Cybersecurity Incidents Data API

The Cybersecurity Incidents Data API provides access to a database of cybersecurity incidents, extracted from material event disclosures filed under Item 1.05 of Form 8-K: "Material Cybersecurity Incidents." A company must file Item 1.05 when it has a cybersecurity incident that it determines to be material. The company must describe the material aspects of the nature, scope and timing of the incident, and the material impact or reasonably likely material impact on the company, including its financial condition and results of operations. The filing is due within four business days after the company determines that the incident is material. Item 1.05 became effective in December 2023.

Data sample · Cybersecurity incidents
Filed atTickerCompanyMaterialityFiling roleAttack typesThreat actorDetectedData statusData categoriesOperational impactFinancial impactStated costLaw enforcementIncident keyCIKAccession no.Details
2026-08-31NUTXNutex Health Inc.not_statednew_8k_updatedata_exfiltration; unauthorized_accessnot_stated–exfiltrated_confirmedpatient; employee; provider; proprietary_business; financial_informationnone_identifiedunable_to_determine–Yes1479681-2026-08-1114796810001628280-26-059602
2026-07-02NAVINavient Corpdetermined_materialinitialransomware; unauthorized_accessnot_stated2026-06-08accessed_confirmedcustomer; pii; ssn; dob; contact_infonone_identifiednot_material_expected–Yes1593538-2026-06-2915935380001140361-26-027441
2026-05-11CBFVCB Financial Services, Inc.determined_materialinitialunauthorized_ai_tool_use; insiderinsider2026-05-05accessed_confirmedcustomer; ssn; dob; piinone_identifiednot_material_expected––1605301-2026-05-0716053010001605301-26-000021
2026-04-08BTMBitcoin Depot Inc.determined_materialinitialunauthorized_access; credential_compromise; digital_asset_theftnot_stated2026-03-23no_evidence–none_identifiednot_material_expected$3,665,000.00Yes1901799-2026-04-0619017990001193125-26-147772
2025-05-15COINCoinbase Global, Inc.not_statedinitialinsider; data_exfiltrationnot_stated2025-05-11exfiltrated_confirmedcustomer; contact_info; pii; ssn_partial; financial_account_partial; government_id; transaction_history; proprietary_businessnone_identifiedunable_to_determine–Yes1679788-2025-05-1416797880001679788-25-000094
2024-12-11DNUTKrispy Kreme, Inc.determined_materialinitialunauthorized_accessnot_stated2024-11-29not_stated–material_disruptionmaterial_expected–Yes1857154-2024-12-1118571540001857154-24-000123
2024-07-12TAT&T Inc.determined_not_materialinitialunauthorized_access; data_exfiltrationnot_stated2024-04-19exfiltrated_confirmedcall_records; contact_info; customer; location_datanone_identifiednot_material_expected–Yes732717-2024-05-067327170000732717-24-000046
2024-06-14KTCCKey Tronic Corpdetermined_materialamendment_updateunauthorized_access; data_exfiltrationnot_stated2024-05-06exfiltrated_confirmedpiitemporary_disruptionmaterial_expected$600,000.00Yes719733-2024-05-067197330000719733-24-000035
2024-01-19MSFTMICROSOFT CORPnot_yet_determinedinitialunauthorized_access; data_exfiltrationnation_state2024-01-12exfiltrated_confirmedunspecified_confidential; piinone_identifiedunable_to_determine–Yes789019-2024-01-177890190001193125-24-011295
2023-12-18VFCV F CORPdetermined_materialinitialransomware; data_exfiltrationnot_stated2023-12-13exfiltrated_confirmedpiimaterial_disruptionunable_to_determine–Yes103379-2023-12-151033790000950123-23-011228

The data is extracted from the text disclosed under Item 1.05 and from attached press releases. The data is provided in a structured JSON format. The extracted information includes:

  • Materiality conclusion of the company, the date and the reasons of the materiality determination, and disclosure delays under Item 1.05(c) at the request of the U.S. Attorney General
  • Detection date, start date, affected subsidiary, and the location of the affected systems, such as own systems, a service provider or a cloud platform
  • Attack types, such as ransomware, data exfiltration, social engineering or insider activity, and the type and name of the threat actor
  • Ransom demands, ransom payments, leak threats and contact by the threat actor
  • Affected data, including the confirmed data categories, the categories under assessment, and the number of affected individuals and accounts
  • Operational impact, affected business functions and the status of the restoration
  • Financial impact, including the assessment, the affected periods, the effect on guidance, stated costs, direct losses, customer compensation and insurance
  • Response actions, and notifications to law enforcement, regulators and affected individuals
  • Lawsuits, regulatory inquiries, arrests and executive departures related to the incident
  • An incident key that links the first filing about an incident to all later updates about the same incident
  • Short quotes from the filing text that support key values

