Summer 2026 was marked by a number of cyber threats that fundamentally changed how enterprise defenders view the current threat landscape, but three incidents stood out: Ransomware halted production at Coca-Cola subsidiary Fairlife, coordinated threat actors compromised 12 US water utility facilities, and OpenAI’s artificial intelligence (AI) agents hacked Hugging Face — operating undetected for days without human knowledge or intervention.
In the September edition of the Reporters’ Notebook, Dark Reading’s Arielle Waldman, David Jones from Cybersecurity Dive, and Richard Livingston from TechTarget Cybersecurity discuss the top three cyber threats that defined summer 2026. The conversation opened with the now-infamous OpenAI and Hugging Face incident, which has seen multiple significant developments since the initial July disclosure. News reports suggest Hugging Face may not have been OpenAI’s first victim. Heightened concerns around these autonomous agents led Anthropic CEO Dario Amodei to call for an AI slowdown so that regulation and safeguards can catch up to development.
More run-of-the-mill than agents launching a coordinated, autonomous attack against an unsuspecting company, the reporters also discussed the ransomware attack at dairy company Fairlife that forced US production facilities offline for 11 days. A potentially Russian-affiliated threat group named Anubis claimed credit for the attack and said it stole 1TB of data. The reporters discussed Fairlife’s swift response to the breach, whether a ransom was paid, and how businesses must now focus on continuity and resilience rather than just attack response.
Jones concluded the conversation with an analysis of the attacks against US water facilities. Threat groups with suspected links to Iran targeted programmable logic controller (PLC) devices, which are notorious for having weak security controls despite being connected to the Internet. These attacks not only disrupted operational technology systems, they also eroded public trust in critical infrastructure. Now, they raise basic questions around whether the US can effectively manage the security of these critical systems.
Learn more in the video, and also check out other Reporters’ Notebook episodes, available here, for insights and coverage from across Informa TechTarget’s network of cybersecurity sister sites.
Arielle Waldman, David Jones, and Richard Livingston: Full Video Transcript
This transcript has been edited for clarity and length by Informa TechTarget’s internal AI assistant. For the full experience, please watch the video.
Dark Reading’s Arielle Waldman: Hi, my name is Arielle Waldman, features writer for Dark Reading, and welcome to another edition of the Reporter’s Notebook. I’m here with Dave and Richard. Would you like to introduce yourselves, and then I’ll get into today’s topics?
TechTarget Cybersecurity’s Richard Livingston: Hi, I’m Richard Livingston. I am an editor and a writer with TechTarget Cybersecurity. So glad to be here.
Cybersecurity Dive’s David Jones: I am David Jones. I’m a reporter at Cybersecurity Dive.
DR’s Arielle Waldman: So today, we’re going to be talking about the cyber threats that define the summer of 2026. We narrowed it down to three: OpenAI and Hugging Face incident, the breach against Coca-Cola and Fairlife, and the attacks against the US water facilities.
When we first brought up this topic, one thing immediately stood out: the OpenAI and Hugging Face incident. But there’s been even more revelations over the last week. If you haven’t heard or need a refresh, in July we found out that OpenAI’s agents broke out of a testing sandbox on their own, gained Internet access, and then started attacking Hugging Face, which is an open source central repository for machine learning and artificial intelligence.
These rogue agents eventually breached Hugging Face’s production infrastructure, and it sort of launched a domino effect. Anthropic saw what happened, so they reviewed their evaluation runs to look for similar issues, and they found out that Claude, their frontier AI model, also broke out and accessed the Internet. It was conducting capture-the-flag exercises looking for vulnerabilities in fictional companies, but instead the agents went rogue and attacked real companies.
These agents really reignited a guardrail debate, which maybe isn’t so much a debate anymore. In the case of OpenAI, the company had turned off some security measures to test offensive capabilities. But as we could see, that didn’t end up so well.
After an investigation into the Hugging Face breach, we found out that the agents actually worked together. They communicated through message boards where they posted credentials and other sensitive information. They did privilege escalation, they performed lateral movement, and they even exploited a zero-day vulnerability, which is kind of similar to attackers. Reports are kind of coming out now. Hugging Face may not have been the first victim.
