← The Hacker in a Hoodie Index  ·  complete ledger
Hacker in a Hoodie Index
The SEC’s 8-K Scoreboard · complete ledger

Material cyber incidents disclosed to the SEC under Item 1.05, and cyber-flagged Item 8.01 filings, approved to this index. Each entry is a primary filing, graded Verified. This is the complete record for this feed, uncapped.

118 approved disclosed 8-K incidents, most recent first. The complete record, nothing hidden, never summed.
The revision trail
A cost figure arrives after an incident is disclosed, and it moves as stronger sources report it. Early estimates run below the figure a company eventually discloses. The amount shown for each incident is its most recent claim; the trail beneath it is every claim in order, each with its date, its source, and its grade, from an Inferred early estimate to a higher Verified filing figure.
Corrections
Every figure on this ledger is read from a primary SEC filing and links to it. If we have read one wrong, tell us: info@hackerinahoodie.com.
CLOVER HEALTH INVESTMENTS, CORP. /DEJul 2026
Filing excerpt“Based on preliminary findings from the Company’s investigation, those accounts were assigned to employees who had member visit-scheduling and broker-facing sales functions. The employee accounts had access to certain personally identifiable information and protected health information, but had no access to corporate financial or claims systems. While the investigation is ongoing into the precise nature, scope, and extent of data that was subject to unauthorized access and acquisition, the Company believes that its rapid response successfully contained and terminated the unauthorized access.”
Not yet quantified
VVerifiedFinancial Services
Coca Cola CompanyJul 2026
Filing excerpt“On July 16, 2026, The Coca-Cola Company announced that Fairlife, a $4bn dairy company owned by the Company was hit by a ransomware event. Coca-Cola does not disclose the actual date that the event occurred or the scale of the potential loss but filed an 8k to acknowledge the possibility that this was a material event. This event can only be measured against the disclosure date of 7/16/2026 due to the limited information Coca-Cola shares in their filing. https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/”
Not yet quantified
VVerifiedManufacturing
River Financial CorpJun 2026
Since the date of the original filing, River's investigation has progressed. River has determined that an unauthorized threat actor accessed portions of its network and removed certain data from its environment.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial Services
SR Bancorp, Inc.Jul 2026
Other Events Mercadien, P.C. CPAs ("Mercadien"), which provides internal audit-related services to SR Bancorp, Inc (the "Company") and Somerset Regal Bank (the "Bank"), has discovered a data security incident in which an unauthorized actor accessed and acquired certain files on Mercadien's computer servers.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial Services
AdaptHealth Corp.Jun 2026
AdaptHealth Corp. (the "Company") is investigating a security incident whereby a threat actor gained unauthorized access to Company systems and exfiltrated certain data therefrom.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life Sciences
NAVIENT CORP (JSM, NAVI)Jun 2026
On June 8, 2026, the Company became aware of a cybersecurity incident involving a third-party law firm (the "Firm") that provides services to the Company. The incident involved a ransomware attack affecting certain of the Firm's information systems.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial Services
AFLAC INCJun 2026
Other Events. On June 30, 2026, Aflac Life Insurance Japan Ltd. ("Aflac Japan"), a wholly owned subsidiary of Aflac Incorporated, a Georgia corporation (the "Company"), issued a press release announcing that, on June 25, 2026, Aflac Japan discovered an unauthorized third-party had unlawfully accessed certain of Aflac Japan systems and data.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedHealthcare and Life Sciences
8X8 INCJun 2026
On June 13, 2026, 8x8, Inc. (the " Company " or " we" ) was informed that an unauthorized third party threat actor exploited the Klue Labs, Inc. (" Klue ") third-party application programming integration connected to the Company's Salesforce, Inc. (" Salesforce ") customer relationship management system.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTechnology and Software
iRhythm Holdings, Inc.Jun 2026
On June 8, 2026, iRhythm Holdings, Inc. (the "Company") identified unauthorized activity involving data maintained on certain third-party-hosted business applications.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life Sciences
POPULAR, INC. (BPOP, BPOPM, BPOPO)Jun 2026
Filing excerpt“On May 15, 2026, Popular, Inc. (the "Corporation") was notified by Evertec, Inc. ("Evertec"), a third-party core financial transaction processing and information technology services provider of the Corporation, that Evertec had experienced a cybersecurity incident affecting certain data of its clients, including that of Banco Popular de Puerto Rico ("BPPR"), the Corporation's Puerto Rico banking subsidiary.”
Not yet quantified
VVerifiedFinancial Services
EVERTEC, Inc.Jun 2026
Filing excerpt“On May 13, 2026, EVERTEC, Inc. ("Evertec" or the "Company") learned of potential unauthorized access to customer data. Based on our current understanding, the Company believes that the incident has primarily impacted our financial institution clients in Puerto Rico and their respective customers”
Not yet quantified
VVerifiedFinancial Services
Oncology Institute, Inc. (TOI, DFPH, TOIIW)May 2026
Filing excerpt“The Oncology Institute, Inc. (the "Company") is providing this disclosure, as a follow-up to its voluntary disclosure in Item 7.01 of a Current Report on Form 8-K filed on November 6, 2025, regarding a cybersecurity incident affecting a software service provider ("Vendor") utilized by the Company. The Company is reserving all rights with respect to potential claims against relevant third parties or service providers. ”
Not yet quantified
VVerifiedHealthcare and Life Sciences
WEST PHARMACEUTICAL SERVICES INCMay 2026
Filing excerpt“As previously disclosed in the Original Report, the Company determined on May 7, 2026 that the Company had experienced a material cybersecurity attack, in which certain data was exfiltrated by an unauthorized party and certain systems were encrypted.”
Not yet quantified
VVerifiedHealthcare and Life Sciences
Inotiv, Inc.May 2026
Filing excerpt“5 Privacy Class Actions As previously disclosed, the Company has been a party to three putative class actions filed in the United States District Court for the Northern District of Indiana (the "Federal Actions") relating to the cybersecurity incident experienced in August 2025 (the "Cybersecurity Incident"), in which a threat actor gained unauthorized access to the Company's systems and may have acquired certain data.”
