Cybersecurity Incidents Data API
The Cybersecurity Incidents Data API provides access to a database of cybersecurity incidents, extracted from material event disclosures filed under Item 1.05 of Form 8-K: "Material Cybersecurity Incidents." A company must file Item 1.05 when it has a cybersecurity incident that it determines to be material. The company must describe the material aspects of the nature, scope and timing of the incident, and the material impact or reasonably likely material impact on the company, including its financial condition and results of operations. The filing is due within four business days after the company determines that the incident is material. Item 1.05 became effective in December 2023.
| Filed at | Ticker | Company | Materiality | Filing role | Attack types | Threat actor | Detected | Data status | Data categories | Operational impact | Financial impact | Stated cost | Law enforcement | Incident key | CIK | Accession no. | Details |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026-08-31 | NUTX | Nutex Health Inc. | not_stated | new_8k_update | data_exfiltration; unauthorized_access | not_stated | – | exfiltrated_confirmed | patient; employee; provider; proprietary_business; financial_information | none_identified | unable_to_determine | – | Yes | 1479681-2026-08-11 | 1479681 | 0001628280-26-059602 | |
| 2026-07-02 | NAVI | Navient Corp | determined_material | initial | ransomware; unauthorized_access | not_stated | 2026-06-08 | accessed_confirmed | customer; pii; ssn; dob; contact_info | none_identified | not_material_expected | – | Yes | 1593538-2026-06-29 | 1593538 | 0001140361-26-027441 | |
| 2026-05-11 | CBFV | CB Financial Services, Inc. | determined_material | initial | unauthorized_ai_tool_use; insider | insider | 2026-05-05 | accessed_confirmed | customer; ssn; dob; pii | none_identified | not_material_expected | – | – | 1605301-2026-05-07 | 1605301 | 0001605301-26-000021 | |
| 2026-04-08 | BTM | Bitcoin Depot Inc. | determined_material | initial | unauthorized_access; credential_compromise; digital_asset_theft | not_stated | 2026-03-23 | no_evidence | – | none_identified | not_material_expected | $3,665,000.00 | Yes | 1901799-2026-04-06 | 1901799 | 0001193125-26-147772 | |
| 2025-05-15 | COIN | Coinbase Global, Inc. | not_stated | initial | insider; data_exfiltration | not_stated | 2025-05-11 | exfiltrated_confirmed | customer; contact_info; pii; ssn_partial; financial_account_partial; government_id; transaction_history; proprietary_business | none_identified | unable_to_determine | – | Yes | 1679788-2025-05-14 | 1679788 | 0001679788-25-000094 | |
| 2024-12-11 | DNUT | Krispy Kreme, Inc. | determined_material | initial | unauthorized_access | not_stated | 2024-11-29 | not_stated | – | material_disruption | material_expected | – | Yes | 1857154-2024-12-11 | 1857154 | 0001857154-24-000123 | |
| 2024-07-12 | T | AT&T Inc. | determined_not_material | initial | unauthorized_access; data_exfiltration | not_stated | 2024-04-19 | exfiltrated_confirmed | call_records; contact_info; customer; location_data | none_identified | not_material_expected | – | Yes | 732717-2024-05-06 | 732717 | 0000732717-24-000046 | |
| 2024-06-14 | KTCC | Key Tronic Corp | determined_material | amendment_update | unauthorized_access; data_exfiltration | not_stated | 2024-05-06 | exfiltrated_confirmed | pii | temporary_disruption | material_expected | $600,000.00 | Yes | 719733-2024-05-06 | 719733 | 0000719733-24-000035 | |
| 2024-01-19 | MSFT | MICROSOFT CORP | not_yet_determined | initial | unauthorized_access; data_exfiltration | nation_state | 2024-01-12 | exfiltrated_confirmed | unspecified_confidential; pii | none_identified | unable_to_determine | – | Yes | 789019-2024-01-17 | 789019 | 0001193125-24-011295 | |
| 2023-12-18 | VFC | V F CORP | determined_material | initial | ransomware; data_exfiltration | not_stated | 2023-12-13 | exfiltrated_confirmed | pii | material_disruption | unable_to_determine | – | Yes | 103379-2023-12-15 | 103379 | 0000950123-23-011228 |
The data is extracted from the text disclosed under Item 1.05 and from attached press releases. The data is provided in a structured JSON format. The extracted information includes:
