# Material Cybersecurity Incidents - SEC Form 8-K, Item 1.05 > Database of material cybersecurity incidents from Form 8-K material event filings under Item 1.05, including materiality conclusions, attack types, threat actors, affected data, operational and financial impact, response actions, lawsuits and Item 1.05(c) disclosure delays. Source: https://sec-api.io/docs/cybersecurity-incidents-form-8k-item-1-05-data-api The Cybersecurity Incidents Data API provides access to a database of cybersecurity incidents, extracted from material event disclosures filed under Item 1.05 of Form 8-K: "Material Cybersecurity Incidents." A company must file Item 1.05 when it has a cybersecurity incident that it determines to be material. The company must describe the material aspects of the nature, scope and timing of the incident, and the material impact or reasonably likely material impact on the company, including its financial condition and results of operations. The filing is due within four business days after the company determines that the incident is material. Item 1.05 became effective in December 2023. Data sample · Cybersecurity incidents | Filed at | Ticker | Company | Materiality | Filing role | Attack types | Threat actor | Detected | Data status | Data categories | Operational impact | Financial impact | Stated cost | Law enforcement | Incident key | CIK | Accession no. | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | 2026-08-31 | NUTX | Nutex Health Inc. | not_stated | new_8k_update | data_exfiltration; unauthorized_access | not_stated | – | exfiltrated_confirmed | patient; employee; provider; proprietary_business; financial_information | none_identified | unable_to_determine | – | Yes | 1479681-2026-08-11 | 1479681 | 0001628280-26-059602 | | 2026-07-02 | NAVI | Navient Corp | determined_material | initial | ransomware; unauthorized_access | not_stated | 2026-06-08 | accessed_confirmed | customer; pii; ssn; dob; contact_info | none_identified | not_material_expected | – | Yes | 1593538-2026-06-29 | 1593538 | 0001140361-26-027441 | | 2026-05-11 | CBFV | CB Financial Services, Inc. | determined_material | initial | unauthorized_ai_tool_use; insider | insider | 2026-05-05 | accessed_confirmed | customer; ssn; dob; pii | none_identified | not_material_expected | – | – | 1605301-2026-05-07 | 1605301 | 0001605301-26-000021 | | 2026-04-08 | BTM | Bitcoin Depot Inc. | determined_material | initial | unauthorized_access; credential_compromise; digital_asset_theft | not_stated | 2026-03-23 | no_evidence | – | none_identified | not_material_expected | $3,665,000.00 | Yes | 1901799-2026-04-06 | 1901799 | 0001193125-26-147772 | | 2025-05-15 | COIN | Coinbase Global, Inc. | not_stated | initial | insider; data_exfiltration | not_stated | 2025-05-11 | exfiltrated_confirmed | customer; contact_info; pii; ssn_partial; financial_account_partial; government_id; transaction_history; proprietary_business | none_identified | unable_to_determine | – | Yes | 1679788-2025-05-14 | 1679788 | 0001679788-25-000094 | | 2024-12-11 | DNUT | Krispy Kreme, Inc. | determined_material | initial | unauthorized_access | not_stated | 2024-11-29 | not_stated | – | material_disruption | material_expected | – | Yes | 1857154-2024-12-11 | 1857154 | 0001857154-24-000123 | | 2024-07-12 | T | AT&T Inc. | determined_not_material | initial | unauthorized_access; data_exfiltration | not_stated | 2024-04-19 | exfiltrated_confirmed | call_records; contact_info; customer; location_data | none_identified | not_material_expected | – | Yes | 732717-2024-05-06 | 732717 | 0000732717-24-000046 | | 2024-06-14 | KTCC | Key Tronic Corp | determined_material | amendment_update | unauthorized_access; data_exfiltration | not_stated | 2024-05-06 | exfiltrated_confirmed | pii | temporary_disruption | material_expected | $600,000.00 | Yes | 719733-2024-05-06 | 719733 | 0000719733-24-000035 | | 2024-01-19 | MSFT | MICROSOFT CORP | not_yet_determined | initial | unauthorized_access; data_exfiltration | nation_state | 2024-01-12 | exfiltrated_confirmed | unspecified_confidential; pii | none_identified | unable_to_determine | – | Yes | 789019-2024-01-17 | 789019 | 0001193125-24-011295 | | 2023-12-18 | VFC | V F CORP | determined_material | initial | ransomware; data_exfiltration | not_stated | 2023-12-13 | exfiltrated_confirmed | pii | material_disruption | unable_to_determine | – | Yes | 103379-2023-12-15 | 103379 | 0000950123-23-011228 | The