点上发生了一定程度的转变,即更加侧重于业务连续性和韧性,而不再仅仅局限于对攻击的响应。
因为现在的情况是,如果回顾四五年前的情况,许多董事会成员和高管层并没有太多关注网络安全,因为他们认为这不过是有人窃取数据而已,让IT部门和安保人员去处理就好,这不是他们的问题。
此次攻击凸显出一个问题,这也是近年来许多公司日益面临的难题:业务韧性和网络安全已成为公司整体战略规划的一部分。必须将其置于更大的商业战略框架中进行考量,因为如果一家公司从事生产活动,那么无论此类攻击是否得逞,都可能完全破坏其生产核心产品的能力,这对企业来说是一个严重的问题。
这是你们股东面临的问题。如果你不能提前展示计划、战略以及应对方案,这对你来说将是一个更大的问题,因为一旦遭到攻击,后果将非常严重,因为你们现在成了众矢之的。其他黑客能看到你们的脆弱性,看到你们容易受到干扰,看到他们手中握有对你们的把柄。
必须让大家相信这种情况不会再发生。你知道,你还需要考虑供应链问题。有些公司与供应商的联系日益紧密。它们与所合作的零售商和批发商相连。任何与你的组织有关联的人,基本上都可能受到影响。
如果你们的系统中出现恶意软件或其他类型的干扰,会造成什么样的下游影响?勒索软件攻击者是否不仅能攻击主要目标,还能获取下游客户群的数据并开始敲诈勒索?断连状态会持续多久?
我的意思是,今年发生的多次攻击中都出现了这种情况。Stryker 公司最近就发生了此类事件。波士顿科学公司一直在处理类似的问题。
这不是孤立的事件,也不是偶发个案;它会影响到公司的方方面面,而你们的股东将会是
Informa TechTarget
|
Cybersecurity Dive
InformationWeek
Channel Dive
TechTarget: Cybersecurity
Explore our brands
Dark Reading Resource Library
Black Hat News
Omdia Cybersecurity
Advertise
NEWSLETTER SIGN-UP
Cybersecurity Topics
World
The Edge
DR Technology
Events
Resources
CYBERATTACKS & DATA BREACHES
CYBER RISK
THREAT INTELLIGENCE
ICS/OT SECURITY
NEWS
Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know.
3 Cyber Threats That Defined the Summer of 2026
This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
Arielle Waldman,Features Writer,Dark Reading
September 24, 2026
SOURCE: DARK READING
Summer 2026 was marked by a number of cyber threats that fundamentally changed how enterprise defenders view the current threat landscape, but three incidents stood out: Ransomware halted production at Coca-Cola subsidiary Fairlife, coordinated threat actors compromised 12 US water utility facilities, and OpenAI's artificial intelligence (AI) agents hacked Hugging Face — operating undetected for days without human knowledge or intervention.
In the September edition of the Reporters' Notebook, Dark Reading's Arielle Waldman, David Jones from Cybersecurity Dive, and Richard Livingston from TechTarget Cybersecurity discuss the top three cyber threats that defined summer 2026. The conversation opened with the now-infamous OpenAI and Hugging Face incident, which has seen multiple significant developments since the initial July disclosure. News reports suggest Hugging Face may not have been OpenAI's first victim. Heightened concerns around these autonomous agents led Anthropic CEO Dario Amodei to call for an AI slowdown so that regulation and safeguards can catch up to development.
Related:Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
More run-of-the-mill than agents launching a coordinated, autonomous attack against an unsuspecting company, the reporters also discussed the ransomware attack at dairy company Fairlife that forced US production facilities offline for 11 days. A potentially Russian-affiliated threat group named Anubis claimed credit for the attack and said it stole 1TB of data. The reporters discussed Fairlife's swift response to the breach, whether a ransom was paid, and how businesses must now focus on continuity and resilience rather than just attack response.
Jones concluded the conversation with an analysis of the attacks against US water facilities. Threat groups with suspected links to Iran targeted programmable logic controller (PLC) devices, which are notorious for having weak security controls despite being connected to the Internet. These attacks not only disrupted operational technology systems, they also eroded public trust in critical infrastructure. Now, they raise basic questions around whether the US can effectively manage the security of these critical systems.
Learn more in the video, and also check out other Reporters' Notebook episodes, available here, for insights and coverage from across Informa TechTarget's network of cybersecurity sister sites.
Arielle Waldman, David Jones, and Richard Livingston: Full Video Transcript
This transcript has been edited for clarity and length by Informa TechTarget's internal AI assistant. For the full experience, please watch the video.