- Materiality conclusion of the company, the date and the reasons of the materiality determination, and disclosure delays under Item 1.05(c) at the request of the U.S. Attorney General
- Detection date, start date, affected subsidiary, and the location of the affected systems, such as own systems, a service provider or a cloud platform
- Attack types, such as ransomware, data exfiltration, social engineering or insider activity, and the type and name of the threat actor
- Ransom demands, ransom payments, leak threats and contact by the threat actor
- Affected data, including the confirmed data categories, the categories under assessment, and the number of affected individuals and accounts
- Operational impact, affected business functions and the status of the restoration
- Financial impact, including the assessment, the affected periods, the effect on guidance, stated costs, direct losses, customer compensation and insurance
- Response actions, and notifications to law enforcement, regulators and affected individuals
- Lawsuits, regulatory inquiries, arrests and executive departures related to the incident
- An incident key that links the first filing about an incident to all later updates about the same incident
- Short quotes from the filing text that support key values
API Endpoint
Search and retrieve structured details about material cybersecurity incidents from Form 8-K filings by sending POST HTTP requests with search parameters as JSON-formatted payload to the following API endpoint:
Supported HTTP methods: POST
Request and response content type: JSON
Authentication
To authenticate your API requests, use the API key available in your user profile. You can use your API key in one of two ways. Choose the method that best fits your implementation:
- Authorization Header: Include your API key as an
Authorizationheader in yourPOSTrequests. For instance, before sending aPOSTrequest tohttps://api.sec-api.io/material-events/cybersecurity-incidents, ensure the header is set as follows:Authorization: YOUR_API_KEY. - Query Parameter: Alternatively, append your API key directly to the URL as a query parameter. For example, when making
POSTrequests, use the URLhttps://api.sec-api.io/material-events/cybersecurity-incidents?token=YOUR_API_KEYinstead of the base endpoint.
Request Parameters
Search material cybersecurity incidents disclosed in Form 8-K filings by sending a search query to the API. All fields of the extracted data are searchable. For a complete list of searchable fields, refer to the Response Structure section below. Send a search query as a JSON-formatted payload to the API using the structure explained below.
Request parameters:
query: string
Your search criteria in the format field:value defining the fields to search in and the values to search for in those fields. The query is written in Lucene syntax and supports boolean operators (AND, OR, NOT), range queries across date and number fields using square brackets ([, ]), wildcards (*) and search expression grouping with normal brackets ((, )). More information on Lucene is available here. Query examples are available below.
from: integer
Specifies the starting position of your results, allowing for pagination. For instance, set from to 50 to skip the first 50 results. Default: 0. Maximum: 10,000, which is also the cap for the maximum number of results returned per query. To retrieve all results in your search universe, increment from by the value of the size parameter (e.g., 50) until no more results are returned or the 10,000 limit is reached. For example, use 0, 50, 100, and so on. If your query locates more than 10,000 results, consider narrowing your search by refining your filter criteria, such as using a date range filter to iterate over months or years. One approach would be to search for items with a filing.filedAt date range filter, e.g., filing.filedAt:[2025-01-01 TO 2025-01-31] (all filings from January 2025), then paginate through the results by incrementing from, and once completed, repeat the process for the next month, and so on.
size: integer
The number of results to be returned per request. Default: 50. Maximum: 50.
sort: array
An array of objects that specify how the returned results are sorted. For example, [{ "filing.filedAt": { "order": "desc" } }] sorts the results by the filing date, most recent filings first. Set order to asc to sort in ascending order.