And in the wake of the July incident, OpenAI, Anthropic, Google, Microsoft, and more than 100 other industry leaders published a letter, a call for collective action on cyber defense, following all these issues that they were seeing. And even more recently, the Anthropic CEO, Dario Amodei, said that AI progress needs to slow down. In the letter he wrote,
“We must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain.”
He attributed the OpenAI and Hugging Face incident as one of two concerns that prompted the letter. Now I’m curious if we’ll be seeing more regulations or kind of what’s to come there. Do you guys have any opinions on that or what you think that set off?
TTC’s Richard Livingston: It’s interesting what Anthropic is saying about slowing down the pace of development. And I don’t think anyone’s going to voluntarily do that. It doesn’t make sense geopolitically; it doesn’t make sense commercially. I think probably, and I’ve heard this from some corners, is that what the industry needs to do is actually create a cross-functional group.
From all different areas of the AI industry who will self-regulate, where nobody’s going to score their own homework here. You would have a number of peers who would look at the platforms that are being introduced, hopefully before deployment, to go ahead and look at it and set up reasonable guardrails and basically ensure that this is something that can safely go out. And then, just to wrap that up, I think the most interesting thing I’ve heard, and I think there’s actually legislation out there over this, is that any frontier AI developer, when they build that model, they have to build in a kill switch that if it starts acting in unexpected ways, they pull the plug.
CD’s David Jones: There’s a little more uncertainty about this whole thing because I think there were a couple of questions that have come up. One question that comes to mind is, there was a lot of debate before this incident about why the AI industry seemed to be against any kind of regulation or oversight. China obviously is a main geostrategic competitor. But China has its own concerns about AI running wild as well.
You can think about it from the standpoint of an authoritarian government. China could be concerned about whether AI could unleash something that could take down their entire government. So, they have an interest in making sure that there’s a way to manage, if not control to a certain extent, what AI is capable of doing.
So, it’s not as if China is just willing to let anything happen. They’re just trying to make sure that whatever capabilities their AI has, it’s in their interest. So, I don’t necessarily think that just letting AI do what it does is really a strategy. I think that what there needs to be a dialogue about is:
If you have the people that created AI all of a sudden saying, “Please regulate us,” that’s a little unusual from any perspective. Not just from the standpoint of, initially they didn’t want any regulation. Now they are begging for regulation, and people are wondering, OK, is there something that they know that we still haven’t been told about? Is there something going on behind the scenes that they’re seeing in terms of risk that they can’t control?
I think what you want to do is restore confidence from a policy standpoint in terms of making sure that once we allow these models to continue development, that the people at the wheel are not going to just drive this entire industry off a cliff. Because they seem to be indicating that they don’t necessarily believe they can control their own creation.
So, there needs to be some transparency. Obviously, you want to continue to develop the technology, but there needs to be some kind of an open dialogue about how you make sure this growth is created with some type of oversight, whether it’s an industry model, whether it’s a hybrid model with the government. There has to be some discussion.
DR’s Arielle Waldman: Definitely. Yeah. There’s so many different aspects to cover. But I’m going to turn over to Richard now to talk about the Coca-Cola Fairlife ransomware attack. Can you tell us what happened there?
TTC’s Richard Livingston: Fairlife Coca-Cola, their data breach, July 2026. So, Fairlife is a company that’s known for their ultra-filtered milk products, their protein shakes, their nutritional products. They’re not insignificant in scale, about $3 billion in annual sales, and they were acquired by Coca-Cola in 2020.
Their data breach in July, in many ways it was a garden-variety breach and ransomware attack. But when I kind of looked at my favorite cyberattacks from this summer, what stood out to me is that for Fairlife Coca-Cola, this was kind of a double whammy.
First, threat actors were able to access their systems, and it was attributed to Anubis, which is a Russian-linked group. They’ve been active for a number of years. This is probably Coca-Cola being their biggest swing at bat here. And so, first, they were able to introduce a ransomware request, as these things typically go. They apparently stole a terabyte of data, and they threatened to make this public if not paid.