Not yet quantified
VVerifiedProfessional and Business Services
CB Financial Services, Inc.May 2026
Filing excerpt“On May 5, 2026, Community Bank (the "Bank"), the wholly-owned subsidiary of CB Financial Services, Inc. (the "Company"), became aware of an internal incident involving the handling of certain non-public customer information using an unauthorized artificial intelligence-based software application. Among the customer information the Bank has determined was disclosed are customer names, social security numbers and dates of birth.”
Not yet quantified
VVerifiedFinancial Services
West Pharmaceutical ServicesMay 2026
Material attack. Data exfiltrated, systems encrypted, global operations disrupted.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life Sciences
CB Financial ServicesMay 2026
Determined material. Customer names, Social Security numbers and dates of birth disclosed.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial Services
ITRON, INC.Apr 2026
Filing excerpt“As previously disclosed, on April 13, 2026, Itron, Inc. (the Company) was informed that an unauthorized third party had gained access to certain of its systems. With the assistance of external cybersecurity experts, the Company has continued its investigation, remediation, and containment activities relating to the unauthorized access.”
Not yet quantified
VVerifiedManufacturing
ADT Inc.Apr 2026
Filing excerpt“On April 20, 2026, ADT Inc. ("ADT" or the "Company") became aware of unauthorized access to certain cloud-based environments. Following the investigation conducted in accordance with its IRP, the Company determined that only limited customer and prospective customer data was accessed.”
Not yet quantified
VVerifiedProfessional and Business Services
RCI HOSPITALITY HOLDINGS, INC.Apr 2026
Filing excerpt“RCI Internet Services, Inc., a subsidiary of RCI Hospitality Holdings, Inc., (the "Company"), recently discovered on March 23, 2026 that it sustained a cybersecurity incident starting March 19, 2026. The incident did not impact the business operations of the Company. As the investigation concluded on April 7, 2026, the Company learned that a potential insecure direct object reference vulnerability was present on its Internet Information Services (“IIS”) web server. To remediate, the Company promptly enhanced its technical security posture, including expanding the use of multifactor authentication and disabling external access to the IIS. ”
Not yet quantified
VVerifiedRetail and Consumer
STRYKER CORPMar 2026
Filing excerpt“As previously disclosed in the Original Report and as further reported on two Item 7.01 Current Reports on Form 8-K, furnished to the SEC on March 12, 2026, and March 23, 2026 respectively, on March 11, 2026, the Company identified a cybersecurity incident, which when it occurred, caused disruptions to the Company's business operations.”
Not yet quantified
VVerifiedHealthcare and Life Sciences
Bitcoin Depot Inc. (BTM, BTMWW)Apr 2026
Filing excerpt“On March 23, 2026, Bitcoin Depot Inc. (the "Company") discovered that an unauthorized party gained access to certain of its information technology systems.”
Quantified -2 days after disclosure.
$3.665M
Reimbursement / theft
VVerifiedFinancial Services
Graded revision trail
2026-04-06$3.665MVVerifiedSEC 8-K, Item 1.05 ↗
HASBRO, INC.Apr 2026
Filing excerpt“On March 28, 2026, Hasbro, Inc. (the "Company") identified unauthorized access to the Company's network. The Company has implemented and continues to implement business continuity plans to enable it to continue to take orders, ship product and conduct other key operations while it resolves this situation. The need to run these interim measures may continue for several weeks before the situation is fully resolved and may result in some delays.”
Not yet quantified
VVerifiedManufacturing
CareCloud, Inc. (CCLD, CCLDO)Mar 2026
Filing excerpt“On March 16, 2026, CareCloud, Inc. (the "Company") experienced a temporary network disruption in its CareCloud Health division that partially impacted the functionality and data access to 1 of its 6 electronic health record environments for approximately 8 hours until the Company fully restored all functionality and data access during that evening.”
Not yet quantified
VVerifiedTechnology and Software
HERITAGE FINANCIAL CORPMar 2026
Filing excerpt“On or about March 2, 2026, Heritage Financial Corporation (the "Company") detected a cybersecurity incident involving an internal file share server used by employees and the exfiltration of files from that file share server which may contain personal information.”
Not yet quantified
VVerifiedFinancial Services
TRIO-TECH INTERNATIONALMar 2026
Filing excerpt“On March 11, 2026, Trio-Tech International ("Company") identified and responded to a cybersecurity incident in one of its subsidiaries ("subsidiary") in Singapore. The subsidiary experienced a ransomware incident that resulted in encryption of certain files within the Company’s network. At that time, management determined that the incident was not material. On March 18, 2026, the incident escalated and resulted in the unauthorized disclosure of certain Company data. ”
Not yet quantified
VVerifiedManufacturing
Stryker CorpMar 2026
Material incident disclosed; operations since restored. Cost disclosure pending.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life Sciences
UFP TECHNOLOGIES INCFeb 2026
Filing excerpt“On or about February 14, 2026, UFP Technologies, Inc. (the "Company") detected suspicious activity involving its information technology ("IT") systems.”
Not yet quantified
VVerifiedHealthcare and Life Sciences
WYTEC INTERNATIONAL INCAug 2025
Filing excerpt“As disclosed in a Current Report on Form 8-K (the "Original Report"), on August 25, 2025, Wytec International, Inc. (the "Company") became aware of a cybersecurity incident in which a bad actor published a defaced website at the Company's web address, wytecintl.com.”