Request Examples
Find the first disclosures of all ransomware incidents filed in 2025, with the result sorted by the filing date, starting with the most recent filings. Increment the from parameter by 50 on each subsequent request to paginate through the results.
Retrieve the history of an incident for a specific company using its trading symbol (ticker). In this example, the API returns all Item 1.05 disclosures for the company with the ticker symbol "UNH", starting with the first disclosure. To retrieve all filings about one incident, search for its disclosure.incidentKey instead.
Response Structure
Response type: JSON
The API response represents a JSON object with two fields: total (object) and data (array). The total.value field indicates the total number of results matching your search query. The data array holds up to 50 items per request. Each item represents the extracted data from one Form 8-K filing that discloses Item 1.05.
The data contains only facts that the filing text states. A value of null or not_stated, or an empty array, means that the text does not state the fact. Dates use the format YYYY-MM-DD, or YYYY-MM and YYYY when the text gives only the month or the year. Amounts are in USD. Each item has the following structure:
filing: object
Metadata of the Form 8-K filing.
accessionNo: string
Accession number of the filing, e.g. 0000732717-24-000046.
cik: string
Central Index Key (CIK) of the filer, without leading zeros, e.g. 732717.
ticker: string
Trading symbol of the filer, e.g. T. Is null when the filer has no trading symbol.
companyName: string
Name of the filer, e.g. AT&T Inc..
formType: string
EDGAR form type. Possible values: 8-K, 8-K/A.
filedAt: date
Date on which the filing was filed on SEC EDGAR, e.g. 2024-07-12.
periodOfReport: date
Date of the earliest event reported in the filing, e.g. 2024-05-06.
sic: string
Standard Industrial Classification (SIC) code of the filer, e.g. 4813.
otherItems: array of strings
Other Form 8-K items disclosed in the same filing, e.g. ["9.01"].
url: string
URL of the filing folder on SEC EDGAR.
disclosure: object
Materiality conclusion of the company, and how the filing links to other filings about the same incident.
filingRole: string
Role of the filing in the chain of filings about one incident. initial is the first Form 8-K with Item 1.05 about the incident. amendment_update is a Form 8-K/A. new_8k_update is a later Form 8-K that updates an earlier report. Possible values: initial, amendment_update, new_8k_update.
materialityStatus: string
Materiality conclusion as stated in the text. determined_material means that the company determined the incident to be material, or states that the incident had or is reasonably likely to have a material impact on the company. possibly_material means that the text says that the incident "may" be material. not_yet_determined means that the text says that the determination is pending. not_determined means that the text says that the company has not determined that the incident is reasonably likely to have a material impact, and does not say that a determination is pending. reported_without_determination means that the company files the report without a materiality conclusion. determined_not_material means that the company states that the incident is not material, or is not reasonably likely to have a material impact. Possible values: determined_material, possibly_material, not_yet_determined, not_determined, reported_without_determination, determined_not_material, not_stated.
materialityDeterminationDate: date
Date on which the company determined that the incident is material, e.g. 2026-06-29.
materialityBasis: array of strings
Reasons for the materiality conclusion as stated in the text. Possible values: data_volume, data_sensitivity, operational_disruption, financial_impact, precautionary, not_stated, reputational, legal_regulatory, response_costs.
amendmentUndertaking: boolean
Is true when the company states that it will amend the report when more information becomes available.
incidentKey: string
Key that links all filings about one incident. Format: CIK, a hyphen, and the periodOfReport of the earliest Form 8-K about the incident, e.g. 731766-2024-02-21. The earliest Form 8-K can report the incident under any item, e.g. Item 1.05, 7.01 or 8.01. Use this key to get the full history of an incident.
isDeltaUpdate: boolean
Is true when the filing reports only the changes since an earlier filing about the incident. In this case, an empty field does not mean that the fact does not exist.