data is extracted from the text disclosed under Item 1.05 and from attached press releases. The data is provided in a structured JSON format. The extracted information includes: - Materiality conclusion of the company, the date and the reasons of the materiality determination, and disclosure delays under Item 1.05(c) at the request of the U.S. Attorney General - Detection date, start date, affected subsidiary, and the location of the affected systems, such as own systems, a service provider or a cloud platform - Attack types, such as ransomware, data exfiltration, social engineering or insider activity, and the type and name of the threat actor - Ransom demands, ransom payments, leak threats and contact by the threat actor - Affected data, including the confirmed data categories, the categories under assessment, and the number of affected individuals and accounts - Operational impact, affected business functions and the status of the restoration - Financial impact, including the assessment, the affected periods, the effect on guidance, stated costs, direct losses, customer compensation and insurance - Response actions, and notifications to law enforcement, regulators and affected individuals - Lawsuits, regulatory inquiries, arrests and executive departures related to the incident - An incident key that links the first filing about an incident to all later updates about the same incident - Short quotes from the filing text that support key values ## API Endpoint Search and retrieve structured details about material cybersecurity incidents from Form 8-K filings by sending `POST` HTTP requests with search parameters as JSON-formatted payload to the following API endpoint: https://api.sec-api.io/material-events/cybersecurity-incidents Supported HTTP methods: `POST` Request and response content type: `JSON` ## Authentication To authenticate your API requests, use the API key available in your [user profile](https://sec-api.io/login). You can use your API key in one of two ways. Choose the method that best fits your implementation: - **Authorization Header:** Include your API key as an `Authorization` header in your `POST` requests. For instance, before sending a `POST` request to `https://api.sec-api.io/material-events/cybersecurity-incidents`, ensure the header is set as follows: `Authorization: YOUR_API_KEY`. - **Query Parameter:** Alternatively, append your API key directly to the URL as a query parameter. For example, when making `POST` requests, use the URL `https://api.sec-api.io/material-events/cybersecurity-incidents?token=YOUR_API_KEY` instead of the base endpoint. ## Request Parameters Search material cybersecurity incidents disclosed in Form 8-K filings by sending a search query to the API. All fields of the extracted data are searchable. For a complete list of searchable fields, refer to the [Response Structure section](#response-format) below. Send a search query as a JSON-formatted payload to the API using the structure explained below. **Request parameters:** - query: string Your search criteria in the format `field:value` defining the fields to search in and the values to search for in those fields. The query is written in Lucene syntax and supports boolean operators (AND, OR, NOT), range queries across date and number fields using square brackets (`[`, `]`), wildcards (`*`) and search expression grouping with normal brackets (`(`, `)`). More [information on Lucene is available here](https://sec-api.io/resources/lucene-query-syntax-overview). Query examples are [available below.](#request-examples) - from: integer Specifies the starting position of your results, allowing for pagination. For instance, set `from` to 50 to skip the first 50 results. Default: 0. Maximum: 10,000, which is also the cap for the maximum number of results returned per `query`. To retrieve all results in your search universe, increment `from` by the value of the `size` parameter (e.g., 50) until no more results are returned or the 10,000 limit is reached. For example, use 0, 50, 100, and so on. If your `query` locates more than 10,000 results, consider narrowing your search by refining your filter criteria, such as using a date range filter to iterate over months or years. One approach would be to search for items with a `filing.filedAt` date range filter, e.g., `filing.filedAt:[2025-01-01 TO 2025-01-31]` (all filings from January 2025), then paginate through the results by incrementing `from`, and