Not yet quantified
VVerifiedTelecommunications
Coupang, Inc.Dec 2025
Filing excerpt“On December 24, 2025 (PST) and December 28, 2025 (PST), Coupang Corp., a wholly-owned Korean subsidiary ("Coupang Corp.") of Coupang, Inc. ("Coupang, Inc.," "our," or "we") (Coupang Corp., together with Coupang, Inc. and its subsidiaries and affiliates, "Coupang,"), issued updates (collectively, the "Updates") on the cybersecurity incident (the "Incident") disclosed in the Current Report on Form 8-K filed by Coupang, Inc. with the U.S. Securities and Exchange Commission (the "SEC") on December 16, 2025.”
Not yet quantified
VVerifiedRetail and Consumer
Phoenix Education Partners, Inc.Dec 2025
Filing excerpt“The University of Phoenix, Inc., a subsidiary of Phoenix Education Partners, Inc. (including the University, the " Company "), recently experienced a cybersecurity incident involving the Oracle E-Business Suite software platform (" Oracle EBS "). The Company is one of a number of organizations, including other academic institutions, from which an unauthorized third-party exfiltrated data by exploiting a previously unknown software vulnerability in Oracle EBS.”
Quantified 224 days after disclosure.
$5.1M
Direct expense
VVerifiedPublic Sector and Education
Graded revision trail
2026-07-14$5.1MVVerifiedSEC 10-Q ↗
BayFirst Financial Corp.Oct 2025
Filing excerpt“Cybersecurity Incidents On August 14, 2025, BayFirst National Bank ("BayFirst") was notified of a cybersecurity incident experienced by a third-party provider of marketing services. On October 28, 2025, the third-party provider confirmed that some customer information was exposed by this incident.”
Not yet quantified
VVerifiedFinancial Services
JEWETT CAMERON TRADING CO LTDOct 2025
Filing excerpt“On October 15, 2025, Jewett-Cameron Trading Co. Ltd. (the "Company") learned that a threat actor had gained unauthorized access to portions of the Company's information technology ("IT") environment and claimed to have unlawfully accessed certain Company information and data.”
Not yet quantified
VVerifiedRetail and Consumer
F5, INC.Oct 2025
Filing excerpt“On August 9, 2025, F5, Inc. (the "Company", "F5", "we", or "our") learned that a highly sophisticated nation-state threat actor had gained unauthorized access to certain Company systems.”
Not yet quantified
VVerifiedTechnology and Software
BK Technologies CorpOct 2025
Filing excerpt“Material cybersecurity incident disclosed. As part of the Company’s investigation into this incident, it appears that an unauthorized third-party may have obtained access to and acquired non-public information within the Company’s custody and control, which potentially includes records pertaining to current and former employees.”
Not yet quantified
VVerifiedManufacturing
RTX CorpSep 2025
Filing excerpt“On September 19, 2025, RTX Corporation (the " Company ") became aware of a product cybersecurity incident involving ransomware on systems that support its Multi-User System Environment (" MUSE ") passenger processing software. On September 19, 2025, RTX Corporation (the “Company”) became aware of a product cybersecurity incident involving ransomware on systems that support its Multi-User System Environment (“MUSE”) passenger processing software. This software enables multiple airlines to share check-in and gate resources at airports, including baggage handling. The MUSE airport systems operate outside of the RTX enterprise network, residing on customer-specific networks.”
Not yet quantified
VVerifiedManufacturing
PROSPER MARKETPLACE, INCSep 2025
Filing excerpt“Material cybersecurity incident disclosed. While the Company’s investigation is ongoing, the Company has evidence that confidential, proprietary, and personal information, including Social Security numbers, was obtained, including through unauthorized queries made on Company databases that store customer and applicant data. ”
The company did not separately quantify the cost of the cyber incident. It was reported within a larger charge that also included professional-services increase (incident legal one component). The cyber-specific amount is not determinable from the disclosure.
Not separately
quantified
Financial Services
Graded revision trail
2025-11-13$600KVVerifiedSEC 10-Q ↗
DATA I/O CORPSep 2025
Filing excerpt“Item 7.01 Regulation FD Disclosure Item 9.01 Financial Statements and Exhibits Item 1.05 Material Cybersecurity Incidents.”
Quantified 218 days after disclosure.
$388K
Direct expense
VVerifiedManufacturing
Graded revision trail
2026-04-16$388KVVerifiedSEC 10-K ↗
EVERTEC, Inc.Aug 2025
Filing excerpt“Sinqia S.A. (“Sinqia”), a Brazilian subsidiary of EVERTEC, Inc. (“Evertec” or the “Company”), identified unauthorized activity in its environment of the Brazilian Central Bank (“BCB”) real-time payment system known as Pix. Upon detecting the incident, and in accordance with its incident response protocol, Sinqia halted transaction processing in its Pix environment and began working with outside cybersecurity forensics experts.”
Not yet quantified
VVerifiedTechnology and Software
WYTEC INTERNATIONAL INCAug 2025
Filing excerpt“On August 25, 2025 , Wytec International, Inc. (the "Company") became aware of a cybersecurity incident in which a bad actor published a defaced website at the Company's web address, wytecintl.com.”
Not yet quantified
VVerifiedTelecommunications
Salarius Pharmaceuticals, Inc.Aug 2025
Filing excerpt“Material cybersecurity incident disclosed.”
Not yet quantified
VVerifiedHealthcare and Life Sciences
OMNICOM GROUP INC.Aug 2025
Filing excerpt“Material cybersecurity incident disclosed.”
Not yet quantified
VVerifiedProfessional and Business Services
Ingram Micro Holding CorpJul 2025
Filing excerpt“On July 5, 2025, Ingram Micro Holding Corporation (the "Company") issued a press release stating the Company identified ransomware on certain of its internal systems.”
Not yet quantified
VVerifiedWholesale and Distribution
ALASKA AIR GROUP, INC.Jun 2025
Filing excerpt“On June 23, 2025, Hawaiian Airlines, an Alaska Air Group, Inc. ("we" or "the Company") subsidiary, identified a cybersecurity incident affecting certain information technology systems. Upon learning of this event, we immediately took steps to safeguard Hawaiian's operations and systems.”