textSource: string
Parts of the filing from which the data was extracted: the text of Item 1.05, an Exhibit 99 attachment such as a press release, or both. Possible values: item_body, exhibit_99, item_body_and_exhibit.
dojDelayInvoked: boolean
Is true when the text states that the U.S. Attorney General (Department of Justice) determined under Item 1.05(c) that a delay of the disclosure was warranted.
priorDisclosures: array of objects
Earlier Form 8-K filings about the same incident that the text refers to. These are often filings under Item 7.01 or 8.01.
filingDate: date
Filing date of the earlier Form 8-K, e.g. 2026-08-24.
item: string
Item of the earlier Form 8-K, e.g. 8.01.
initiallyAssessedNotMaterial: boolean
Is true when the text states that the company first assessed the incident as not material.
dojDelayDate: date
Date of the Item 1.05(c) delay determination, e.g. 2024-05-09. When the text names more than one determination, the value is the date of the first one.
dojDelayDates: array of dates
Dates of all Item 1.05(c) delay determinations named in the text, e.g. ["2024-05-09", "2024-06-05"].
incident: object
Nature, timing and source of the incident.
detectionDate: date
Date on which the company discovered the incident or was notified of it, e.g. 2024-04-19. When the text gives the date of an outage but no discovery date, the outage date is in incidentStartDate.
detectionDatePrecision: string
Precision of detectionDate as stated in the text. Possible values: day, month, quarter, year, not_stated.
affectedEntity: string
Name of the affected subsidiary when the text names one, e.g. Coupang Corp..
environment: string
Location of the compromised systems or data. own_systems includes cloud tenants that the company owns. Possible values: own_systems, third_party_service_provider, third_party_cloud, third_party_saas_integration, unknown.
thirdPartyType: string
Type of third party involved in the incident, as written, e.g. law firm.
attackTypes: array of strings
Types of attack as stated in the text. Possible values: ransomware, data_exfiltration, social_engineering, phishing, credential_compromise, unauthorized_access, business_email_compromise, ddos, insider, supply_chain, not_stated, malware, vulnerability_exploit, account_takeover, unauthorized_ai_tool_use, website_defacement, digital_asset_theft, payment_fraud.
threatActorNamed: string
Name of the threat actor as written, e.g. Midnight Blizzard (Cozy Bear).
ransomDemandMentioned: boolean
Is true when the text mentions a ransom demand.
leakThreatMentioned: boolean
Is true when the text mentions a threat to publish the data.
threatActorDeletionAssurance: boolean
Is true when the text states that the threat actor deleted the data, or gave an assurance that it deleted the data.
ongoingAccess: string
Status of the unauthorized access at the time of the filing, as stated in the text. Possible values: contained, no_evidence_of_ongoing, ongoing, not_stated.
investigationStatus: string
Status of the investigation of the incident. Possible values: ongoing, concluded, not_stated.
threatActorType: string
Type of threat actor. Set only when the text describes the actor, e.g. as a nation-state actor or a former employee. The value does not come from the attack type. Possible values: nation_state, criminal, hacktivist, insider, not_stated.
affectedEntityCountry: string
Two-letter ISO 3166-1 country code of the affected subsidiary when it is outside the U.S., e.g. KR.
threatActorContact: boolean
Is true when the threat actor contacted the company, e.g. to claim the attack or to demand payment.
incidentStartDate: date
Date on which the incident started, e.g. 2024-04-14.
ransomPaid: boolean
Is true when the text states that the company paid a ransom. Is false when the text states that the company did not pay.
initialAccessViaThirdParty: boolean
Is true when the attacker got access through a third party, e.g. a contractor session, a vendor firewall or a software integration. This also applies when the attack affected the company's own systems.
data: object
Data affected by the incident.
