Reuters has been keeping a running tally of American companies breached during 2026, and read end to end, it is more instructive than any single entry in it.

The names run from Nike and Coca-Cola to Novo Nordisk and Abbott Laboratories, and almost none of the incidents involve the kind of exotic technique that Google’s discovery of an AI-developed zero-day made everyone worry about.

What recurs instead is social engineering, usually aimed at a third party. Carnival, Clover Health, iRhythm, and AdaptHealth were all reached that way, in several cases through contractor accounts rather than the companies’ own staff.

That is the vulnerability the industry has been slowest to close, because it does not sit inside anyone’s perimeter. A supplier with access to your systems is a security dependency you cannot patch, and the attacker only has to be convincing on the phone.

One group appears repeatedly. ShinyHunters claimed 80 million business records from Take-Two Interactive and Rockstar Games in April, then breached Instructure’s Canvas platform in May in an incident affecting close to 9,000 institutions.