once completed, repeat the process for the next month, and so on. - size: integer The number of results to be returned per request. Default: 50. Maximum: 50. - sort: array An array of objects that specify how the returned results are sorted. For example, `[{ "filing.filedAt": { "order": "desc" } }]` sorts the results by the filing date, most recent filings first. Set `order` to `asc` to sort in ascending order. ### Request Examples Find the first disclosures of all ransomware incidents filed in 2025, with the result sorted by the filing date, starting with the most recent filings. Increment the `from` parameter by 50 on each subsequent request to paginate through the results. ```json { "query": "incident.attackTypes:ransomware AND disclosure.filingRole:initial AND filing.filedAt:[2025-01-01 TO 2025-12-31]", "from": "0", "size": "50", "sort": [{"filing.filedAt":{"order":"desc"}}] } ``` Retrieve the history of an incident for a specific company using its trading symbol (ticker). In this example, the API returns all Item 1.05 disclosures for the company with the ticker symbol "UNH", starting with the first disclosure. To retrieve all filings about one incident, search for its `disclosure.incidentKey` instead. ```json { "query": "filing.ticker:UNH", "from": "0", "size": "50", "sort": [{"filing.filedAt":{"order":"asc"}}] } ``` ## Response Structure **Response type:** JSON The API response represents a JSON object with two fields: `total` (object) and `data` (array). The `total.value` field indicates the total number of results matching your search query. The `data` array holds up to 50 items per request. Each item represents the extracted data from one Form 8-K filing that discloses Item 1.05. The data contains only facts that the filing text states. A value of `null` or `not_stated`, or an empty array, means that the text does not state the fact. Dates use the format `YYYY-MM-DD`, or `YYYY-MM` and `YYYY` when the text gives only the month or the year. Amounts are in USD. Each item has the following structure: - filing: object Metadata of the Form 8-K filing. - accessionNo: string Accession number of the filing, e.g. `0000732717-24-000046`. - cik: string Central Index Key (CIK) of the filer, without leading zeros, e.g. `732717`. - ticker: string Trading symbol of the filer, e.g. `T`. Is `null` when the filer has no trading symbol. - companyName: string Name of the filer, e.g. `AT&T Inc.`. - formType: string EDGAR form type. Possible values: `8-K`, `8-K/A`. - filedAt: date Date on which the filing was filed on SEC EDGAR, e.g. `2024-07-12`. - periodOfReport: date Date of the earliest event reported in the filing, e.g. `2024-05-06`. - sic: string Standard Industrial Classification (SIC) code of the filer, e.g. `4813`. - otherItems: array of strings Other Form 8-K items disclosed in the same filing, e.g. `["9.01"]`. - url: string URL of the filing folder on SEC EDGAR. - disclosure: object Materiality conclusion of the company, and how the filing links to other filings about the same incident. - filingRole: string Role of the filing in the chain of filings about one incident. `initial` is the first Form 8-K with Item 1.05 about the incident. `amendment_update` is a Form 8-K/A. `new_8k_update` is a later Form 8-K that updates an earlier report. Possible values: `initial`, `amendment_update`, `new_8k_update`. - materialityStatus: string Materiality conclusion as stated in the text. `determined_material` means that the company determined the incident to be material, or states that the incident had or is reasonably likely to have a material impact on the company. `possibly_material` means that the text says that the incident "may" be material. `not_yet_determined` means that the text says that the determination is pending. `not_determined` means that the text says that the company has not determined that the incident is reasonably likely to have a material impact, and does not say that a determination is pending. `reported_without_determination` means that the company files the report without a materiality conclusion. `determined_not_material` means that the company states that the incident is not material, or is not reasonably likely to have a material impact. Possible values: `determined_material`, `possibly_material`, `not_yet_determined`, `not_determined`, `reported_without_determination`, `determined_not_material`, `not_stated`. - materialityDeterminationDate: date Date on which the company