Cyberattacks on Major Consumer Brands in 2024: Key Takeaways
- By Erich Kron, KnowBe4
- March 17, 2025

In 2024, several well-known brands faced significant cyberattacks, highlighting that no organization is immune to cyber threats. At the end of the second quarter of 2024, the number of U.S. data breach victims surged by 1,000% compared to the previous period.
Below is just a sample of major household brands that were attacked in 2024, highlighting the nature of cybersecurity risks and lessons organizations can learn from these incidents.
- Home Depot
In April 2024, Home Depot reported it had suffered a major data breach. The incident came to light after a threat actor on a dark web forum claimed they had stolen data belonging to approximately 10,000 employees. According to Home Depot officials, the breach occurred due to an attack on one of their third-party software-as-a-service (SaaS) providers.
- Disney
Walt Disney’s internal communication channel, Slack, suffered a major data breach leading to the exposure of personal information of its employees in addition to its Disneyland and Disney Cruise customers. Hackers reportedly stole about one terabyte of data, including 44 million messages, 18,800 spreadsheets and 13,000 PDF files. While the exact method of the breach has not gone public yet, it is believed that hackers employed social engineering to trick users into downloading malicious files which eventually led to the compromise of Disney’s systems.
- AT&T and Verizon

Major broadband providers AT&T, Verizon and Lumen Technologies were reportedly hacked by China-backed threat actors. Hackers coexisted in these networks for months and even infiltrated systems used to conduct court-authorized wiretaps and collect internet traffic from millions of Americans. Although the initial access method of attackers is unknown, it is suspected that vulnerable routers were the potential entry point.
- Ticketmaster
Ticketmaster fell victim to a major cyberattack resulting in a loss of roughly 1.3TB of information, including 560 million customer records. Hackers claimed they obtained this information by hacking Snowflake, a Ticketmaster cloud storage provider. According to security researchers, threat actors accessed Ticketmaster’s Snowflake accounts using compromised login credentials that may have been acquired using some kind of infostealer malware.
- Shell
Oil giant Shell fell victim to a data breach discovered after a hacker group called 888 made a post on a dark web forum about the availability of 80,0000 Shell customer database records. The stolen records contained personal details such as customer codes, names, addresses, phone numbers, login credentials, and loyalty point balances. A third-party vendor providing anonymous mystery shopping services suffered a cybersecurity incident that resulted in Shell data being exposed.
- Prudential Insurance
Prudential Insurance disclosed in February 2024 that it had suffered a data security breach where information such as names, addresses, driver’s license numbers, and non-driver identification numbers of some 2.5 million customers were stolen. The hack is said to have occurred via a compromised employee account. While it is not clearly stated how this employee was compromised, it is alleged that Prudential was not training its employees well enough to identify social engineering and phishing attempts.
What organizations can learn
The above cases prove that current security controls and approaches are failing, costing organizations USD30 billion annually. Threat actors continue to be successful because they’re not solely attacking networks or systems — they are primarily targeting people, third-party partners, and software vulnerabilities.
Below are some important key takeaways:
- Deliver cybersecurity training to employees: Phishing and poor password hygiene remain the most common vectors for gaining access to systems. Running continuous security training programs and simulation exercises will help boost security instincts and help improve adherence to security best practices.
- Identify and fix vulnerabilities proactively: Unpatched vulnerabilities are one of the leading causes of breaches and ransomware attacks. Therefore, vulnerability assessments and system patching must be done proactively. Check for things like configuration errors, open ports, security policies, and rules, so that threat actors cannot exploit them.
- Close security gaps in the supply chain: Assess the security posture of key supply chain partners at regular intervals and create a plan to tackle identified risks. Maintain a Software Bill of Materials (SBOM) from critical software suppliers to gain an understanding of the software components and associated vulnerabilities.
Cyberattacks and data breaches can happen to any organization, regardless of size, industry, security maturity, or resources. Implementing security controls is essential, but it’s also crucial to gain better control of initial access vectors such as people, supply chain gaps, misconfiguration, and vulnerabilities, to reduce the occurrence of security incidents.
The views and opinions expressed in this article are those of the author and do not necessarily reflect those of CDOTrends. Image credit: iStockphoto/LagartoFilm
Erich Kron, KnowBe4
A 25-year veteran information security professional with experience in the medical, aerospace, manufacturing and defense fields, Erich Kron is Security Awareness Advocate for KnowBe4. Author, and regular contributor to cybersecurity industry publications, he was a security manager for the U.S. Army's 2nd Regional Cyber Center-Western Hemisphere and holds CISSP, CISSP-ISSAP, SACP and many other certifications. Erich has worked with information security professionals around the world to provide the tools, training and educational opportunities to succeed in information security.