API Endpoint

Search and retrieve structured details about material cybersecurity incidents from Form 8-K filings by sending POST HTTP requests with search parameters as JSON-formatted payload to the following API endpoint:

https://api.sec-api.io/material-events/cybersecurity-incidents

Supported HTTP methods: POST

Request and response content type: JSON

Authentication

To authenticate your API requests, use the API key available in your user profile. You can use your API key in one of two ways. Choose the method that best fits your implementation:

  • Authorization Header: Include your API key as an Authorization header in your POST requests. For instance, before sending a POST request to https://api.sec-api.io/material-events/cybersecurity-incidents, ensure the header is set as follows: Authorization: YOUR_API_KEY.
  • Query Parameter: Alternatively, append your API key directly to the URL as a query parameter. For example, when making POST requests, use the URL https://api.sec-api.io/material-events/cybersecurity-incidents?token=YOUR_API_KEY instead of the base endpoint.

Request Parameters

Search material cybersecurity incidents disclosed in Form 8-K filings by sending a search query to the API. All fields of the extracted data are searchable. For a complete list of searchable fields, refer to the Response Structure section below. Send a search query as a JSON-formatted payload to the API using the structure explained below.

Request parameters:

query: string

Your search criteria in the format field:value defining the fields to search in and the values to search for in those fields. The query is written in Lucene syntax and supports boolean operators (AND, OR, NOT), range queries across date and number fields using square brackets ([, ]), wildcards (*) and search expression grouping with normal brackets ((, )). More information on Lucene is available here. Query examples are available below.

from: integer

Specifies the starting position of your results, allowing for pagination. For instance, set from to 50 to skip the first 50 results. Default: 0. Maximum: 10,000, which is also the cap for the maximum number of results returned per query. To retrieve all results in your search universe, increment from by the value of the size parameter (e.g., 50) until no more results are returned or the 10,000 limit is reached. For example, use 0, 50, 100, and so on. If your query locates more than 10,000 results, consider narrowing your search by refining your filter criteria, such as using a date range filter to iterate over months or years. One approach would be to search for items with a filing.filedAt date range filter, e.g., filing.filedAt:[2025-01-01 TO 2025-01-31] (all filings from January 2025), then paginate through the results by incrementing from, and once completed, repeat the process for the next month, and so on.

size: integer

The number of results to be returned per request. Default: 50. Maximum: 50.

sort: array

An array of objects that specify how the returned results are sorted. For example, [{ "filing.filedAt": { "order": "desc" } }] sorts the results by the filing date, most recent filings first. Set order to asc to sort in ascending order.

Request Examples

Find the first disclosures of all ransomware incidents filed in 2025, with the result sorted by the filing date, starting with the most recent filings. Increment the from parameter by 50 on each subsequent request to paginate through the results.

Retrieve the history of an incident for a specific company using its trading symbol (ticker). In this example, the API returns all Item 1.05 disclosures for the company with the ticker symbol "UNH", starting with the first disclosure. To retrieve all filings about one incident, search for its disclosure.incidentKey instead.

Response Structure

Response type: JSON

The API response represents a JSON object with two fields: total (object) and data (array). The total.value field indicates the total number of results matching your search query. The data array holds up to 50 items per request. Each item represents the extracted data from one Form 8-K filing that discloses Item 1.05.

The data contains only facts that the filing text states. A value of null or not_stated, or an empty array, means that the text does not state the fact. Dates use the format YYYY-MM-DD, or YYYY-MM and YYYY when the text gives only the month or the year. Amounts are in USD. Each item has the following structure:

filing: object

Metadata of the Form 8-K filing.

accessionNo: string

Accession number of the filing, e.g. 0000732717-24-000046.

cik: string

Central Index Key (CIK) of the filer, without leading zeros, e.g. 732717.

ticker: string

Trading symbol of the filer, e.g. T. Is null when the filer has no trading symbol.

companyName: string

Name of the filer, e.g. AT&T Inc..

formType: string

EDGAR form type. Possible values: 8-K, 8-K/A.

filedAt: date

Date on which the filing was filed on SEC EDGAR, e.g. 2024-07-12.