status: string
Status of the data as stated in the text. exfiltrated_confirmed means that the text confirms that data was stolen. accessed_confirmed means that the text confirms access to data. potentially_accessed means that data was possibly accessed. no_evidence means that the text says there is no evidence of access to data. Possible values: exfiltrated_confirmed, accessed_confirmed, potentially_accessed, no_evidence, not_stated.
categoriesConfirmed: array of strings
Categories of data that the text confirms as affected, e.g. ["call_records", "contact_info"]. In the values, pii is personal information, phi is protected health information, dob is date of birth and ssn is a Social Security number. ssn_partial and financial_account_partial mean that only a part of the number was affected. customer, patient, employee and provider name the group of persons whose data was affected. Possible values: pii, ssn, dob, contact_info, phi, financial_account, customer, patient, employee, provider, proprietary_business, intellectual_property, research_and_development, financial_information, credentials, unspecified_confidential, ssn_partial, financial_account_partial, government_id, transaction_history, order_history, call_records, location_data.
categoriesUnderAssessment: array of strings
Categories of data that the company still assesses. Uses the same values as categoriesConfirmed. Possible values: pii, ssn, dob, contact_info, phi, financial_account, customer, patient, employee, provider, proprietary_business, intellectual_property, research_and_development, financial_information, credentials, unspecified_confidential, ssn_partial, financial_account_partial, government_id, transaction_history, order_history, call_records, location_data.
individualsAffected: integer
Number of affected individuals as stated, e.g. 35500000.
accountsAffected: integer
Number of affected accounts as stated, e.g. 33000000.
publishedByThreatActor: boolean
Is true when the text states that the threat actor published the data, e.g. on a leak site or on the dark web.
impact: object
Operational and financial impact of the incident on the company.
operationalImpact: string
Impact on operations as stated in the text. ongoing_disruption means that the restoration is still in progress at the time of the filing. temporary_disruption means that operations were disrupted and are restored. none_identified means that the text says that the incident has not had a material impact on operations. When more than one value applies, the value is the first in this order: material_disruption, ongoing_disruption, temporary_disruption, limited, none_identified. Possible values: none_identified, limited, material_disruption, ongoing_disruption, not_stated, temporary_disruption.
functionsAffected: array of strings
Affected business functions or systems as written, e.g. ["order fulfillment", "retail and e-commerce operations"].
restorationStatus: string
Status of the restoration of the affected systems. not_applicable means that there was no disruption. Possible values: not_applicable, in_progress, substantially_restored, fully_restored, not_stated.
financialImpactAssessment: string
Assessment of the financial impact as stated in the text. material_incurred means that a material financial impact occurred. material_expected means that a material financial impact is expected or reasonably likely. not_material_expected means that the company does not expect a material financial impact. unable_to_determine means that the company has not yet determined the financial impact. Possible values: material_incurred, material_expected, not_material_expected, unable_to_determine, not_stated.
financialImpactHorizon: array of strings
Reporting periods in which the text expects the financial impact. Possible values: current_quarter, current_year, long_term, prior_quarter.
guidanceImpact: string
Effect of the incident on the company's financial guidance. Possible values: withdrawn, lowered, below_guidance_expected, reaffirmed, not_stated.
quantifiedCostUSD: number
Cost of the incident in USD, stated as one amount, e.g. 600000.
insuranceMentioned: boolean
Is true when the text mentions insurance.
insuranceExpectedToCover: boolean
Is true when the text states that insurance is expected to cover some or all of the costs.
directLoss: object
Direct loss of funds or assets, e.g. stolen digital assets or a misdirected payment. Is null when the text states no direct loss.
amountUSD: number
Value of the loss in USD, e.g. 3665000.
assetType: string
Type of the lost asset as written, e.g. bitcoin.
quantity: number
Quantity of the lost asset, e.g. 50.903.
estimatedCostRangeUSD: object
Range of the estimated costs in USD. Is null when the text states no range.
low: number
Low end of the range, e.g. 180000000.
high: number
High end of the range, e.g. 400000000.
