← The Hacker in a Hoodie Index  ·  complete ledger
Hacker in a Hoodie Index
Media Reported Incidents · complete ledger

Company results statements (Attested), and outside estimates and news reports (Inferred), approved to this index. No Verified grade appears here; that grade is reserved for the primary filings in the 8-K Scoreboard. This is the complete record for this feed, uncapped, and like everything on this index it is never summed.

17 approved media-reported incidents, most recent first. The complete record, nothing hidden, never summed.
The revision trail
A cost figure arrives after an incident is disclosed, and it moves as stronger sources report it. Early estimates run below the figure a company eventually discloses. The amount shown for each incident is its most recent claim; the trail beneath it is every claim in order, each with its date, its source, and its grade, from an Inferred estimate to an Attested company figure.
Corrections
Every figure on this ledger is drawn from its cited source and links to it. If we have read one wrong, tell us: info@hackerinahoodie.com.
SunoJul 2026
404 Media disclosed that Suno was breached in Nov 2025, as confirmed by HaveIBeenPwnd. Suno has not yet publicly disclosed the cyberattack or notified individuals that their information was taken, and has refused to answer reporter questions on this matter.
Security analyst report
Not yet quantified
IInferredTechnology and Software
Ecopetrol2026-07
The Colombian state-controlled ‌energy company Ecopetrol announced on Friday that a cyberattack resulted in the theft of data tied to about 3,300 user accounts ​and that it could not "guarantee" the breach would ​not have a "material adverse" financial impact.
News: Reuters
Not yet quantified
IInferredEnergy and Utilities
Coca-Cola2026-07
The Coca-Cola Co. said a cyberattack has forced it to temporarily halt its Fairlife milk operations in the U.S. "The full scope, nature, and impacts of the incident are not yet known," Coca-Cola said in a statement. It added that the breach has not affected product quality or safety.
News: CBS News
Not yet quantified
IInferredRetail and Consumer
Abbott2026-07
Abbott did not disclose what kind of information was accessed. The company declined to respond further to MedTech Dive’s request for comment regarding when the attack was discovered and what kind of information was accessed.
News: MedTech Dive
Not yet quantified
IInferredHealthcare and Life Sciences
StadlerJul 2026
Stadler refuses to pay ransom to the Everest hacking group, claims core IT systems were not hacked. ENISA warned that the railway sector’s growing strategic importance was outpacing its ability to manage cyber risks. Findings point to weaknesses highlighted by the Stadler breach. Only 35% of railway companies surveyed regularly assessed the effectiveness of their cybersecurity controls, while 50% did so on an ad hoc basis. Just 25% regularly tested business-continuity and disaster-recovery arrangements.
Media report
Not yet quantified
IInferredTransportation and Logistics
Centers Lab NJ LLC2026-07
Healthcare diagnostics company Centers Laboratory (Centers Lab NJ LLC) has informed the US government that a data breach discovered nearly one year ago affects more than 540,000 individuals.
News: SecurityWeek
Not yet quantified
IInferredHealthcare and Life Sciences
Ernst & YoungJul 2026
Ernst & Young has disclosed a data breach that resulted in the theft of clients' personal information. From March 28 to April 12, attackers had access to a third-party support ticket system containing customer information related to their tax affairs.
Company announcement to media
Not yet quantified
AAttestedProfessional and Business Services
Mount Royal University2026-07
Mount Royal University Confirms Data Stolen in Ransomware Attack.
News: SecurityWeek
Not yet quantified
IInferredPublic Sector and Education
Accenture2026-07
Accenture faces massive data breach that could put clients at risk.
News: Cybersecurity Dive
Not yet quantified
IInferredProfessional and Business Services
Medtronic2026-07
Medtronic Notifies 3.8M Individuals About April 2026 Cyberattack.
News: The HIPAA Journal
Not yet quantified
IInferredHealthcare and Life Sciences
Jaguar Land RoverSep 2025
Production-halting attack. ~$2.5B economic damage, per an external monitoring-centre model.
Third-party estimate
Quantified; lag not tracked, this figure predates the index.
~$2.5B
IInferredManufacturing
Graded revision trail
pre-index~$2.5BIInferredThird-party estimate
Marks & SpencerApr 2025
Ransomware. The company stated an operating-profit impact of roughly 300M pounds sterling in its results.
Company results statement
Quantified; lag not tracked, this figure predates the index.
~$400M
AAttestedRetail and Consumer
Graded revision trail
pre-index~$400MAAttestedCompany results statement
PowerSchool2026-07
PowerSchool Data Breach: What Happened, Who Did It, and What Families Should Do.
News: Security.org
Quantified 130 days after disclosure.
$34M
IInferredPublic Sector and Education
Graded revision trail
2025-05-07$34MIInferredMedia Report ↗
Change Healthcare (UnitedHealth Group)Feb 2024
Ransomware through the Change Healthcare unit halted US medical claims and payments for weeks. UnitedHealth reported its full-year 2024 cyberattack costs in company results.
Company results statement
Not yet quantified
AAttestedHealthcare and Life Sciences
Ascension12/05/2024
Acension stated $1.3 bn as the total overall operational impact from a successful ransomware attack.
Company PR statements
$1.3B
AAttestedHealthcare and Life Sciences
Graded revision trail
undated$1.3BAAttestedCompany PR statements ↗
CDK06/19/2024
CDK's ransomware event drove an immediate payment of $25mm in Bitcoin payments to the BlackSuit ransomware gang. A year before the incident CDK was acquired by a private equity organization, effectively turning it into a private company. Several public companies were impacted, resulting in 8k filings that show in excess of $1bn losses across the automotive industry.
Company announcement
$25mm
AAttestedTechnology and Software
Graded revision trail
undated$25mmAAttestedCompany announcement ↗
CranewareJul 2020
Filing excerpt““The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data,” Craneware said, although it added that an investigation by internal IT staff and third-party cybersecurity firms was ongoing.”
Not yet quantified
AAttestedHealthcare and Life Sciences
← Back to the index