But on the flip side of that, they were actually able to access and encrypt Fairlife’s production systems. So, no idea what they would have done with that, but I think Coca-Cola made the very judicious decision to pull the lever themselves when they realized that their systems had been compromised. They voluntarily shut down all US production during that investigation. That went on for about 11 days.
And what I think is important here is that we have their traditional ransomware request, but at the same time, we are physically halting a company’s ability to bring out products. So, a fair bit of harm here.
There are some things that we don’t know about this breach. We don’t know how the attackers initially gained access. We don’t know whether a ransom was actually paid. We don’t even know if they actually got that terabyte of data. They said they did. Whether they did or not is a question.
But as far as the things that we do know is that for Coke and Fairlife, this became a corporate disclosure and a reputational issue. I mean, they acted pretty quickly on this. They filed their SEC 8-K, which is their shareholder disclosure. They brought in outside cybersecurity counsel. They also brought in law enforcement really quickly.
And when you look at this, I think for Coke and Fairlife, this is kind of a textbook example of something well done. As you might imagine with an organization with the legs of Coke, is that they clearly had a very well put-together incident response plan. They executed it well, and because of that, it limited the scope of how they were affected.
They had to shut down all US production. Canadian production continued. They also had enough inventory to go ahead and make sure that retailers were still taken care of.
And I guess, just the takeaway for CISOs here is that I think, is develop that incident response plan. Make sure it’s realistic for your organization, do your tabletop exercises, do your war games, and then, when a situation like this does knock on your door, you’re going to be ready.
DR’s Arielle Waldman: Yeah.
CD’s David Jones: I wanted to jump in just a second on this because we did a little bit of coverage, and one of the issues that this brings up is there’s been a bit of a shift in terms of the focus of both regulators, governments, and the security community in terms of there’s been an increased focus on business continuity and resilience as opposed to just responding to an attack.
Because what’s happening now, if you go back four or five years, a lot of board members and C-suite members didn’t really think that much about cybersecurity because all they thought about was, well, somebody’s stealing data, let the IT people and let the security people fix it. It’s not our problem.
One of the things that this attack brings out, and it’s been an increasing problem for a lot of companies in recent years and months, is that business resilience and cybersecurity are part of the overall strategic plan for the company. They have to be thought of in terms of a larger business strategy because if you’re a company and you produce things, and basically an attack like this, whether it’s successful or not, can completely disrupt your ability to produce your core products, that’s a problem for you.
It’s a problem for your shareholders. It’s going to be a bigger problem for you if you don’t demonstrate a plan ahead of time, a strategy, and how to respond because there’s going to be a lot of fallout once this attack happens, because now you have a target on your back. Other hackers can see that you’re vulnerable, that you can be disrupted, that they have leverage over you.
And there has to be confidence that this will not happen again. You know, you have a supply chain to consider, too. There are companies that are increasingly interconnected with their vendors. They are connected with the retailers and wholesalers that they work with. Anybody that’s connected to your organization is basically going to be potentially impacted.
If there is malware or some type of other disruption within your systems, what kind of downstream impact can that create? Can the ransomware actor not only attack the main target, but get data on the downstream customer base and start extorting them? How long is there going to be a disconnection?
I mean, this has come up during a number of attacks this year. It just came up during Stryker. Boston Scientific has been dealing with issues like this.
This is not something that’s an isolated incident, and it’s not a one-off; it’s something that is going to reach into every aspect of the company, and your shareholders are going to be asking you questions.
DR’s Arielle Waldman: That ransomware is almost inevitable now and the number of attacks just keep going up every month, it seems like, from reports I’ve seen. So, yeah, companies’ preparation is key now. I’m curious to see if they paid the ransom as well. I don’t know if we’ll find out or they’ll tell us later or not. But I’m always curious about that as well, to see if it made any difference.
TTC’s Richard Livingston: Yeah, apparently, they didn’t ask for a number. They just said a token — a token gesture would be appreciated, something along those lines is what Anubis had said.