customerCompensation: object
Compensation to customers or other affected parties. Is null when the text states no compensation.
amountUSD: number
Amount of the compensation in USD, e.g. 1200000000.
form: string
Form of the compensation as written, e.g. purchase vouchers (KRW 1.685 trillion).
revenueImpactUSD: number
Revenue lost or not fulfilled in USD as stated, e.g. 15000000.
epsImpact: number
Effect on earnings per share in USD as stated. A negative value is a reduction, e.g. -0.64.
otherFinancialEffects: string
Other financial effects as stated that have no separate field, e.g. lender waivers, funding advances to providers or exclusions from adjusted earnings.
response: object
Actions of the company in response to the incident, and notifications to third parties.
actions: array of strings
Response actions as stated in the text. Possible values: incident_response_plan, third_party_forensics, containment, credential_reset, restricted_remote_access, restore_from_backup, enhanced_monitoring, systems_taken_offline, systems_shutdown_precautionary, customer_notification, credit_monitoring_offered, cyber_insurer_notified, data_dissemination_mitigation, disabled_compromised_accounts, additional_access_controls, personnel_terminated, fraud_controls, security_hardening.
lawEnforcementNotified: boolean
Is true when the text states that the company notified law enforcement.
regulatorsNotified: string
Status of the notification of regulators. Possible values: notified, in_progress, planned, evaluating, not_stated.
individualNotification: string
Status of the notification of affected individuals. Possible values: completed, in_progress, planned, evaluating, not_stated, none_planned.
legal: object
Lawsuits, regulatory inquiries and arrests related to the incident.
litigationCount: integer
Number of lawsuits as stated, e.g. 1.
cases: array of objects
Lawsuits named in the text.
caption: string
Case caption, e.g. Haley v. Nutex Health, Inc..
caseNumber: string
Case number, e.g. 4:26-cv-07197.
court: string
Court as written, e.g. S.D. Tex., Houston Division.
filedDate: date
Date on which the lawsuit was filed, e.g. 2026-08-27.
classAction: boolean
Is true when the lawsuit is a class action.
claims: array of strings
Claims as written, e.g. ["negligence", "unjust enrichment"].
regulatoryInquiry: boolean
Is true when the text states that a regulator started an inquiry or an investigation.
arrestsMade: boolean
Is true when the text states that persons were arrested in connection with the incident.
evidence: object
One to five short quotes from the filing text that support key values. Each key is the name or the path of the field that the quote supports, e.g. materialityStatus or data.categoriesConfirmed. Each value is the quote.
governance: object
Management changes related to the incident.
executiveDepartureLinked: boolean
Is true when the text links the departure of an executive or a director to the incident. Is false when the text states that a departure is not related to the incident.
executiveRole: string
Role of the person who left, as written, e.g. CEO of Korean subsidiary (resigned 2025-12-10).
xbrl: object
Text of Item 1.05 tagged with Inline XBRL in the cybersecurity disclosure taxonomy (cyd). Is present only when the filing contains these tags.
MaterialCybersecurityIncidentNatureTextBlock: string
Text that describes the nature of the incident.
MaterialCybersecurityIncidentScopeTextBlock: string
Text that describes the scope of the incident.
MaterialCybersecurityIncidentTimingTextBlock: string
Text that describes the timing of the incident.
MaterialCybersecurityIncidentMaterialImpactOrReasonablyLikelyMaterialImpactTextBlock: string
Text that describes the material impact or the reasonably likely material impact of the incident on the company.
MaterialCybersecurityIncidentInformationNotAvailableOrUndeterminedTextBlock: string
Text that identifies the information that is not determined or not available at the time of the filing.