Not yet quantified
VVerifiedTransportation and Logistics
UNITED NATURAL FOODS INCJun 2025
Filing excerpt“As previously disclosed in a Current Report on Form 8-K filed with the Securities and Exchange Commission ("SEC") on June 9, 2025 (the "Prior 8-K"), on June 5, 2025, United Natural Foods, Inc. (the "Company") became aware of unauthorized activity on certain information technology (IT) systems. The event impacted both order and fulfillment systems.”
$400M
Business interruption
VVerified
$50M
Business interruption
VVerified
shown separately · not a total
Wholesale and Distribution
NUCOR CORPMay 2025
Filing excerpt“As disclosed in the Original Form 8-K, the Company recently experienced a cybersecurity incident affecting certain information technology systems used by the Company. The Company's investigation revealed that a threat actor illegally accessed the Company's information technology systems.”
Not yet quantified
VVerifiedManufacturing
AFLAC INCJun 2025
Filing excerpt“On June 12, 2025, Aflac Incorporated, a Georgia corporation (the "Company"), identified unauthorized access to its network. The Company promptly initiated its cybersecurity incident response protocols and believes that it contained the intrusion within hours.”
Not yet quantified
VVerifiedHealthcare and Life Sciences
Zoomcar Holdings, Inc. (ZCAR, ZCARW)Jun 2025
Filing excerpt“On June 9, 2025, Zoomcar Holdings, Inc. (the "Company") identified a cybersecurity incident involving unauthorized access to its information systems.”
Not yet quantified
VVerifiedTransportation and Logistics
ERIE INDEMNITY COJun 2025
Filing excerpt“Material cybersecurity incident disclosed.On June 7, 2025, Erie Indemnity Company (the "Company") identified unusual network activity, which the Company determined to be the result of an information security event. Upon learning of this activity, the Company activated its incident response protocols and took immediate action to respond to the situation to safeguard our systems. The Company also notified and is working with law enforcement.”
Not yet quantified
VVerifiedFinancial Services
Coinbase Global, Inc.May 2025
Filing excerpt“On May 11, 2025, Coinbase, Inc., a subsidiary of Coinbase Global, Inc. ("Coinbase" or the "Company"), received an email communication from an unknown threat actor claiming to have obtained information about certain Coinbase customer accounts, as well as internal Coinbase documentation, including materials relating to customer-service and account-management systems.”
Not yet quantified
VVerifiedFinancial Services
NUCOR CORPMay 2025
Filing excerpt“Nucor Corporation (the "Company") recently identified a cybersecurity incident involving unauthorized third party access to certain information technology systems used by the Company.”
Not yet quantified
VVerifiedManufacturing
Global Crossing Airlines Group Inc. (JETBF, JETMF)May 2025
Filing excerpt“Discovery of and Response to Cybersecurity Incident On May 5, 2025, Global Crossing Airlines Group Inc. (the "Company") learned of unauthorized activity within its computer networks and systems supporting portions of its business applications, which the Company determined to be the result of a cybersecurity incident.”
Not yet quantified
VVerifiedTransportation and Logistics
CONDUENT IncApr 2025
Filing excerpt“On January 13, 2025, Conduent Incorporated (the "Company") experienced an operational disruption and learned that a 'threat actor' gained unauthorized access to a limited portion of the Company's environment. Due to the complexity of the files, the Company engaged cybersecurity data mining experts to evaluate the exfiltrated data and was recently informed of its nature, scope and validity, confirming that the data sets contained a significant number of individuals’ personal information associated with our clients' end-users. ”
Quantified 23 days after disclosure.
$25M
Direct expense
VVerifiedProfessional and Business Services
Graded revision trail
2025-05-07$25MVVerifiedSEC 10-Q ↗
DAVITA INC.Apr 2025
Filing excerpt“On April 12, 2025, DaVita Inc. (the "Company" or "we") became aware of a ransomware incident that has encrypted certain elements of our network. Upon discovery, we activated our response protocols and implemented containment measures, including proactively isolating impacted systems.”
Quantified 198 days after disclosure.
$25M
Direct expense
VVerifiedHealthcare and Life Sciences
Graded revision trail
2025-10-29$25MVVerifiedSEC 10-Q ↗
Sensata Technologies Holding plcApr 2025
Filing excerpt“On April 6, 2025, Sensata Technologies Holding plc (the "Company") experienced a ransomware incident that has encrypted certain devices in the Company's network. While the Company has implemented interim measures to allow for the restoration of certain functions, the timeline for a full restoration is not yet known. The preliminary investigation has identified evidence that files were taken from the Company’s environment. ”
Not yet quantified
VVerifiedManufacturing
LEE ENTERPRISES, IncFeb 2025
Filing excerpt“As previously disclosed in the Original Form 8-K, the Company experienced a system outage on February 3, 2025, caused by a cybersecurity attack by threat actors who unlawfully accessed the Company's network, encrypted critical applications, and exfiltrated certain files (the "Incident").”
Quantified 358 days after disclosure.
$10.5M
VVerifiedMedia and Entertainment
Graded revision trail
2026-02-11$10.5MVVerifiedSEC 10-Q ↗
NATIONAL PRESTO INDUSTRIES INCMar 2025
Filing excerpt“On March 1, 2025, the Registrant experienced a system outage caused by a cybersecurity incident. Upon discovery, the Registrant activated its incident response team, comprised of internal personnel and external cybersecurity experts retained to assist in addressing the incident.”
Not yet quantified
VVerifiedManufacturing
NIOCORP DEVELOPMENTS LTD (NB, NIOBW)Feb 2025
Filing excerpt“On February 14, 2025, NioCorp Developments Ltd. (the "Company") became aware of unauthorized third-party access to its information systems, including portions of its email systems, that resulted in misdirected vendor payments totaling approximately $0.5 million (the "cybersecurity incident").”
Quantified 78 days after disclosure.