periodOfReport: date

Date of the earliest event reported in the filing, e.g. 2024-05-06.

sic: string

Standard Industrial Classification (SIC) code of the filer, e.g. 4813.

otherItems: array of strings

Other Form 8-K items disclosed in the same filing, e.g. ["9.01"].

url: string

URL of the filing folder on SEC EDGAR.

disclosure: object

Materiality conclusion of the company, and how the filing links to other filings about the same incident.

filingRole: string

Role of the filing in the chain of filings about one incident. initial is the first Form 8-K with Item 1.05 about the incident. amendment_update is a Form 8-K/A. new_8k_update is a later Form 8-K that updates an earlier report. Possible values: initial, amendment_update, new_8k_update.

materialityStatus: string

Materiality conclusion as stated in the text. determined_material means that the company determined the incident to be material, or states that the incident had or is reasonably likely to have a material impact on the company. possibly_material means that the text says that the incident "may" be material. not_yet_determined means that the text says that the determination is pending. not_determined means that the text says that the company has not determined that the incident is reasonably likely to have a material impact, and does not say that a determination is pending. reported_without_determination means that the company files the report without a materiality conclusion. determined_not_material means that the company states that the incident is not material, or is not reasonably likely to have a material impact. Possible values: determined_material, possibly_material, not_yet_determined, not_determined, reported_without_determination, determined_not_material, not_stated.

materialityDeterminationDate: date

Date on which the company determined that the incident is material, e.g. 2026-06-29.

materialityBasis: array of strings

Reasons for the materiality conclusion as stated in the text. Possible values: data_volume, data_sensitivity, operational_disruption, financial_impact, precautionary, not_stated, reputational, legal_regulatory, response_costs.

amendmentUndertaking: boolean

Is true when the company states that it will amend the report when more information becomes available.

incidentKey: string

Key that links all filings about one incident. Format: CIK, a hyphen, and the periodOfReport of the earliest Form 8-K about the incident, e.g. 731766-2024-02-21. The earliest Form 8-K can report the incident under any item, e.g. Item 1.05, 7.01 or 8.01. Use this key to get the full history of an incident.

isDeltaUpdate: boolean

Is true when the filing reports only the changes since an earlier filing about the incident. In this case, an empty field does not mean that the fact does not exist.

textSource: string

Parts of the filing from which the data was extracted: the text of Item 1.05, an Exhibit 99 attachment such as a press release, or both. Possible values: item_body, exhibit_99, item_body_and_exhibit.

dojDelayInvoked: boolean

Is true when the text states that the U.S. Attorney General (Department of Justice) determined under Item 1.05(c) that a delay of the disclosure was warranted.

priorDisclosures: array of objects

Earlier Form 8-K filings about the same incident that the text refers to. These are often filings under Item 7.01 or 8.01.

filingDate: date

Filing date of the earlier Form 8-K, e.g. 2026-08-24.

item: string

Item of the earlier Form 8-K, e.g. 8.01.

initiallyAssessedNotMaterial: boolean

Is true when the text states that the company first assessed the incident as not material.

dojDelayDate: date

Date of the Item 1.05(c) delay determination, e.g. 2024-05-09. When the text names more than one determination, the value is the date of the first one.

dojDelayDates: array of dates

Dates of all Item 1.05(c) delay determinations named in the text, e.g. ["2024-05-09", "2024-06-05"].

incident: object

Nature, timing and source of the incident.

detectionDate: date

Date on which the company discovered the incident or was notified of it, e.g. 2024-04-19. When the text gives the date of an outage but no discovery date, the outage date is in incidentStartDate.

detectionDatePrecision: string

Precision of detectionDate as stated in the text. Possible values: day, month, quarter, year, not_stated.

affectedEntity: string

Name of the affected subsidiary when the text names one, e.g. Coupang Corp..

environment: string

Location of the compromised systems or data. own_systems includes cloud tenants that the company owns. Possible values: own_systems, third_party_service_provider, third_party_cloud, third_party_saas_integration, unknown.

thirdPartyType: string

Type of third party involved in the incident, as written, e.g. law firm.

attackTypes: array of strings

Types of attack as stated in the text. Possible values: ransomware, data_exfiltration, social_engineering, phishing, credential_compromise, unauthorized_access, business_email_compromise, ddos, insider, supply_chain, not_stated, malware, vulnerability_exploit, account_takeover, unauthorized_ai_tool_use, website_defacement, digital_asset_theft, payment_fraud.

