REGULATORY DISCLOSURES

SEC Form 8-K Item 1.05 Tracker

Comprehensive tracker of public cybersecurity disclosures filed under SEC Item 1.05 and Item 8.01 rules. Analyze filing delay windows, extortion payments, material impact statements, and legal exposure.

Key Facts

  • Item 1.05 mandates public disclosure within four business days after determining an incident is material.
  • Determination must be made without unreasonable delay, focusing on quantitative and qualitative factors.
  • National security delay provisions require written determination from the U.S. Attorney General.
  • Federal court precedents establish that internal misstatements regarding cyber controls create severe Rule 10b-5 liability.
1. Trigger Point

Determination, Not Discovery

The four-business-day filing clock starts the instant the registrant determines the incident is material, not when the breach was first discovered. However, materiality assessments cannot be unreasonably delayed.

2. Scope of Materiality

Quantitative & Qualitative

Materiality encompasses both balance sheet costs (loss of revenue, response fees) and qualitative factors: customer churn, intellectual property theft, reputational harm, and regulatory exposure.

3. National Security Delay

Strict DOJ Certification

Registrants can delay Item 1.05 filing only if the Attorney General notifies the SEC in writing that public disclosure poses a substantial risk to national security or public safety.

Notable Primary SEC 8-K Disclosures

Company & Ticker Filing Item Filing Date Threat Actor Disclosed Loss / Cost Official Record
UnitedHealth Group / Change Healthcare
NYSE: UNH
Item 1.05 & 8.01 Feb 22, 2024 ALPHV / BlackCat Affiliate $3.3B cumulative response costs, loan advances, and customer disruption SEC EDGAR →
Caesars Entertainment, Inc.
NASDAQ: CZR
Item 8.01 (Pre-Rule) Sep 14, 2023 Scattered Spider / UNC3944 Loyalty program database exfiltration of 65M members, $15M extortion settlement SEC EDGAR →
MGM Resorts International
NYSE: MGM
Item 8.01 / 10-Q Oct 5, 2023 Scattered Spider / ALPHV $100M direct adjusted EBITDAR loss, $10M technology remediation costs SEC EDGAR →
Hewlett Packard Enterprise (HPE)
NYSE: HPE
Item 1.05 Jan 24, 2024 Midnight Blizzard (APT29 / Russian SVR) Unauthorized access to Office 365 cloud email environments of cybersecurity staff SEC EDGAR →
Prudential Financial, Inc.
NYSE: PRU
Item 1.05 Feb 15, 2024 ALPHV / BlackCat Administrative data exfiltration from corporate tenants and employee directories SEC EDGAR →
First American Financial Corp.
NYSE: FAF
Item 1.05 Dec 22, 2023 Undisclosed Ransomware Group Nationwide title closing, escrow processing, and banking system isolation SEC EDGAR →
SolarWinds Corporation
NYSE: SWI
Item 8.01 Dec 14, 2020 Cozy Bear (APT29 / Russian SVR) 18,000 corporate/government customers impacted, subsequent SEC enforcement action SEC EDGAR →

Filing Case Studies & Forensic Analysis

UnitedHealth Group / Change Healthcare 24 hrs
Actor: ALPHV / BlackCat Affiliate | Extortion: $22.0M

First massive public test of SEC Item 1.05 rules. Filed initial 8-K within 24 hours of discovering critical enterprise ransomware disruption. Later disclosed $22M ransom payment and nationwide healthcare clearinghouse suspension.

Item: Item 1.05 & 8.01 View Form 8-K →
Caesars Entertainment, Inc. 168 hrs
Actor: Scattered Spider / UNC3944 | Extortion: $15.0M

Disclosed payment of $15 million in extortion fees to prevent publication of exfiltrated rewards customer data obtained via outsourced IT helpdesk social engineering.

Item: Item 8.01 (Pre-Rule) View Form 8-K →
MGM Resorts International 600 hrs
Actor: Scattered Spider / ALPHV | Extortion: $0 (Refused)

Refused extortion payment. System shutdown caused 9-day blackout of casino slots, digital hotel keys, and reservation systems across the Las Vegas Strip.

Item: Item 8.01 / 10-Q View Form 8-K →
Hewlett Packard Enterprise (HPE) 1,032 hrs
Actor: Midnight Blizzard (APT29 / Russian SVR) | Extortion: $0 (Espionage)

Russian foreign intelligence SVR infiltrated M365 email environment using legacy test tenant credentials. HPE assessed incident did not have material financial impact.

Item: Item 1.05 View Form 8-K →
Prudential Financial, Inc. 240 hrs
Actor: ALPHV / BlackCat | Extortion: $0

Disclosed intrusion under new Item 1.05 within 4 business days of determining materiality, reporting unauthorized access to corporate directory systems.

Item: Item 1.05 View Form 8-K →
First American Financial Corp. 48 hrs
Actor: Undisclosed Ransomware Group | Extortion: Undisclosed

Shut down production book-of-business systems to contain operational intrusion, halting residential real estate closings nationwide right before holiday closures.

Item: Item 1.05 View Form 8-K →
SolarWinds Corporation 48 hrs
Actor: Cozy Bear (APT29 / Russian SVR) | Extortion: $0 (Supply Chain)

Historic supply chain breach disclosure following discovery of SUNBURST backdoor injected into Orion software updates. Led to landmark SEC civil enforcement charges.

Item: Item 8.01 View Form 8-K →