Companies across sectors faced data breaches and cybersecurity incidents in 2026, with attacks exposing customer information, disrupting operations and increasing the financial cost of protecting corporate systems.
The incidents showed that data breaches were not limited to large technology companies or a single attack method. Verizon’s 2026 Data Breach Investigations Report said software vulnerabilities became the leading starting point for breaches, accounting for 31% of breaches analysed, while ransomware appeared in 48% of breaches.
Origin Energy Limited disclosed in July that unauthorised access had resulted in the disclosure of some customer data. The Australian energy company said on July 28 that its initial review indicated information belonging to approximately 900,000 current and former customers had been accessed.
The information potentially included names, addresses, dates of birth, telephone numbers and account information, along with limited payment information, Origin said. The company said it was contacting affected customers and working with cybersecurity specialists and Australian authorities as its investigation continued.
Other companies reported incidents involving different routes into corporate systems. ADT Inc. said in an April filing with the US Securities and Exchange Commission that unauthorised parties had accessed certain cloud-based environments, while an investigation found that limited customer and prospective customer data had been accessed.
West Pharmaceutical Services Inc. reported in May that an unauthorised party had exfiltrated certain data and encrypted some systems. The company said it took systems offline globally as part of its response, while manufacturing, shipping and receiving operations were progressively restored.
The incidents also showed how third-party services can expand the exposure of corporate data. Verizon said third-party involvement in breaches had risen to 30% in its 2025 report, while its 2026 report identified software vulnerabilities as the leading initial access route.
The financial impact can extend beyond the immediate cost of investigation and recovery. IBM’s 2026 Cost of a Data Breach Report said malicious breaches enabled by artificial intelligence averaged $6 million, compared with a global average breach cost of $4.99 million. IBM also said AI-enabled malicious breaches had increased 56% from the previous year.
IBM’s findings showed that attackers were using artificial intelligence to accelerate phishing, impersonation and malware-related activity. The report said organisations using AI and automation extensively in security operations reduced breach costs by almost $2 million on average.
The risks also extend to companies handling sensitive information. iRhythm Holdings Inc. disclosed in June that an unauthorised actor had accessed data from third-party-hosted business applications after social engineering. The company said the information potentially included patient protected health information and other personal data, while its clinical and medical-device systems were not affected.
For Indian businesses, the cost of a breach has also risen. IBM’s 2025 India report put the average organisational cost of a data breach in the country at INR 220 million, or Rs 22 crore, a 13% increase from the previous year.
Companies are responding by strengthening basic security controls as well as adopting newer defensive technologies. Verizon recommends measures including multifactor authentication, software updates, employee training, encryption and regular security testing to reduce exposure to attacks.
The investigations into several 2026 incidents remain ongoing, meaning the final number of affected records and the full operational and financial consequences are not yet known. Companies including Origin Energy, West Pharmaceutical Services and iRhythm have said their assessments or remediation work would continue.
Filed by
Startup Unplugged
.png)