threatActorNamed: string

Name of the threat actor as written, e.g. Midnight Blizzard (Cozy Bear).

ransomDemandMentioned: boolean

Is true when the text mentions a ransom demand.

leakThreatMentioned: boolean

Is true when the text mentions a threat to publish the data.

threatActorDeletionAssurance: boolean

Is true when the text states that the threat actor deleted the data, or gave an assurance that it deleted the data.

ongoingAccess: string

Status of the unauthorized access at the time of the filing, as stated in the text. Possible values: contained, no_evidence_of_ongoing, ongoing, not_stated.

investigationStatus: string

Status of the investigation of the incident. Possible values: ongoing, concluded, not_stated.

threatActorType: string

Type of threat actor. Set only when the text describes the actor, e.g. as a nation-state actor or a former employee. The value does not come from the attack type. Possible values: nation_state, criminal, hacktivist, insider, not_stated.

affectedEntityCountry: string

Two-letter ISO 3166-1 country code of the affected subsidiary when it is outside the U.S., e.g. KR.

threatActorContact: boolean

Is true when the threat actor contacted the company, e.g. to claim the attack or to demand payment.

incidentStartDate: date

Date on which the incident started, e.g. 2024-04-14.

ransomPaid: boolean

Is true when the text states that the company paid a ransom. Is false when the text states that the company did not pay.

initialAccessViaThirdParty: boolean

Is true when the attacker got access through a third party, e.g. a contractor session, a vendor firewall or a software integration. This also applies when the attack affected the company's own systems.

data: object

Data affected by the incident.

status: string

Status of the data as stated in the text. exfiltrated_confirmed means that the text confirms that data was stolen. accessed_confirmed means that the text confirms access to data. potentially_accessed means that data was possibly accessed. no_evidence means that the text says there is no evidence of access to data. Possible values: exfiltrated_confirmed, accessed_confirmed, potentially_accessed, no_evidence, not_stated.

categoriesConfirmed: array of strings

Categories of data that the text confirms as affected, e.g. ["call_records", "contact_info"]. In the values, pii is personal information, phi is protected health information, dob is date of birth and ssn is a Social Security number. ssn_partial and financial_account_partial mean that only a part of the number was affected. customer, patient, employee and provider name the group of persons whose data was affected. Possible values: pii, ssn, dob, contact_info, phi, financial_account, customer, patient, employee, provider, proprietary_business, intellectual_property, research_and_development, financial_information, credentials, unspecified_confidential, ssn_partial, financial_account_partial, government_id, transaction_history, order_history, call_records, location_data.

categoriesUnderAssessment: array of strings

Categories of data that the company still assesses. Uses the same values as categoriesConfirmed. Possible values: pii, ssn, dob, contact_info, phi, financial_account, customer, patient, employee, provider, proprietary_business, intellectual_property, research_and_development, financial_information, credentials, unspecified_confidential, ssn_partial, financial_account_partial, government_id, transaction_history, order_history, call_records, location_data.

individualsAffected: integer

Number of affected individuals as stated, e.g. 35500000.

accountsAffected: integer

Number of affected accounts as stated, e.g. 33000000.

publishedByThreatActor: boolean

Is true when the text states that the threat actor published the data, e.g. on a leak site or on the dark web.

impact: object

Operational and financial impact of the incident on the company.

operationalImpact: string

Impact on operations as stated in the text. ongoing_disruption means that the restoration is still in progress at the time of the filing. temporary_disruption means that operations were disrupted and are restored. none_identified means that the text says that the incident has not had a material impact on operations. When more than one value applies, the value is the first in this order: material_disruption, ongoing_disruption, temporary_disruption, limited, none_identified. Possible values: none_identified, limited, material_disruption, ongoing_disruption, not_stated, temporary_disruption.

functionsAffected: array of strings

Affected business functions or systems as written, e.g. ["order fulfillment", "retail and e-commerce operations"].

restorationStatus: string

Status of the restoration of the affected systems. not_applicable means that there was no disruption. Possible values: not_applicable, in_progress, substantially_restored, fully_restored, not_stated.

financialImpactAssessment: string

Assessment of the financial impact as stated in the text. material_incurred means that a material financial impact occurred. material_expected means that a material financial impact is expected or reasonably likely. not_material_expected means that the company does not expect a material financial impact. unable_to_determine means that the company has not yet determined the financial impact. Possible values: material_incurred, material_expected, not_material_expected, unable_to_determine, not_stated.