determined that the incident is material, e.g. `2026-06-29`. - materialityBasis: array of strings Reasons for the materiality conclusion as stated in the text. Possible values: `data_volume`, `data_sensitivity`, `operational_disruption`, `financial_impact`, `precautionary`, `not_stated`, `reputational`, `legal_regulatory`, `response_costs`. - amendmentUndertaking: boolean Is `true` when the company states that it will amend the report when more information becomes available. - incidentKey: string Key that links all filings about one incident. Format: CIK, a hyphen, and the `periodOfReport` of the earliest Form 8-K about the incident, e.g. `731766-2024-02-21`. The earliest Form 8-K can report the incident under any item, e.g. Item 1.05, 7.01 or 8.01. Use this key to get the full history of an incident. - isDeltaUpdate: boolean Is `true` when the filing reports only the changes since an earlier filing about the incident. In this case, an empty field does not mean that the fact does not exist. - textSource: string Parts of the filing from which the data was extracted: the text of Item 1.05, an Exhibit 99 attachment such as a press release, or both. Possible values: `item_body`, `exhibit_99`, `item_body_and_exhibit`. - dojDelayInvoked: boolean Is `true` when the text states that the U.S. Attorney General (Department of Justice) determined under Item 1.05(c) that a delay of the disclosure was warranted. - priorDisclosures: array of objects Earlier Form 8-K filings about the same incident that the text refers to. These are often filings under Item 7.01 or 8.01. - filingDate: date Filing date of the earlier Form 8-K, e.g. `2026-08-24`. - item: string Item of the earlier Form 8-K, e.g. `8.01`. - initiallyAssessedNotMaterial: boolean Is `true` when the text states that the company first assessed the incident as not material. - dojDelayDate: date Date of the Item 1.05(c) delay determination, e.g. `2024-05-09`. When the text names more than one determination, the value is the date of the first one. - dojDelayDates: array of dates Dates of all Item 1.05(c) delay determinations named in the text, e.g. `["2024-05-09", "2024-06-05"]`. - incident: object Nature, timing and source of the incident. - detectionDate: date Date on which the company discovered the incident or was notified of it, e.g. `2024-04-19`. When the text gives the date of an outage but no discovery date, the outage date is in `incidentStartDate`. - detectionDatePrecision: string Precision of `detectionDate` as stated in the text. Possible values: `day`, `month`, `quarter`, `year`, `not_stated`. - affectedEntity: string Name of the affected subsidiary when the text names one, e.g. `Coupang Corp.`. - environment: string Location of the compromised systems or data. `own_systems` includes cloud tenants that the company owns. Possible values: `own_systems`, `third_party_service_provider`, `third_party_cloud`, `third_party_saas_integration`, `unknown`. - thirdPartyType: string Type of third party involved in the incident, as written, e.g. `law firm`. - attackTypes: array of strings Types of attack as stated in the text. Possible values: `ransomware`, `data_exfiltration`, `social_engineering`, `phishing`, `credential_compromise`, `unauthorized_access`, `business_email_compromise`, `ddos`, `insider`, `supply_chain`, `not_stated`, `malware`, `vulnerability_exploit`, `account_takeover`, `unauthorized_ai_tool_use`, `website_defacement`, `digital_asset_theft`, `payment_fraud`. - threatActorNamed: string Name of the threat actor as written, e.g. `Midnight Blizzard (Cozy Bear)`. - ransomDemandMentioned: boolean Is `true` when the text mentions a ransom demand. - leakThreatMentioned: boolean Is `true` when the text mentions a threat to publish the data. - threatActorDeletionAssurance: boolean Is `true` when the text states that the threat actor deleted the data, or gave an assurance that it deleted the data. - ongoingAccess: string Status of the unauthorized access at the time of the filing, as stated in the text. Possible values: `contained`, `no_evidence_of_ongoing`, `ongoing`, `not_stated`. - investigationStatus: string Status of the investigation of the incident. Possible values: `ongoing`, `concluded`, `not_stated`. - threatActorType: string Type of threat actor. Set only when the text describes the actor, e.g. as a nation-state actor or a former employee. The value does not come from the attack type. Possible values: `nation_state`, `criminal`, `hacktivist`, `insider`, `not_stated`. - affectedEntityCountry: string Two-letter ISO 3166-1 country code of the affected subsidiary when it is outside the U.S., e.g. `KR`. - threatActorContact: boolean Is `true` when the threat actor contacted the company, e.g. to claim the attack or to demand payment. - incidentStartDate: date Date on which the incident started, e.g. `2024-04-14`. - ransomPaid: boolean Is `true` when the text states that the company paid a ransom. Is `false` when the text states that the company did not pay. - initialAccessViaThirdParty: boolean Is `true` when the attacker got access through a third party, e.g. a contractor session, a vendor firewall or a software integration. This also applies when the attack affected the company's own systems. - data: object Data affected by the incident. - status: string Status of the data as stated in the text. `exfiltrated_confirmed` means that the text confirms that data was stolen. `accessed_confirmed` means that the text confirms access to data. `potentially_accessed` means that data was possibly accessed. `no_evidence` means that the text says there is no evidence of access to data. Possible values: `exfiltrated_confirmed`, `accessed_confirmed`, `potentially_accessed`, `no_evidence`, `not_stated`. - categoriesConfirmed: array of strings Categories of data that the text confirms as affected, e.g. `["call_records", "contact_info"]`. In the values, `pii` is personal information, `phi` is protected health information, `dob` is date of birth and `ssn` is a Social Security number. `ssn_partial` and `financial_account_partial` mean that only a part of the number was affected. `customer`, `patient`, `employee` and `provider` name the group of persons whose data was affected. Possible values: `pii`, `ssn`, `dob`, `contact_info`, `phi`, `financial_account`, `customer`, `patient`, `employee`, `provider`, `proprietary_business`, `intellectual_property`, `research_and_development`, `financial_information`, `credentials`, `unspecified_confidential`, `ssn_partial`, `financial_account_partial`, `government_id`, `transaction_history`, `order_history`, `call_records`, `location_data`. - categoriesUnderAssessment: array of strings Categories of data that the company still assesses. Uses the same values as `categoriesConfirmed`. Possible values: `pii`, `ssn`, `dob`, `contact_info`, `phi`, `financial_account`, `customer`, `patient`, `employee`, `provider`, `proprietary_business`, `intellectual_property`, `research_and_development`, `financial_information`, `credentials`, `unspecified_confidential`, `ssn_partial`, `financial_account_partial`, `government_id`, `transaction_history`, `order_history`, `call_records`, `location_data`. - individualsAffected: integer Number of affected individuals as stated, e.g. `35500000`. - accountsAffected: integer Number of affected accounts as stated, e.g. `33000000`. - publishedByThreatActor: boolean Is `true` when the text states that the threat actor published the data, e.g. on a leak site or on the dark web. - impact: object Operational and financial impact of the incident on the company. - operationalImpact: string Impact on operations as stated in the text. `ongoing_disruption` means that the restoration is still in progress at the time of the filing. `temporary_disruption` means that operations were disrupted and are restored. `none_identified` means that the text says that the incident has not had a material impact on operations. When more than one value applies, the value is the first in this order: `material_disruption`, `ongoing_disruption`, `temporary_disruption`, `limited`, `none_identified`. Possible values: `none_identified`, `limited`, `material_disruption`, `ongoing_disruption`, `not_stated`, `temporary_disruption`. - functionsAffected: array of strings Affected business functions or systems as written, e.g. `["order fulfillment", "retail and e-commerce operations"]`. - restorationStatus: string Status of the restoration of the affected systems. `not_applicable` means that there was no disruption. Possible values: `not_applicable`, `in_progress`, `substantially_restored`, `fully_restored`, `not_stated`. - financialImpactAssessment: string Assessment of the financial impact as stated in the text. `material_incurred` means that a material financial impact occurred. `material_expected` means that a material financial impact is expected or reasonably likely. `not_material_expected` means that