Related:EdTech Attackers Shift From Schools to Their Software Suppliers
Dark Reading's Arielle Waldman: Hi, my name is Arielle Waldman, features writer for Dark Reading, and welcome to another edition of the Reporter's Notebook. I'm here with Dave and Richard. Would you like to introduce yourselves, and then I'll get into today's topics?
TechTarget Cybersecurity's Richard Livingston: Hi, I'm Richard Livingston. I am an editor and a writer with TechTarget Cybersecurity. So glad to be here.
Cybersecurity Dive's David Jones: I am David Jones. I'm a reporter at Cybersecurity Dive.
DR's Arielle Waldman: So today, we're going to be talking about the cyber threats that define the summer of 2026. We narrowed it down to three: OpenAI and Hugging Face incident, the breach against Coca-Cola and Fairlife, and the attacks against the US water facilities.
When we first brought up this topic, one thing immediately stood out: the OpenAI and Hugging Face incident. But there's been even more revelations over the last week. If you haven't heard or need a refresh, in July we found out that OpenAI's agents broke out of a testing sandbox on their own, gained Internet access, and then started attacking Hugging Face, which is an open source central repository for machine learning and artificial intelligence.
Related:Processes & Culture Top Reasons Behind Data Breaches
These rogue agents eventually breached Hugging Face's production infrastructure, and it sort of launched a domino effect. Anthropic saw what happened, so they reviewed their evaluation runs to look for similar issues, and they found out that Claude, their frontier AI model, also broke out and accessed the Internet. It was conducting capture-the-flag exercises looking for vulnerabilities in fictional companies, but instead the agents went rogue and attacked real companies.
These agents really reignited a guardrail debate, which maybe isn't so much a debate anymore. In the case of OpenAI, the company had turned off some security measures to test offensive capabilities. But as we could see, that didn't end up so well.
After an investigation into the Hugging Face breach, we found out that the agents actually worked together. They communicated through message boards where they posted credentials and other sensitive information. They did privilege escalation, they performed lateral movement, and they even exploited a zero-day vulnerability, which is kind of similar to attackers. Reports are kind of coming out now. Hugging Face may not have been the first victim.
And in the wake of the July incident, OpenAI, Anthropic, Google, Microsoft, and more than 100 other industry leaders published a letter, a call for collective action on cyber defense, following all these issues that they were seeing. And even more recently, the Anthropic CEO, Dario Amodei, said that AI progress needs to slow down. In the letter he wrote,
"We must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain."
He attributed the OpenAI and Hugging Face incident as one of two concerns that prompted the letter. Now I'm curious if we'll be seeing more regulations or kind of what's to come there. Do you guys have any opinions on that or what you think that set off?
TTC's Richard Livingston: It's interesting what Anthropic is saying about slowing down the pace of development. And I don't think anyone's going to voluntarily do that. It doesn't make sense geopolitically; it doesn't make sense commercially. I think probably, and I've heard this from some corners, is that what the industry needs to do is actually create a cross-functional group.
From all different areas of the AI industry who will self-regulate, where nobody's going to score their own homework here. You would have a number of peers who would look at the platforms that are being introduced, hopefully before deployment, to go ahead and look at it and set up reasonable guardrails and basically ensure that this is something that can safely go out. And then, just to wrap that up, I think the most interesting thing I've heard, and I think there's actually legislation out there over this, is that any frontier AI developer, when they build that model, they have to build in a kill switch that if it starts acting in unexpected ways, they pull the plug.
CD's David Jones: There's a little more uncertainty about this whole thing because I think there were a couple of questions that have come up. One question that comes to mind is, there was a lot of debate before this incident about why the AI industry seemed to be against any kind of regulation or oversight. China obviously is a main geostrategic competitor. But China has its own concerns about AI running wild as well.
You can think about it from the standpoint of an authoritarian government. China could be concerned about whether AI could unleash something that could take down their entire government. So, they have an interest in making sure that there's a way to manage, if not control to a certain extent, what AI is capable of doing.
So, it's not as if China is just willing to let anything happen. They're just trying to make sure that whatever capabilities their AI has, it's in their interest. So, I don't necessarily think that just letting AI do what it does is really a strategy. I think that what there needs to be a dialogue about is:
If you have the people that created AI all of a sudden saying, "Please regulate us," that's a little unusual from any perspective. Not just from the standpoint of, initially they didn't want any regulation. Now they are begging for regulation, and people are wondering, OK, is there something that they know that we still haven't been told about? Is there something going on behind the scenes that they're seeing in terms of risk that they can't control?
I think what you want to do is restore confidence from a policy standpoint in terms of making sure that once we allow these models to continue development, that the people at the wheel are not going to just drive this entire industry off a cliff. Because they seem to be indicating that they don't necessarily believe they can control their own creation.
