Hackers Aren't Stealing Data Anymore. They're Breaking Companies.
In 2026, cyberattacks stopped being a privacy problem and became an earnings problem — wiped devices, weeks of downtime, delayed SEC filings. The market is still pricing cyber like an IT line item.
On a Tuesday in March, employees at Stryker — a $130 billion medical technology company that makes surgical robots and hospital equipment — watched tens of thousands of their laptops and workstations get remotely wiped in a single coordinated strike. Not encrypted for ransom. Not quietly mined for data. Destroyed. The company lost control of its own systems for days, and the U.S. government later attributed the attack to an arm of Iranian intelligence. When Stryker reported first-quarter earnings, the hack was in the numbers.
That is the story of cybersecurity in 2026, and it is a fundamentally different story than the one investors have been trained to read. For twenty years, the corporate hack followed a familiar script: intruders steal records, the company apologizes, offers credit monitoring, absorbs a fine, and the stock recovers within a quarter. The data breach became a cost of doing business — annoying, embarrassing, and almost never material.
This year, the script changed. The attackers stopped stealing the data and started breaking the machines.
The Business Model Flipped
Look at the pattern across 2026's worst incidents and the common thread is not exposure — it's stoppage.
Hasbro, the 103-year-old toymaker behind Transformers and Dungeons & Dragons, discovered hackers in its systems in late March. Weeks later, the company was still largely offline — website down, unable to serve customers — and was forced to file for an extension on its financial reporting with the SEC because it could not close its own books. A company that survived a century of wars, recessions, and retail collapses was functionally paralyzed by an intrusion it still hasn't fully explained.
Instructure, whose Canvas platform is the operating system for American education, was breached by the ShinyHunters gang, exposing data on more than 30 million students and staff. When the company refused to pay, the hackers broke in a second time and defaced Canvas login screens — deliberately timed to school finals, disrupting exams across the country. Instructure paid the ransom, over the FBI's objections. The lesson every extortion crew took from that episode: disruption converts to payment far more reliably than a leak threat does.
And the supply chain became the delivery mechanism. Market research provider Klue was breached through a single credential issued in 2022 for a limited pilot — left active for four years — and the intrusion cascaded into roughly 200 downstream companies, including security firms like LastPass, HackerOne, and Jamf, because Klue held the keys to its customers' cloud environments. Parallel campaigns compromised widely used open-source tools — the Trivy security scanner, Bitwarden's CLI, Checkmarx — turning the software that companies install to protect themselves into the intrusion vector, with downstream data theft reaching OpenAI and Vercel.
The Targets Are Now Physical
The same shift is visible at the state level, and it is more alarming. Over the past year, hackers attributed in whole or part to Russia have hit Poland's energy grid with wiper malware, breached Polish water treatment plants, targeted a Swedish thermal power plant, and hijacked the controls of a Norwegian dam — releasing swimming pools' worth of water before anyone noticed. These are not espionage operations. They are rehearsals.
American infrastructure is not a bystander. U.S. agencies have warned that Iranian actors are probing privately owned American water utilities — among the softest targets in the country, thousands of them running with minimal security staff and decades-old control systems. And in April, the FBI itself declared a "major cyber incident" after suspected Chinese intruders breached a bureau surveillance system, exposing information about active federal wiretap targets. When the premier law enforcement agency in the world's largest economy cannot secure its own surveillance apparatus, the baseline assumption for every other institution needs revisiting.
Here is what matters for investors: every one of these incidents destroyed operational capacity, not just confidentiality. Downtime, not data, is now the loss driver. Yet most of the market still prices cyber risk the old way — as an IT line item, a compliance cost, a fine-sized contingency. If the loss model has changed and the pricing hasn't, somebody is on the wrong side of that gap — and somebody else is getting paid to close it.
The rest of this briefing is free — it just requires a free AlphaBriefing account: the three business models that capture the spending shift now underway, the cyber insurance repricing that state-sponsored attacks are about to force, and a five-question screen for finding cyber-operational risk hiding in your portfolio.
Create your free account → — 30 seconds, no card.