$506K
Reimbursement / theft
VVerifiedMining and Minerals
Graded revision trail
2025-05-08$10KVVerifiedSEC 10-Q ↗
LEE ENTERPRISES, IncFeb 2025
Filing excerpt“On February 3, 2025, Lee Enterprises, Inc. ("Lee" or the "Company") experienced a systems outage caused by a cybersecurity attack. The incident impacted the Company’s operations, including distribution of products, billing, collections, and vendor payments. ”
Quantified 358 days after disclosure.
$10.5M
VVerifiedMedia and Entertainment
Graded revision trail
2026-02-11$11MVVerifiedSEC 10-Q ↗
GLOBE LIFE INC. (GL, GL-PD)Oct 2024
Filing excerpt“As disclosed on October 17, 2024, Globe Life Inc. (the "Company") received communications from an unknown threat actor seeking to extort money from the Company in exchange for not disclosing certain information held and used by the Company and its independent agents.”
Not yet quantified
VVerifiedFinancial Services
ENGLOBAL CORPNov 2024
Filing excerpt“As previously reported in the Original Form 8-K, on November 25, 2024, the Company became aware of a cybersecurity incident. The preliminary investigation revealed that a threat actor illegally accessed the Company's information technology ("IT") system and encrypted some of its data files.”
Not yet quantified
VVerifiedProfessional and Business Services
LKQ CORPDec 2024
Filing excerpt“On November 13, 2024, LKQ Corporation (the "Company" or "we") detected unauthorized access to information technology (IT) systems of a single business unit in Canada ("Business Unit"). The attack disrupted the Business Unit's operations.”
Not yet quantified
VVerifiedWholesale and Distribution
Krispy Kreme, Inc.Dec 2024
Filing excerpt“On November 29, 2024, Krispy Kreme, Inc. (the "Company") was notified regarding unauthorized activity on a portion of its information technology systems.As of the date of this filing, the incident has had and is reasonably likely to have a material impact on the Company’s business operations until recovery efforts are completed. The expected costs related to the incident, including the loss of revenues from digital sales during the recovery period, fees for our cybersecurity experts and other advisors, and costs to restore any impacted systems, are reasonably likely to have a material impact on the Company’s results of operations and financial condition.”
Quantified 148 days after disclosure.
$4.4M
Direct expense
VVerified
$11M
Business interruption
VVerified
$10M
Business interruption
VVerified
$5M
Business interruption
VVerified
shown separately · not a total
Retail and Consumer
Graded revision trail
2025-05-08$4.4MVVerifiedSEC 10-Q ↗
ARTIVION, INC.Dec 2024
Filing excerpt“Artivion, Inc. ("Artivion" or the "Company") identified and began taking measures to address a cybersecurity incident on November 21, 2024.”
Quantified 436 days after disclosure.
The company reported this as a combined incident total. The split across incident-related expense and revenue and margin impact was not separately disclosed.
$4.6M
Total incident cost
VVerified
$3.5M
Direct expense
Healthcare and Life Sciences
Graded revision trail
2026-02-18$3.5MVVerifiedSEC 10-K ↗
iLearningEngines, Inc. (AILE, AILEW)Nov 2024
Filing excerpt“The ongoing investigation has revealed that a threat actor illegally accessed the Company's environment and certain files on its network, misdirected a $250,000 wire payment, and deleted a number of email messages. The wire payment has not been recovered.”
Not yet quantified
VVerifiedTechnology and Software
NEWPARK RESOURCES INCOct 2024
Filing excerpt“On October 29, 2024, the Company detected a ransomware cybersecurity incident ("Incident") in which an unauthorized third party gained access to certain of the Company's internal information systems.”
Not yet quantified
VVerifiedProfessional and Business Services
Karat Packaging Inc.Oct 2024
Filing excerpt“On October 18, 2024, Karat Packaging Inc. (the "Company") discovered unauthorized third-party access to its information systems. Upon detecting the incident, the Company activated its cybersecurity response plan to investigate the scope of the incident and to contain the threat.”
Not yet quantified
VVerifiedManufacturing
GLOBE LIFE INC. (GL, GL-PD)Oct 2024
Filing excerpt“Globe Life Inc. (the "Company") recently received communications from an unknown threat actor seeking to extort money from the Company in exchange for not disclosing certain information held and used by the Company and its independent agents.”
Not yet quantified
VVerifiedFinancial Services
HEALTHCARE SERVICES GROUP INCOct 2024
Filing excerpt“On October 9, 2024, Healthcare Services Group, Inc. (the "Company") identified a cybersecurity incident, which involved unauthorized activity within some of its systems.”
Not yet quantified
VVerifiedHealthcare and Life Sciences
ADT Inc.Oct 2024
Filing excerpt“ADT Inc. ("ADT" or the "Company") recently became aware of unauthorized activity on the Company's network, and discovered an unauthorized actor had illegally accessed ADT's network using compromised credentials obtained through a third-party business partner.”
Not yet quantified
VVerifiedProfessional and Business Services
American Water Works Company, Inc.Oct 2024
Filing excerpt“Discovery of and Response to Cybersecurity Incident On October 3, 2024, American Water Works Company, Inc. (the "Company") learned of unauthorized activity within its computer networks and systems, which the Company determined to be the result of a cybersecurity incident. The Company currently believes that none of its water or wastewater facilities or operations have been negatively impacted by this incident. ”
Not yet quantified
VVerifiedEnergy and Utilities
VEEA INC. (PLMI, VEEA, PLMIU, PLMIW, VEEAW)Sep 2024
Filing excerpt“Material cybersecurity incident disclosed.”