Response Example
1
{
2
"total": {
3
"value": 1,
4
"relation": "eq"
5
},
6
"data": [
7
{
8
"filing": {
9
"ticker": "T",
10
"sic": "4813",
11
"otherItems": [
12
"9.01"
13
],
14
"periodOfReport": "2024-05-06",
15
"accessionNo": "0000732717-24-000046",
16
"cik": "732717",
17
"companyName": "AT&T Inc.",
18
"formType": "8-K",
19
"filedAt": "2024-07-12",
20
"url": "https://www.sec.gov/Archives/edgar/data/732717/000073271724000046/"
21
},
22
"disclosure": {
23
"filingRole": "initial",
24
"priorDisclosures": [],
25
"materialityStatus": "determined_not_material",
26
"materialityDeterminationDate": null,
27
"materialityBasis": [
28
"not_stated"
29
],
30
"amendmentUndertaking": null,
31
"isDeltaUpdate": false,
32
"textSource": "item_body",
33
"dojDelayInvoked": true,
34
"dojDelayDate": "2024-05-09",
35
"initiallyAssessedNotMaterial": null,
36
"incidentKey": "732717-2024-05-06",
37
"dojDelayDates": [
38
"2024-05-09",
39
"2024-06-05"
40
]
41
},
42
"incident": {
43
"detectionDate": "2024-04-19",
44
"detectionDatePrecision": "day",
45
"incidentStartDate": "2024-04-14",
46
"affectedEntity": null,
47
"affectedEntityCountry": null,
48
"environment": "own_systems",
49
"thirdPartyType": "AT&T workspace on a third-party cloud platform",
50
"attackTypes": [
51
"unauthorized_access",
52
"data_exfiltration"
53
],
54
"threatActorNamed": null,
55
"threatActorType": "not_stated",
56
"threatActorContact": null,
57
"ransomDemandMentioned": null,
58
"leakThreatMentioned": null,
59
"threatActorDeletionAssurance": null,
60
"ongoingAccess": "contained",
61
"investigationStatus": "not_stated",
62
"ransomPaid": null,
63
"initialAccessViaThirdParty": null
64
},
65
"data": {
66
"status": "exfiltrated_confirmed",
67
"categoriesConfirmed": [
68
"call_records",
69
"contact_info",
70
"customer",
71
"location_data"
72
],
73
"categoriesUnderAssessment": [],
74
"individualsAffected": null,
75
"accountsAffected": null,
76
"publishedByThreatActor": false
77
},
78
"impact": {
79
"operationalImpact": "none_identified",
80
"functionsAffected": [],
81
"restorationStatus": "not_stated",
82
"financialImpactAssessment": "not_material_expected",
83
"financialImpactHorizon": [],
84
"guidanceImpact": "not_stated",
85
"quantifiedCostUSD": null,
86
"directLoss": null,
87
"insuranceMentioned": false,
88
"insuranceExpectedToCover": null,
89
"estimatedCostRangeUSD": null,
90
"customerCompensation": null
91
},
92
"response": {
93
"actions": [
94
"incident_response_plan",
95
"third_party_forensics",
96
"containment",
97
"security_hardening"
98
],
99
"lawEnforcementNotified": true,
100
"regulatorsNotified": "not_stated",
101
"individualNotification": "planned"
102
},
103
"legal": {
104
"litigationCount": null,
105
"cases": [],
106
"regulatoryInquiry": null,
107
"arrestsMade": true
108
},
109
"governance": {
110
"executiveDepartureLinked": null,
111
"executiveRole": null
112
},
113
"evidence": {
114
"environment": "threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions",
115
"dojDelayInvoked": "On May 9, 2024, and again on June 5, 2024, the U.S. Department of Justice determined that, under Item 1.05(c) of Form 8-K, a delay in providing public disclosure was warranted",
116
"data.categoriesConfirmed": "records of calls and texts of nearly all of AT&T's wireless customers ... For a subset of records, one or more cell site identification number(s) are also included",
117
"materialityStatus": "this incident has not had a material impact on AT&T's operations, and AT&T does not believe that this incident is reasonably likely to materially impact AT&T's financial condition or results of operations"
118
}
119
}
120
]
121
}