DR’s Arielle Waldman: Gotcha, gotcha. Dave, do you want to talk about the US water utilities attacks now?
CD’s David Jones: Water has been a major concern for a number of years. Water utilities have been facing attacks dating back several years now to the beginning of the Gaza war, going back about three years, more than three years.
And what’s happened lately is with the launch of the US and Israeli bombing against Iran and the full-scale war that broke out earlier this year, asymmetric attacks have become a way to respond when there’s an obvious military imbalance.
So, there are devices that water utilities and other critical infrastructure providers use called programmable logic controllers that are often exposed to the Internet. They are not very well configured by a lot of utilities because a lot of these utilities don’t have large cybersecurity teams, they don’t have large cybersecurity budgets. They often leave them exposed where they can be visible online.
They have often allowed default passwords to remain or not use very complex passwords. There are other issues where they’re not using the most up-to-date software. And they don’t really have somebody monitoring those environments 24/7.
So, there are suspected Iran Nexus hackers. Some are connected to Iranian intelligence. There are also hacktivists that have been working with Iran and suspected Russian and possibly Chinese actors as well, criminal, possibly state, may have been lending them expertise.
And water utilities have become a way to not only disrupt the actual services but create an element of psychological damage to the American public. You care about being able to use clean, available water in all types of businesses. You need it in a farming environment, you need it in the hospital, you need to be able to use it at a school.
And when you have a situation where you’re in a small town and the water is either shut off or there’s a boil-water advisory or something else is disrupting the supply or raising questions about the supply, you’re kind of like, what in the world is going on?
And there are tens of thousands of water systems all over the US that have very limited assets to manage the security, but they need a lot of help in terms of resources, in terms of training, in terms of up-to-date technology.
We know that at least 12 states reported impacts from these attacks. The hackers were able to get into many of these systems by targeting these PLCs. In some cases, the operators were locked out, where their passwords no longer worked. They lost visibility in some cases into their systems where you can’t tell whether the water is being properly monitored or whether it’s running properly.
There were wastewater issues where there were leaks. And it went beyond just water. There were other critical infrastructure systems targeted by these attacks. Energy was one of them. There are a lot of other sectors that use these types of devices.
And it raised some basic questions about whether the US can manage and monitor the security of its critical systems. And it also raised a lot of questions about whether Iran is a lot more sophisticated in terms of their capabilities of targeting US critical infrastructure than we realized.
DR’s Arielle Waldman: Hopefully, it promotes better security of our critical infrastructure.
CD’s David Jones: No, absolutely, absolutely. I think that there are questions now about whether we have enough investment from the government, from the private sector, invested in terms of protecting these systems, in terms of road-testing a potential attack.
There are efforts now to quickly try to secure more of these systems, make sure the technology’s up to date, and make sure that, in the future, if there are attempted attacks, because we can’t rule out the possibility that there will be attacks by other actors, we’re going to need to develop more comprehensive plans to protect these critical systems.
TTC’s Richard Livingston: You know, it’s funny, Dave. It just, you know, it touches on a national security issue. I was just at the Billington conference, and that’s all military and government agency cybersecurity experts, and you spoke about the trust that can be lost in these systems, and they talked about something that they call cognitive warfare. That’s where the aim of the cyberattack might not necessarily bring that system down, but to absolutely erode morale and to make people question the things that otherwise they would just take for granted every darn day.
CD’s David Jones: That’s true. And, you know, considering what we’ve been dealing with in terms of our relationship with China, there were concerns that there were Chinese state-linked actors that were prepositioning on critical sectors across multiple industries for potential distraction activity.
We don’t necessarily know who or what it’s being done in terms of our critical systems, and do we have ways to detect that activity? Do we have ways to interrupt it? Do we have ways to make sure that we have the most up-to-date software and firmware in our critical infrastructure because what happened in water could easily transfer to another industry?
DR’s Arielle Waldman: Definitely. Well, those were our top three cyber threats of summer 2026. There were probably others that we didn’t have time for, but those were what we thought were most notable. Thank you for joining. Thanks, Dave and Richard.
TTC’s Richard Livingston: Thank you.

No responses yet