Not yet quantified
VVerifiedTechnology and Software
MICROCHIP TECHNOLOGY INCSep 2024
Material cybersecurity incident disclosed. The Company is aware that an unauthorized party claims to have acquired and posted online certain data from the Company’s systems. The Company is investigating the validity of this claim with assistance from its outside cybersecurity and forensic experts.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedTechnology and Software
HALLIBURTON COAug 2024
Filing excerpt“The incident has caused disruptions and limitation of access to portions of the Company’s business applications supporting aspects of the Company’s operations and corporate functions. The Company believes the unauthorized third party accessed and exfiltrated information from the Company’s systems. Note: Halliburton posted $116M in charges but they represented costs incurred that weren't related to the cyber event like severance. The total media reported charges were $35M”
The company did not separately quantify the cost of the cyber incident. It was reported within a larger charge that also included severance costs and asset impairment. The cyber-specific amount is not determinable from the disclosure.
Not separately
quantified
Energy and Utilities
Graded revision trail
2024-11-07$116MVVerifiedSEC 10-Q ↗
DICK'S SPORTING GOODS, INC.Aug 2024
Filing excerpt“On August 21, 2024, the Company discovered unauthorized third-party access to its information systems, including portions of its systems containing certain confidential information. The Company has no knowledge that this incident has disrupted business operations.”
Not yet quantified
VVerifiedRetail and Consumer
MICROCHIP TECHNOLOGY INCAug 2024
Filing excerpt“Material cybersecurity incident disclosed. As a result of the incident, certain of the Company’s manufacturing facilities are operating at less than normal levels, and the Company’s ability to fulfill orders is currently impacted.”
Not yet quantified
VVerifiedTechnology and Software
ENZO BIOCHEM INCAug 2024
Filing excerpt“These agreements, consisting of an Assurance of Discontinuance entered into with the New York Attorney General, a Consent Order, entered into with the New Jersey Attorney General, and an Assurance of Voluntary Compliance, entered into with the Connecticut Attorney General, resolve inquiries previously disclosed in the Company's public filings related to the ransomware attack it experienced in April 2023.”
Quantified 124 days after disclosure.
$3M
VVerifiedHealthcare and Life Sciences
Graded revision trail
2024-12-16$3MVVerifiedSEC 10-Q ↗
ADT Inc.Aug 2024
Filing excerpt“ADT Inc. ("ADT" or the "Company") recently experienced a cybersecurity incident during which unauthorized actors illegally accessed certain databases containing ADT customer order information.”
Not yet quantified
VVerifiedProfessional and Business Services
BASSETT FURNITURE INDUSTRIES INCJul 2024
Filing excerpt“As disclosed in the Original Report, on July 10, 2024, Bassett detected unauthorized occurrences on a portion of its information technology (IT) systems.”
Quantified 428 days after disclosure.
$609K
Direct expense
VVerified
$1M to $2M
Business interruption
VVerified
shown separately · not a total
Manufacturing
Graded revision trail
2025-10-08$609KVVerifiedSEC 10-Q ↗
SONIC AUTOMOTIVE INCJul 2024
Filing excerpt“As previously disclosed in the Original Form 8-K, the Company has experienced disruptions in its access to certain information systems provided to the Company by CDK Global ("CDK") due to a cybersecurity incident experienced by CDK on June 19, 2024 (the "Incident").”
Not yet quantified
VVerifiedRetail and Consumer
META MATERIALS INC.Jul 2024
Filing excerpt“On initial investigation, the Company learned that a former executive officer of the Company deliberately de-activated and cancelled the renewal of the Company’s website, which significantly impacted the Company’s IT systems, including delivery and receipt of electronic email communications from customers, investors and other stakeholders of the Company.”
Not yet quantified
VVerifiedManufacturing
Cencora, Inc.Feb 2024
Filing excerpt“In the Original Report the Company disclosed that it learned, on February 21, 2024, that data from its information systems had been exfiltrated, some of which may contain personal information.”
Not yet quantified
VVerifiedWholesale and Distribution
Crimson Wine Group, LtdJul 2024
Filing excerpt“As previously disclosed on the Current Report on Form 8-K filed by Crimson Wine Group, Ltd. (the "Company") on July 5, 2024 (the "Initial Report"), on June 30, 2024, the Company detected a cybersecurity incident in which an unauthorized third party gained access to certain information systems of the Company.”
Not yet quantified
VVerifiedManufacturing
Cadre Holdings, Inc.Jul 2024
Filing excerpt“On July 15, 2024, Cadre Holdings, Inc. (the "Company") determined that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to certain technology systems of the Company.”
$6.4M
Business interruption
VVerified
$22.3M
Business interruption
VVerified
shown separately · not a total
Healthcare and Life Sciences
AUTONATION, INC.Jul 2024
Filing excerpt“Material cybersecurity incident disclosed. As a result of the incident’s impacts, we currently estimate earnings per share for the quarter ended June 30, 2024, will be negatively impacted by approximately $1.50 per share, without taking into account any potential recoveries related to the incident.”
Quantified 17 days after disclosure.
$43M
Direct expense
VVerifiedRetail and Consumer
Graded revision trail
2024-08-01$43MVVerifiedSEC 10-Q ↗
REPLIGEN CORPJul 2024
Filing excerpt“On July 9, 2024, Repligen Corporation (the “Company”) discovered that an unauthorized third party had accessed certain files on the Company’s information systems. ”
Not yet quantified
VVerifiedHealthcare and Life Sciences
AT&T INC. (T, TBB, TBC, T-PA, T-PC)May 2024
Filing excerpt“On April 19, 2024, AT&T Inc. ("AT&T") learned that a threat actor claimed to have unlawfully accessed and copied AT&T call logs. AT&T immediately activated its incident response process to investigate and retained external cybersecurity experts to assist.”
Not yet quantified
VVerifiedTelecommunications
SONIC AUTOMOTIVE INCJul 2024
Filing excerpt“As previously disclosed on its Current Report on Form 8-K filed on June 21, 2024, Sonic Automotive, Inc. (the "Company") has experienced disruptions since June 19, 2024 in its access to certain information systems provided to the Company by CDK Global ("CDK") due to a cybersecurity incident experienced by CDK (the "Incident").”