the company does not expect a material financial impact. `unable_to_determine` means that the company has not yet determined the financial impact. Possible values: `material_incurred`, `material_expected`, `not_material_expected`, `unable_to_determine`, `not_stated`. - financialImpactHorizon: array of strings Reporting periods in which the text expects the financial impact. Possible values: `current_quarter`, `current_year`, `long_term`, `prior_quarter`. - guidanceImpact: string Effect of the incident on the company's financial guidance. Possible values: `withdrawn`, `lowered`, `below_guidance_expected`, `reaffirmed`, `not_stated`. - quantifiedCostUSD: number Cost of the incident in USD, stated as one amount, e.g. `600000`. - insuranceMentioned: boolean Is `true` when the text mentions insurance. - insuranceExpectedToCover: boolean Is `true` when the text states that insurance is expected to cover some or all of the costs. - directLoss: object Direct loss of funds or assets, e.g. stolen digital assets or a misdirected payment. Is `null` when the text states no direct loss. - amountUSD: number Value of the loss in USD, e.g. `3665000`. - assetType: string Type of the lost asset as written, e.g. `bitcoin`. - quantity: number Quantity of the lost asset, e.g. `50.903`. - estimatedCostRangeUSD: object Range of the estimated costs in USD. Is `null` when the text states no range. - low: number Low end of the range, e.g. `180000000`. - high: number High end of the range, e.g. `400000000`. - customerCompensation: object Compensation to customers or other affected parties. Is `null` when the text states no compensation. - amountUSD: number Amount of the compensation in USD, e.g. `1200000000`. - form: string Form of the compensation as written, e.g. `purchase vouchers (KRW 1.685 trillion)`. - revenueImpactUSD: number Revenue lost or not fulfilled in USD as stated, e.g. `15000000`. - epsImpact: number Effect on earnings per share in USD as stated. A negative value is a reduction, e.g. `-0.64`. - otherFinancialEffects: string Other financial effects as stated that have no separate field, e.g. lender waivers, funding advances to providers or exclusions from adjusted earnings. - response: object Actions of the company in response to the incident, and notifications to third parties. - actions: array of strings Response actions as stated in the text. Possible values: `incident_response_plan`, `third_party_forensics`, `containment`, `credential_reset`, `restricted_remote_access`, `restore_from_backup`, `enhanced_monitoring`, `systems_taken_offline`, `systems_shutdown_precautionary`, `customer_notification`, `credit_monitoring_offered`, `cyber_insurer_notified`, `data_dissemination_mitigation`, `disabled_compromised_accounts`, `additional_access_controls`, `personnel_terminated`, `fraud_controls`, `security_hardening`. - lawEnforcementNotified: boolean Is `true` when the text states that the company notified law enforcement. - regulatorsNotified: string Status of the notification of regulators. Possible values: `notified`, `in_progress`, `planned`, `evaluating`, `not_stated`. - individualNotification: string Status of the notification of affected individuals. Possible values: `completed`, `in_progress`, `planned`, `evaluating`, `not_stated`, `none_planned`. - legal: object Lawsuits, regulatory inquiries and arrests related to the incident. - litigationCount: integer Number of lawsuits as stated, e.g. `1`. - cases: array of objects Lawsuits named in the text. - caption: string Case caption, e.g. `Haley v. Nutex Health, Inc.`. - caseNumber: string Case number, e.g. `4:26-cv-07197`. - court: string Court as written, e.g. `S.D. Tex., Houston Division`. - filedDate: date Date on which the lawsuit was filed, e.g. `2026-08-27`. - classAction: boolean Is `true` when the lawsuit is a class action. - claims: array of strings Claims as written, e.g. `["negligence", "unjust enrichment"]`. - regulatoryInquiry: boolean Is `true` when the text states that a regulator started an inquiry or an investigation. - arrestsMade: boolean Is `true` when the text states that persons were arrested in connection with the incident. - evidence: object One to five short quotes from the filing text that support key values. Each key is the name or the path of the field that the quote supports, e.g. `materialityStatus` or `data.categoriesConfirmed`. Each value is the quote. - governance: object Management changes related to the