financialImpactHorizon: array of strings

Reporting periods in which the text expects the financial impact. Possible values: current_quarter, current_year, long_term, prior_quarter.

guidanceImpact: string

Effect of the incident on the company's financial guidance. Possible values: withdrawn, lowered, below_guidance_expected, reaffirmed, not_stated.

quantifiedCostUSD: number

Cost of the incident in USD, stated as one amount, e.g. 600000.

insuranceMentioned: boolean

Is true when the text mentions insurance.

insuranceExpectedToCover: boolean

Is true when the text states that insurance is expected to cover some or all of the costs.

directLoss: object

Direct loss of funds or assets, e.g. stolen digital assets or a misdirected payment. Is null when the text states no direct loss.

amountUSD: number

Value of the loss in USD, e.g. 3665000.

assetType: string

Type of the lost asset as written, e.g. bitcoin.

quantity: number

Quantity of the lost asset, e.g. 50.903.

estimatedCostRangeUSD: object

Range of the estimated costs in USD. Is null when the text states no range.

low: number

Low end of the range, e.g. 180000000.

high: number

High end of the range, e.g. 400000000.

customerCompensation: object

Compensation to customers or other affected parties. Is null when the text states no compensation.

amountUSD: number

Amount of the compensation in USD, e.g. 1200000000.

form: string

Form of the compensation as written, e.g. purchase vouchers (KRW 1.685 trillion).

revenueImpactUSD: number

Revenue lost or not fulfilled in USD as stated, e.g. 15000000.

epsImpact: number

Effect on earnings per share in USD as stated. A negative value is a reduction, e.g. -0.64.

otherFinancialEffects: string

Other financial effects as stated that have no separate field, e.g. lender waivers, funding advances to providers or exclusions from adjusted earnings.

response: object

Actions of the company in response to the incident, and notifications to third parties.

actions: array of strings

Response actions as stated in the text. Possible values: incident_response_plan, third_party_forensics, containment, credential_reset, restricted_remote_access, restore_from_backup, enhanced_monitoring, systems_taken_offline, systems_shutdown_precautionary, customer_notification, credit_monitoring_offered, cyber_insurer_notified, data_dissemination_mitigation, disabled_compromised_accounts, additional_access_controls, personnel_terminated, fraud_controls, security_hardening.

lawEnforcementNotified: boolean

Is true when the text states that the company notified law enforcement.

regulatorsNotified: string

Status of the notification of regulators. Possible values: notified, in_progress, planned, evaluating, not_stated.

individualNotification: string

Status of the notification of affected individuals. Possible values: completed, in_progress, planned, evaluating, not_stated, none_planned.

legal: object

Lawsuits, regulatory inquiries and arrests related to the incident.

litigationCount: integer

Number of lawsuits as stated, e.g. 1.

cases: array of objects

Lawsuits named in the text.

caption: string

Case caption, e.g. Haley v. Nutex Health, Inc..

caseNumber: string

Case number, e.g. 4:26-cv-07197.

court: string

Court as written, e.g. S.D. Tex., Houston Division.

filedDate: date

Date on which the lawsuit was filed, e.g. 2026-08-27.

classAction: boolean

Is true when the lawsuit is a class action.

claims: array of strings

Claims as written, e.g. ["negligence", "unjust enrichment"].

regulatoryInquiry: boolean

Is true when the text states that a regulator started an inquiry or an investigation.

arrestsMade: boolean

Is true when the text states that persons were arrested in connection with the incident.

evidence: object

One to five short quotes from the filing text that support key values. Each key is the name or the path of the field that the quote supports, e.g. materialityStatus or data.categoriesConfirmed. Each value is the quote.

governance: object

Management changes related to the incident.

executiveDepartureLinked: boolean

Is true when the text links the departure of an executive or a director to the incident. Is false when the text states that a departure is not related to the incident.

executiveRole: string

Role of the person who left, as written, e.g. CEO of Korean subsidiary (resigned 2025-12-10).

xbrl: object

Text of Item 1.05 tagged with Inline XBRL in the cybersecurity disclosure taxonomy (cyd). Is present only when the filing contains these tags.

MaterialCybersecurityIncidentNatureTextBlock: string

Text that describes the nature of the incident.

MaterialCybersecurityIncidentScopeTextBlock: string

Text that describes the scope of the incident.

MaterialCybersecurityIncidentTimingTextBlock: string

Text that describes the timing of the incident.

MaterialCybersecurityIncidentMaterialImpactOrReasonablyLikelyMaterialImpactTextBlock: string

Text that describes the material impact or the reasonably likely material impact of the incident on the company.