So, there needs to be some transparency. Obviously, you want to continue to develop the technology, but there needs to be some kind of an open dialogue about how you make sure this growth is created with some type of oversight, whether it's an industry model, whether it's a hybrid model with the government. There has to be some discussion.
DR's Arielle Waldman: Definitely. Yeah. There's so many different aspects to cover. But I'm going to turn over to Richard now to talk about the Coca-Cola Fairlife ransomware attack. Can you tell us what happened there?
TTC's Richard Livingston: Fairlife Coca-Cola, their data breach, July 2026. So, Fairlife is a company that's known for their ultra-filtered milk products, their protein shakes, their nutritional products. They're not insignificant in scale, about $3 billion in annual sales, and they were acquired by Coca-Cola in 2020.
Their data breach in July, in many ways it was a garden-variety breach and ransomware attack. But when I kind of looked at my favorite cyberattacks from this summer, what stood out to me is that for Fairlife Coca-Cola, this was kind of a double whammy.
First, threat actors were able to access their systems, and it was attributed to Anubis, which is a Russian-linked group. They've been active for a number of years. This is probably Coca-Cola being their biggest swing at bat here. And so, first, they were able to introduce a ransomware request, as these things typically go. They apparently stole a terabyte of data, and they threatened to make this public if not paid.
But on the flip side of that, they were actually able to access and encrypt Fairlife's production systems. So, no idea what they would have done with that, but I think Coca-Cola made the very judicious decision to pull the lever themselves when they realized that their systems had been compromised. They voluntarily shut down all US production during that investigation. That went on for about 11 days.
And what I think is important here is that we have their traditional ransomware request, but at the same time, we are physically halting a company's ability to bring out products. So, a fair bit of harm here.
There are some things that we don't know about this breach. We don't know how the attackers initially gained access. We don't know whether a ransom was actually paid. We don't even know if they actually got that terabyte of data. They said they did. Whether they did or not is a question.
But as far as the things that we do know is that for Coke and Fairlife, this became a corporate disclosure and a reputational issue. I mean, they acted pretty quickly on this. They filed their SEC 8-K, which is their shareholder disclosure. They brought in outside cybersecurity counsel. They also brought in law enforcement really quickly.
And when you look at this, I think for Coke and Fairlife, this is kind of a textbook example of something well done. As you might imagine with an organization with the legs of Coke, is that they clearly had a very well put-together incident response plan. They executed it well, and because of that, it limited the scope of how they were affected.
They had to shut down all US production. Canadian production continued. They also had enough inventory to go ahead and make sure that retailers were still taken care of.
And I guess, just the takeaway for CISOs here is that I think, is develop that incident response plan. Make sure it's realistic for your organization, do your tabletop exercises, do your war games, and then, when a situation like this does knock on your door, you're going to be ready.
DR's Arielle Waldman: Yeah.
CD's David Jones: I wanted to jump in just a second on this because we did a little bit of coverage, and one of the issues that this brings up is there's been a bit of a shift in terms of the focus of both regulators, governments, and the security community in terms of there's been an increased focus on business continuity and resilience as opposed to just responding to an attack.
Because what's happening now, if you go back four or five years, a lot of board members and C-suite members didn't really think that much about cybersecurity because all they thought about was, well, somebody's stealing data, let the IT people and let the security people fix it. It's not our problem.
One of the things that this attack brings out, and it's been an increasing problem for a lot of companies in recent years and months, is that business resilience and cybersecurity are part of the overall strategic plan for the company. They have to be thought of in terms of a larger business strategy because if you're a company and you produce things, and basically an attack like this, whether it's successful or not, can completely disrupt your ability to produce your core products, that's a problem for you.
It's a problem for your shareholders. It's going to be a bigger problem for you if you don't demonstrate a plan ahead of time, a strategy, and how to respond because there's going to be a lot of fallout once this attack happens, because now you have a target on your back. Other hackers can see that you're vulnerable, that you can be disrupted, that they have leverage over you.
And there has to be confidence that this will not happen again. You know, you have a supply chain to consider, too. There are companies that are increasingly interconnected with their vendors. They are connected with the retailers and wholesalers that they work with. Anybody that's connected to your organization is basically going to be potentially impacted.
If there is malware or some type of other disruption within your systems, what kind of downstream impact can that create? Can the ransomware actor not only attack the main target, but get data on the downstream customer base and start extorting them? How long is there going to be a disconnection?
I mean, this has come up during a number of attacks this year. It just came up during Stryker. Boston Scientific has been dealing with issues like this.
This is not something that's an isolated incident, and it's not a one-off; it's something that is going to reach into every aspect of the company, and your shareholders are going to be a
首次收录 · 2026-09-25 · 9.58 分