Not yet quantified
VVerifiedRetail and Consumer
Crimson Wine Group, LtdJun 2024
Filing excerpt“On June 30, 2024, Crimson Wine Group, Ltd. (the "Company") determined that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to certain technology systems of the Company. The Company is in the early stages of its investigation and assessment of this incident. The full scope of the costs and related impacts of this incident has not been determined. ”
Not yet quantified
VVerifiedManufacturing
HEALTHEQUITY, INC.Jul 2024
Filing excerpt“Material cybersecurity incident disclosed. Earlier this year, HealthEquity, Inc. (the “Company”) became aware, through routine monitoring, of anomalous behavior by a personal use device belonging to a business partner (the “Partner”). The Company promptly took steps to isolate and triage the issue and began an investigation into the nature and scope of the issue. The investigation concluded that the Partner’s user account had been compromised by an unauthorized third party,”
Not yet quantified
VVerifiedProfessional and Business Services
Affirm Holdings, Inc.Jun 2024
Filing excerpt“On June 25, 2024, Evolve Bank & Trust ("Evolve"), the third-party issuer of the Affirm Card, notified the Company that Evolve had experienced a cybersecurity incident whereby a third party gained unauthorized access to personal information and financial information ("Personal Information") of Evolve retail banking customers and the customers of its financial technology partners.”
Not yet quantified
VVerifiedFinancial Services
LITHIA MOTORS INCJun 2024
Filing excerpt“On June 19, 2024, Lithia Motors, Inc. (the "Company") received notice from CDK Global ("CDK"), a third-party provider of certain information systems used by the Company, that CDK had suspended systems used by the Company in response to a cybersecurity incident impacting CDK.”
Not yet quantified
VVerifiedRetail and Consumer
GROUP 1 AUTOMOTIVE INCJun 2024
Filing excerpt“On June 19, 2024, Group 1 Automotive, Inc. ("Group 1" or the "Company") was informed of a cybersecurity incident experienced by CDK Global LLC ("CDK"), which resulted in service outages on CDK's dealers' systems (the "CDK incident"). The CDK incident has disrupted the Company’s business applications and processes in its U.S. operations that rely on CDK’s dealers’ systems.”
Quantified 235 days after disclosure.
$5.9M
Direct expense
VVerifiedRetail and Consumer
Graded revision trail
2025-02-14$5.9MVVerifiedSEC 10-K ↗
PENSKE AUTOMOTIVE GROUP, INC.Jun 2024
Filing excerpt“On June 19, 2024, we became aware that CDK Global, LLC ("CDK"), a provider of dealer management software systems to retail automotive and commercial truck dealerships, was experiencing a cybersecurity incident and its systems were not operational.”
Quantified 496 days after disclosure.
The company reported this as a combined incident total. The split across net-income effect: revenue impact and incident costs, netted was not separately disclosed.
$2.5M
Total incident cost
VVerifiedRetail and Consumer
Graded revision trail
2025-10-30$2.5MVVerifiedSEC 10-Q ↗
SONIC AUTOMOTIVE INCJun 2024
Filing excerpt“On June 19, 2024, CDK Global ("CDK"), a third-party provider of certain information systems used by Sonic Automotive, Inc. (the "Company"), notified its dealership customers that CDK had suspended certain systems, including systems used by the Company, in response to a cybersecurity incident impacting CDK.”
Not yet quantified
VVerifiedRetail and Consumer
GLOBE LIFE INC. (GL, GL-PD)Jun 2024
Filing excerpt“On June 13, 2024, following an inquiry from a state insurance regulator, Globe Life Inc. (the "Company") initiated a review of potential vulnerabilities related to access permissions and user identity management for a Company web portal that likely resulted in unauthorized access to certain consumer and policyholder information.”
Not yet quantified
VVerifiedFinancial Services
KEY TRONIC CORPMay 2024
Filing excerpt“As disclosed in the Original Report, on May 6, 2024, the Company detected unauthorized third party access to portions of its information technology ("IT") systems (the "cybersecurity incident").”
Quantified 53 days after disclosure.
$2.3M
Direct expense
VVerified
$15M
Business interruption
VVerified
shown separately · not a total
Manufacturing
Graded revision trail
2024-08-06$2.3MVVerifiedSEC 8-K/A ↗
KULICKE & SOFFA INDUSTRIES INCMay 2024
Filing excerpt“On May 28, 2024, Kulicke and Soffa Industries, Inc. (the "Company") announced that on May 12, 2024, it detected unauthorized access attempts into its network and servers.”
Not yet quantified
VVerifiedTechnology and Software
BRANDYWINE REALTY TRUSTMay 2024
Filing excerpt“On May 1, 2024, Brandywine Realty Trust (the "Company") detected what was determined to be a cybersecurity incident, whereby a third party gained unauthorized access to portions of its information technology ("IT") environment. The cybersecurity incident consisted of unauthorized access and deployment of encryption by a third party to a portion of the Company’s internal corporate IT systems. The incident caused disruptions to, and limitation of access to, portions of the Company’s business applications”
Not yet quantified
VVerifiedReal Estate and Construction
DocGo Inc.May 2024
Filing excerpt“DocGo Inc. (the "Company") recently identified a cybersecurity incident involving certain of the Company's systems.As part of its investigation, the Company has determined that the threat actor accessed and acquired data, including certain protected health information, from a limited number of healthcare records within the Company’s U.S.-based ambulance transportation business.”
Not yet quantified
VVerifiedHealthcare and Life Sciences
DROPBOX, INC.Apr 2024
Filing excerpt“On April 24, 2024, Dropbox, Inc. (" Dropbox " or " we ") became aware of unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. We immediately activated our cybersecurity incident response process to investigate, contain, and remediate the incident.”
Not yet quantified
VVerifiedTechnology and Software
UNITEDHEALTH GROUP INCFeb 2024
Filing excerpt“As an update to information concerning the Change Healthcare cyberattack contained in the Filed Reports, the Company issued a press release on April 22, 2024, regarding its ongoing data assessment and support for impacted individuals, support for providers and customers with notifications, and Change Healthcare service restoration progress.”