MaterialCybersecurityIncidentInformationNotAvailableOrUndeterminedTextBlock: string

Text that identifies the information that is not determined or not available at the time of the filing.

Response Example

JSON
1 {
2 "total": {
3 "value": 1,
4 "relation": "eq"
5 },
6 "data": [
7 {
8 "filing": {
9 "ticker": "T",
10 "sic": "4813",
11 "otherItems": [
12 "9.01"
13 ],
14 "periodOfReport": "2024-05-06",
15 "accessionNo": "0000732717-24-000046",
16 "cik": "732717",
17 "companyName": "AT&T Inc.",
18 "formType": "8-K",
19 "filedAt": "2024-07-12",
20 "url": "https://www.sec.gov/Archives/edgar/data/732717/000073271724000046/"
21 },
22 "disclosure": {
23 "filingRole": "initial",
24 "priorDisclosures": [],
25 "materialityStatus": "determined_not_material",
26 "materialityDeterminationDate": null,
27 "materialityBasis": [
28 "not_stated"
29 ],
30 "amendmentUndertaking": null,
31 "isDeltaUpdate": false,
32 "textSource": "item_body",
33 "dojDelayInvoked": true,
34 "dojDelayDate": "2024-05-09",
35 "initiallyAssessedNotMaterial": null,
36 "incidentKey": "732717-2024-05-06",
37 "dojDelayDates": [
38 "2024-05-09",
39 "2024-06-05"
40 ]
41 },
42 "incident": {
43 "detectionDate": "2024-04-19",
44 "detectionDatePrecision": "day",
45 "incidentStartDate": "2024-04-14",
46 "affectedEntity": null,
47 "affectedEntityCountry": null,
48 "environment": "own_systems",
49 "thirdPartyType": "AT&T workspace on a third-party cloud platform",
50 "attackTypes": [
51 "unauthorized_access",
52 "data_exfiltration"
53 ],
54 "threatActorNamed": null,
55 "threatActorType": "not_stated",
56 "threatActorContact": null,
57 "ransomDemandMentioned": null,
58 "leakThreatMentioned": null,
59 "threatActorDeletionAssurance": null,
60 "ongoingAccess": "contained",
61 "investigationStatus": "not_stated",
62 "ransomPaid": null,
63 "initialAccessViaThirdParty": null
64 },
65 "data": {
66 "status": "exfiltrated_confirmed",
67 "categoriesConfirmed": [
68 "call_records",
69 "contact_info",
70 "customer",
71 "location_data"
72 ],
73 "categoriesUnderAssessment": [],
74 "individualsAffected": null,
75 "accountsAffected": null,
76 "publishedByThreatActor": false
77 },
78 "impact": {
79 "operationalImpact": "none_identified",
80 "functionsAffected": [],
81 "restorationStatus": "not_stated",
82 "financialImpactAssessment": "not_material_expected",
83 "financialImpactHorizon": [],
84 "guidanceImpact": "not_stated",
85 "quantifiedCostUSD": null,
86 "directLoss": null,
87 "insuranceMentioned": false,
88 "insuranceExpectedToCover": null,
89 "estimatedCostRangeUSD": null,
90 "customerCompensation": null
91 },
92 "response": {
93 "actions": [
94 "incident_response_plan",
95 "third_party_forensics",
96 "containment",
97 "security_hardening"
98 ],
99 "lawEnforcementNotified": true,
100 "regulatorsNotified": "not_stated",
101 "individualNotification": "planned"
102 },
103 "legal": {
104 "litigationCount": null,
105 "cases": [],
106 "regulatoryInquiry": null,
107 "arrestsMade": true
108 },
109 "governance": {
110 "executiveDepartureLinked": null,
111 "executiveRole": null
112 },
113 "evidence": {
114 "environment": "threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions",
115 "dojDelayInvoked": "On May 9, 2024, and again on June 5, 2024, the U.S. Department of Justice determined that, under Item 1.05(c) of Form 8-K, a delay in providing public disclosure was warranted",
116 "data.categoriesConfirmed": "records of calls and texts of nearly all of AT&T's wireless customers ... For a subset of records, one or more cell site identification number(s) are also included",
117 "materialityStatus": "this incident has not had a material impact on AT&T's operations, and AT&T does not believe that this incident is reasonably likely to materially impact AT&T's financial condition or results of operations"
118 }
119 }
120 ]
121 }