incident. - executiveDepartureLinked: boolean Is `true` when the text links the departure of an executive or a director to the incident. Is `false` when the text states that a departure is not related to the incident. - executiveRole: string Role of the person who left, as written, e.g. `CEO of Korean subsidiary (resigned 2025-12-10)`. - xbrl: object Text of Item 1.05 tagged with Inline XBRL in the cybersecurity disclosure taxonomy (`cyd`). Is present only when the filing contains these tags. - MaterialCybersecurityIncidentNatureTextBlock: string Text that describes the nature of the incident. - MaterialCybersecurityIncidentScopeTextBlock: string Text that describes the scope of the incident. - MaterialCybersecurityIncidentTimingTextBlock: string Text that describes the timing of the incident. - MaterialCybersecurityIncidentMaterialImpactOrReasonablyLikelyMaterialImpactTextBlock: string Text that describes the material impact or the reasonably likely material impact of the incident on the company. - MaterialCybersecurityIncidentInformationNotAvailableOrUndeterminedTextBlock: string Text that identifies the information that is not determined or not available at the time of the filing. ### Response Example JSON ```json { "total": { "value": 1, "relation": "eq" }, "data": [ { "filing": { "ticker": "T", "sic": "4813", "otherItems": [ "9.01" ], "periodOfReport": "2024-05-06", "accessionNo": "0000732717-24-000046", "cik": "732717", "companyName": "AT&T Inc.", "formType": "8-K", "filedAt": "2024-07-12", "url": "https://www.sec.gov/Archives/edgar/data/732717/000073271724000046/" }, "disclosure": { "filingRole": "initial", "priorDisclosures": [], "materialityStatus": "determined_not_material", "materialityDeterminationDate": null, "materialityBasis": [ "not_stated" ], "amendmentUndertaking": null, "isDeltaUpdate": false, "textSource": "item_body", "dojDelayInvoked": true, "dojDelayDate": "2024-05-09", "initiallyAssessedNotMaterial": null, "incidentKey": "732717-2024-05-06", "dojDelayDates": [ "2024-05-09", "2024-06-05" ] }, "incident": { "detectionDate": "2024-04-19", "detectionDatePrecision": "day", "incidentStartDate": "2024-04-14", "affectedEntity": null, "affectedEntityCountry": null, "environment": "own_systems", "thirdPartyType": "AT&T workspace on a third-party cloud platform", "attackTypes": [ "unauthorized_access", "data_exfiltration" ], "threatActorNamed": null, "threatActorType": "not_stated", "threatActorContact": null, "ransomDemandMentioned": null, "leakThreatMentioned": null, "threatActorDeletionAssurance": null, "ongoingAccess": "contained", "investigationStatus": "not_stated", "ransomPaid": null, "initialAccessViaThirdParty": null }, "data": { "status": "exfiltrated_confirmed", "categoriesConfirmed": [ "call_records", "contact_info", "customer", "location_data" ], "categoriesUnderAssessment": [], "individualsAffected": null, "accountsAffected": null, "publishedByThreatActor": false }, "impact": { "operationalImpact": "none_identified", "functionsAffected": [], "restorationStatus": "not_stated", "financialImpactAssessment": "not_material_expected", "financialImpactHorizon": [], "guidanceImpact": "not_stated", "quantifiedCostUSD": null, "directLoss": null, "insuranceMentioned": false, "insuranceExpectedToCover": null, "estimatedCostRangeUSD": null, "customerCompensation": null }, "response": { "actions": [ "incident_response_plan", "third_party_forensics", "containment", "security_hardening" ], "lawEnforcementNotified": true, "regulatorsNotified": "not_stated", "individualNotification": "planned" }, "legal": { "litigationCount": null, "cases": [], "regulatoryInquiry": null, "arrestsMade": true }, "governance": { "executiveDepartureLinked": null, "executiveRole": null }, "evidence": { "environment": "threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions", "dojDelayInvoked": "On May 9, 2024, and again on June 5, 2024, the U.S. Department of Justice determined that, under Item 1.05(c) of Form 8-K, a delay in providing public disclosure was warranted", "data.categoriesConfirmed": "records of calls and texts of nearly all of AT&T's wireless customers ... For a subset of records, one or more cell site identification number(s) are also included", "materialityStatus": "this incident has not had a material impact on AT&T's operations, and AT&T does not believe that this incident is reasonably likely to materially impact AT&T's financial condition or results of operations" } } ] } ```