Quantified 15 days after disclosure.
$340M
Direct expense
VVerifiedHealthcare and Life Sciences
Graded revision trail
2024-05-09$340MVVerifiedSEC 10-Q ↗
Frontier Communications Parent, Inc.Apr 2024
Filing excerpt“On April 14, 2024, Frontier Communications Parent, Inc. (the "Company") detected that a third party had gained unauthorized access to portions of its information technology environment. Based on the Company’s investigation, it has determined that the third party was likely a cybercrime group, which gained access to, among other information, personally identifiable information.”
Not yet quantified
VVerifiedTelecommunications
ORASURE TECHNOLOGIES INCApr 2024
Filing excerpt“On or about March 27, 2024, OraSure Technologies, Inc. (the "Company") became aware of a cybersecurity incident in which an unauthorized third party gained access to Company data from certain information systems.”
Not yet quantified
VVerifiedHealthcare and Life Sciences
B. Riley Financial, Inc. (RILY, RILYG, RILYK, RILYL, RILYM, RILYN, RILYP, RILYT, RILYZ)Apr 2024
Filing excerpt“Riley Financial, Inc. (the "Company"), discovered that a threat actor gained unauthorized access to certain of Targus' file systems. On April 5, 2024, Targus International, LLC and certain affiliates (collectively, “Targus”), each of which is an indirect subsidiary of B. Riley Financial, Inc. (the “Company”), discovered that a threat actor gained unauthorized access to certain of Targus’ file systems. ”
Not yet quantified
VVerifiedFinancial Services
MARINEMAX INCMar 2024
Filing excerpt“As disclosed in the Original Report, on March 10, 2024, we determined that the Company experienced a "cybersecurity incident," as defined in applicable SEC rules, whereby a third party gained unauthorized access to portions of our information environment (the "Incident").”
Not yet quantified
VVerifiedRetail and Consumer
SouthState CorpFeb 2024
Filing excerpt“Upon detection, SouthState initiated its incident response and business continuity protocols and began taking measures to disrupt the unauthorized activity. In addition, SouthState has been conducting an investigation.”
Not yet quantified
VVerifiedFinancial Services
RADIANT LOGISTICS, INCMar 2024
Filing excerpt“On or about March 14, 2024, through its information technology systems monitoring tools, Radiant Logistics, Inc. (the "Company") detected what was determined to be the initial stages of a cybersecurity incident related to its Canadian operations. While the incident in combination with the Company’s security protocols have caused service delays for customers in Canada, systems recovery efforts are in process”
Not yet quantified
VVerifiedTransportation and Logistics
MICROSOFT CORPJan 2024
Filing excerpt“As disclosed in the Original Filing, the Company detected that beginning in late November 2023, a nation-state threat actor had gained access to and exfiltrated information from a very small percentage of employee email accounts including members of our senior leadership team and employees in our cybersecurity, legal, and other functions.”
Not yet quantified
VVerifiedTechnology and Software
Federal Home Loan Bank of New YorkFeb 2024
Filing excerpt“On February 21, 2024, the Federal Home Loan Bank of New York ("Bank"), through its operational controls, detected unknown persons attempting to fraudulently obtain funds from the Bank (the "incident").”
Not yet quantified
VVerifiedFinancial Services
loanDepot, Inc.Jan 2024
Filing excerpt“As disclosed in the Original Report, as further amended by Amendment No. 1, the Company identified a cybersecurity incident, which it has contained. Our engagement with law enforcement and regulators continues.”
The company reported this as a combined incident total. The split across incident response expense and litigation settlements was not separately disclosed.
$24.6M
Total incident cost
VVerified
$1.8M
Direct expense
Financial Services
PRUDENTIAL FINANCIAL INC (PFH, PRH, PRS, PRU)Feb 2024
Filing excerpt“As disclosed in the Original Report, on February 5, 2024, we detected that, beginning February 4, 2024, a threat actor had gained unauthorized access to certain of our systems.”
Not yet quantified
VVerifiedFinancial Services
WILLIS LEASE FINANCE CORPFeb 2024
Filing excerpt“Material cybersecurity incident disclosed. An investigation into the nature and scope of the incident was launched with the assistance of leading third-party cybersecurity experts and the Company took steps to contain, assess and remediate the activity, including taking certain systems offline.”
Not yet quantified
VVerifiedFinancial Services
Hewlett Packard Enterprise CoJan 2024
Filing excerpt“On December 12, 2023, Hewlett Packard Enterprise Company (the "Company," "HPE," or "we") was notified that a suspected nation-state actor, believed to be the threat actor Midnight Blizzard, the state-sponsored actor also known as Cozy Bear, had gained unauthorized access to HPE's cloud-based email environment.”
Not yet quantified
VVerifiedTechnology and Software
V F CORPDec 2023
Filing excerpt“As disclosed in the Original Report, on December 13, 2023, VF detected unauthorized occurrences on a portion of its information technology (IT) systems.”
Not yet quantified
VVerifiedManufacturing
First American Financial CorpDec 2023
Filing excerpt“As disclosed in the Original Report, the Company identified unauthorized activity on certain of its information technology systems. Upon detection, the Company acted to contain, assess and remediate the incident.”
Not yet quantified
VVerifiedFinancial Services
Fidelity National Financial, Inc.Nov 2023
Filing excerpt“On November 19, 2023, the Company became aware of a cybersecurity incident that impacted certain of our systems. We determined that an unauthorized third-party accessed certain FNF systems, deployed a type of malware that is not self-propagating, and exfiltrated certain data.”
Not yet quantified
VVerifiedFinancial Services
First American Financial CorpDec 2023
Filing excerpt“As disclosed in the Original Report, the Company recently identified unauthorized activity on certain of its information technology systems. Upon detection of the unauthorized activity, the Company took steps in an effort to contain, assess and remediate the incident.”
Not yet quantified
VVerifiedFinancial Services
← Back to the index