Live Cuts

Recomputed on every build. As of September 7, 2026.

What a live cut is

A live cut is a reading of this index’s own ledger, computed from the incidents tracked here. It is a count, never a sum. It moves as the record does: every figure on this page is recomputed on each build.

Two cuts draw on outside feeds, shown alongside the ledger and never merged with it: the ransomware leak-site activity (ransomware.live) and the ITRC breach-transparency context. For outside primary-source evidence held to the Exhibit Rule, see the Exhibits.

Live Cuts

FROM THE LEDGER · SHARE OF ITEM 1.05 FILINGS

Most “material” cyber filings report no dollar figure

n = 53 filings
A company files an SEC 8-K under Item 1.05 only when a cyber incident is material to investors — a statement about size. Of the 53 such filings on this ledger, 40 state no dollar amount at all: 75.5% material, unpriced.
carries a figure (13)   no figure (40)

Each cell is one approved primary Item 1.05 filing on this ledger; every one links to its 8-K, and the count is verifiable filing by filing.

Item 1.05 materiality can rest on non-financial factors, and a cost is often unknown when the 8-K is filed. That is the point: the disclosure built to signal significance rarely carries its size.

THE FLOOR · A count of filings tracked to date, not a census of all disclosures.

FROM THE LEDGER · SHARE OF INCIDENTS WITH A DOLLAR FIGURE

Most incidents on this ledger carry no dollar figure

n = 187 incidents
A dollar figure appears on just 27 of the 187 incidents tracked here. For 160 of them — 85.6% — the cost is absent: unknown, not yet disclosed, or never quantified. A missing number is not a small loss; it is an unmeasured one.
85.6%of tracked incidents carry no dollar figure

The silence holds across both feeds: a figure appears on 25 of 115 government-record incidents and 2 of 72 beyond the filings. Each is an approved primary record; a count of incidents, never a sum of dollars.

Enforcement and registry records (state-attorney-general notices, regulator actions, the HHS OCR breach portal) are not counted here: their money is a penalty or none at all, not an incident cost, so they are neither priced nor silent. 76 such records are set aside.

A missing figure is not a loss of zero. It means the cost is unknown, not yet disclosed, or never quantified. The absence is the finding: the public record of what cyber costs is mostly blank.

THE FLOOR · A count of incidents tracked to date, not a census of all breaches.

FROM THE LEDGER · INCIDENT COUNT

Tracked incidents by sector

n = 263 incidents
A count of incidents, not dollars; each bar is that sector’s share of the 263 tracked incidents.

263 incidents shown, tagged approved primaries. 0 more are pending a sector and are not yet placed. 19 corroborations nest under their primary incidents and are not counted separately. So 263 plus 0 pending is 263 primaries, and the corroborations are nested, not missing.

Share of incidents tracked on this ledger, not of all breaches. Healthcare leads partly because mandatory breach-disclosure rules in that sector put more of its incidents into the public record, not because it is necessarily attacked more often.

THE FLOOR · This count is a floor, the incidents tracked to date, not a census of all breaches.

LIVE CUT · RANSOMWARE LEAK-SITE ACTIVITY · SOURCE: RANSOMWARE.LIVE

Ransomware leak sites named 86 organizations in the last 7 days

a sample of one attack type
A directional count of victims posted to ransomware groups’ leak sites, broken out by sector. Postings, not confirmed breaches, and never a dollar figure. A separate outside feed, ransomware.live, shown alongside the record and never summed with it.

31,532 organizations tracked across 396 groups since 2005, per ransomware.live.

Provided as-is by an independent project; postings can lag or be revised, and a claimed victim is not a confirmed breach. A count of leak-site postings, never summed and never a cost.

Source: ransomware.live → · updated 2026-09-05

CONTEXT · U.S. DATA COMPROMISES · SOURCE: ITRC

A record pace of breaches, and the least disclosed on record

First half of 2026
An outside benchmark: Identity Theft Resource Center’s count of publicly reported U.S. data compromises. A different measure than this index’s primary-source cost ledger — a national count of breach events, not a total of dollars — shown for scale and never summed with the record.
1,803
U.S. data compromises
first half of 2026, on pace for a record ~3,600
471M
victim notices
more than all of 2025
24%
of notices named an attack vector
the lowest transparency ITRC has ever recorded

2025 set a record at 3,322 U.S. compromises; ITRC has tracked more than 25,200 over its 20-year history.

ITRC counts publicly reported compromises from news, government, and company sources; figures can be revised as more is disclosed. A count of events and notices, never a dollar figure and never merged with this ledger.

Source: Identity Theft Resource Center · H1 2026 Data Breach Report →

FROM THE LEDGER · HOW THE BREACH HAPPENED

Most incidents never say how the attacker got in

n = 261 classified
Of the 261 incidents classified so far, 86 disclosed the initial attack type — 33% — while 175 left it undisclosed. Companies say what was taken; they rarely say how. This is the Index’s own read on the gap, counted from the ledger, never summed.
67%of classified incidents never disclosed the initial attack type
What the attacks did:

The national picture agrees: ITRC records that only about a quarter of breach notices name how the attacker got in, the lowest on record. See the ITRC context card above.

Initial attack type graded confirmed (the source states it) or inferred (circumstantial); undisclosed is the honest majority. A count of incidents by attack type, never a dollar figure and never summed.

THE FLOOR · Counted from incidents classified to date, not a census of all attacks.

Exhibits, outside primary-source evidence →  ·  ← Back to the index