SEC Form 8-K Item 1.05 Tracker
Comprehensive tracker of public cybersecurity disclosures filed under SEC Item 1.05 and Item 8.01 rules. Analyze filing delay windows, extortion payments, material impact statements, and legal exposure.
Key Facts
- Item 1.05 mandates public disclosure within four business days after determining an incident is material.
- Determination must be made without unreasonable delay, focusing on quantitative and qualitative factors.
- National security delay provisions require written determination from the U.S. Attorney General.
- Federal court precedents establish that internal misstatements regarding cyber controls create severe Rule 10b-5 liability.
Determination, Not Discovery
The four-business-day filing clock starts the instant the registrant determines the incident is material, not when the breach was first discovered. However, materiality assessments cannot be unreasonably delayed.
Quantitative & Qualitative
Materiality encompasses both balance sheet costs (loss of revenue, response fees) and qualitative factors: customer churn, intellectual property theft, reputational harm, and regulatory exposure.
Strict DOJ Certification
Registrants can delay Item 1.05 filing only if the Attorney General notifies the SEC in writing that public disclosure poses a substantial risk to national security or public safety.
Notable Primary SEC 8-K Disclosures
| Company & Ticker | Filing Item | Filing Date | Threat Actor | Disclosed Loss / Cost | Official Record |
|---|---|---|---|---|---|
| UnitedHealth Group / Change Healthcare NYSE: UNH | Item 1.05 & 8.01 | Feb 22, 2024 | ALPHV / BlackCat Affiliate | $3.3B cumulative response costs, loan advances, and customer disruption | SEC EDGAR → |
| Caesars Entertainment, Inc. NASDAQ: CZR | Item 8.01 (Pre-Rule) | Sep 14, 2023 | Scattered Spider / UNC3944 | Loyalty program database exfiltration of 65M members, $15M extortion settlement | SEC EDGAR → |
| MGM Resorts International NYSE: MGM | Item 8.01 / 10-Q | Oct 5, 2023 | Scattered Spider / ALPHV | $100M direct adjusted EBITDAR loss, $10M technology remediation costs | SEC EDGAR → |
| Hewlett Packard Enterprise (HPE) NYSE: HPE | Item 1.05 | Jan 24, 2024 | Midnight Blizzard (APT29 / Russian SVR) | Unauthorized access to Office 365 cloud email environments of cybersecurity staff | SEC EDGAR → |
| Prudential Financial, Inc. NYSE: PRU | Item 1.05 | Feb 15, 2024 | ALPHV / BlackCat | Administrative data exfiltration from corporate tenants and employee directories | SEC EDGAR → |
| First American Financial Corp. NYSE: FAF | Item 1.05 | Dec 22, 2023 | Undisclosed Ransomware Group | Nationwide title closing, escrow processing, and banking system isolation | SEC EDGAR → |
| SolarWinds Corporation NYSE: SWI | Item 8.01 | Dec 14, 2020 | Cozy Bear (APT29 / Russian SVR) | 18,000 corporate/government customers impacted, subsequent SEC enforcement action | SEC EDGAR → |
Filing Case Studies & Forensic Analysis
First massive public test of SEC Item 1.05 rules. Filed initial 8-K within 24 hours of discovering critical enterprise ransomware disruption. Later disclosed $22M ransom payment and nationwide healthcare clearinghouse suspension.
Disclosed payment of $15 million in extortion fees to prevent publication of exfiltrated rewards customer data obtained via outsourced IT helpdesk social engineering.
Refused extortion payment. System shutdown caused 9-day blackout of casino slots, digital hotel keys, and reservation systems across the Las Vegas Strip.
Russian foreign intelligence SVR infiltrated M365 email environment using legacy test tenant credentials. HPE assessed incident did not have material financial impact.
Disclosed intrusion under new Item 1.05 within 4 business days of determining materiality, reporting unauthorized access to corporate directory systems.
Shut down production book-of-business systems to contain operational intrusion, halting residential real estate closings nationwide right before holiday closures.
Historic supply chain breach disclosure following discovery of SUNBURST backdoor injected into Orion software updates. Led to landmark SEC civil enforcement charges.