RADIANT LOGISTICS, INC disclosed a cybersecurity incident: initial stages of a cybersecurity incident related to its Canadian operations. Impact: service delays for customers in Canada, but no material impact on overall operations yet determined. Materiality is still being assessed. Discovered 2024-03-14.
“While the investigation is ongoing, as of the date of this filing, the incident has not had a material impact on the Company’s overall operations, and the Company has not determined the incident is reasonably likely to materially impact the Company's financial conditions or results of operations.”
HZOMARINEMAX INC
MARINEMAX INC disclosed a cybersecurity incident: unauthorized third-party access to portions of its information environment. Impact: containment measures resulted in some disruption to a portion of the business; operations continued in all material respects; incident has not had a material impact on operations; still determining if reasonably likely to materially impact financial conditions or results. Materiality is still being assessed. Discovered 2024-03-10.
“determined on March 10, 2024, that it experienced a “cybersecurity incident,” as defined in applicable Securities and Exchange Commission rules, whereby a third party gained unauthorized access to portions of its information environment”
MSFTMICROSOFT CORP
MICROSOFT CORP disclosed a cybersecurity incident: a nation-state threat actor gained access to and exfiltrated information from a very small percentage of employee email accounts, including senior leadership and cybersecurity, legal, and other functions, and has used or attempted to use that information to gain unauthorized access to source code re. Impact: the incident has not had a material impact on the Company’s operations, but the Company has not yet determined that it is reasonably likely to materially impact financial condition or results of operations. Materiality is still being assessed.
“As of the date of this filing, the incident has not had a material impact on the Company’s operations. The Company has not yet determined that the incident is reasonably likely to materially impact the Company’s financial condition or results of operations.”
UNHUNITEDHEALTH GROUP INC
UNITEDHEALTH GROUP INC disclosed a cybersecurity incident: cybercrime threat actors accessed certain Change Healthcare IT systems. Impact: disruption to pharmacy, medical claims and payment services; company working to restore systems. Materiality is still being assessed.
“As of the date of this Amendment, the Company has not determined the incident is reasonably likely to materially impact the Company’s financial condition or results of operations.”
Federal Home Loan Bank of New York
Federal Home Loan Bank of New York disclosed a cybersecurity incident: unknown persons attempted to fraudulently obtain funds from the Bank due to a fourth-party vendor compromise. Impact: no unauthorized transactions executed, no monies transferred, Bank members able to continue transactions, no material impact on operations or financial condition. Company determined it not material. Discovered 2024-02-21.
“On February 21, 2024, the Federal Home Loan Bank of New York (“Bank”), through its operational controls, detected unknown persons attempting to fraudulently obtain funds from the Bank (the “incident”).”
CORCencora, Inc.
Cencora, Inc. disclosed a cybersecurity incident: data from its information systems had been exfiltrated, some of which may contain personal information. Impact: the incident has not had a material impact on the Company’s operations, and its information systems continue to be operational. Materiality is still being assessed. Discovered 2024-02-21.
“On February 21, 2024, Cencora, Inc. (the “Company”), learned that data from its information systems had been exfiltrated, some of which may contain personal information.”
UNHUNITEDHEALTH GROUP INC
UNITEDHEALTH GROUP INC disclosed a cybersecurity incident: a suspected nation-state associated cyber security threat actor had gained access to some of the Change Healthcare information technology systems. Impact: the Company proactively isolated the impacted systems from other connecting systems; working to restore systems but cannot estimate the duration or extent of the disruption; certain networks and transactional services may not be accessible. Company determined it not material. Discovered 2024-02-21.
“As of the date of this report, the Company has not determined the incident is reasonably likely to materially impact the Company’s financial condition or results of operations.”
PRUPRUDENTIAL FINANCIAL INC
PRUDENTIAL FINANCIAL INC disclosed a cybersecurity incident: a threat actor gained unauthorized access to certain systems, accessed and exfiltrated limited data including client information, personally identifiable information, and Company administrative/user data, and accessed a small percentage of employee/contractor accounts. Impact: No evidence of malware, ransomware, data destruction/alteration; incident has not had a material impact on operations; Company has not determined it is reasonably likely to materially impact financial condition or results. Materiality is still being assessed. Discovered 2024-02-05.
“As of the date of this Report, the incident has not had a material impact on the Company’s operations, and the Company has not determined the incident is reasonably likely to materially impact the Company’s financial condition or results of operations.”
PRUPRUDENTIAL FINANCIAL INC
PRUDENTIAL FINANCIAL INC disclosed a cybersecurity incident: A threat actor gained unauthorized access to certain systems; accessed administrative and user data from certain IT systems and a small percentage of user accounts of employees and contractors. Impact: The incident has not had a material impact on the Company’s operations, and the Company has not determined the incident is reasonably likely to materially impact the Company’s financial condition or results of operations. Company determined it not material. Discovered 2024-02-05.
“On February 5, 2024, Prudential Financial, Inc. (the “Company” or “we”) detected that, beginning February 4, 2024, a threat actor had gained unauthorized access to certain of our systems. With assistance from external cybersecurity experts, we immediately activated our cybersecurity incident response process to investigate, contain, and remediate the incident. As of the date of this Report, we believe that the threat actor, who we suspect to be a cybercrime group, accessed Company administrative and user data from certain information technology systems and a small percentage of Company user accounts associated with employees and contractors. We continue to investigate the extent of the incident, including whether the threat actor accessed any additional information or systems, to determine the impact of the incident. On the basis of the investigation to date, we do not have any evidence that the threat actor has taken customer or client data. We have reported this matter to relevant la”
SSBSouthState Bank Corp
SouthState Bank Corp disclosed a cybersecurity incident: detected a cybersecurity incident on February 6, 2024; proactively isolated parts of its network causing some disruption to business processes. Impact: incident has not had a material impact on operations as of filing date; ongoing investigation; not yet determined if reasonably likely to materially impact financial condition or results. Materiality is still being assessed. Discovered 2024-02-06.
“the incident has not had a material impact on the Company's operations, and the Company has not determined the incident is reasonably likely to materially impact the Company's financial conditions or results of operations”
HPEHewlett Packard Enterprise Co
Hewlett Packard Enterprise Co disclosed a cybersecurity incident: Unauthorized access by suspected nation-state actor Midnight Blizzard/Cozy Bear to HPE's cloud-based email environment; data accessed and exfiltrated beginning in May 2023 from a small percentage of HPE mailboxes. Impact: Incident has not had a material impact on operations; the Company has not determined it is reasonably likely to materially impact financial condition or results of operations. Company determined it not material. Discovered 2023-12-12.
“As of the date of this filing, the incident has not had a material impact on the Company’s operations, and the Company has not determined the incident is reasonably likely to materially impact the Company’s financial condition or results of operations.”
MSFTMICROSOFT CORP
MICROSOFT CORP disclosed a cybersecurity incident: A nation-state associated threat actor gained access to and exfiltrated information from a very small percentage of employee email accounts, including members of senior leadership and employees in cybersecurity, legal, and other functions. Impact: The incident has not had a material impact on operations; the Company has not yet determined whether it is reasonably likely to materially impact financial condition or results of operations. Materiality is still being assessed. Discovered 2024-01-12.
“On January 12, 2024, Microsoft (the “Company” or “we”) detected that beginning in late November 2023, a nation-state associated threat actor had gained access to and exfiltrated information from a very small percentage of employee email accounts including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, on the basis of preliminary analysis.”
VFCV F CORP
V F CORP disclosed a cybersecurity incident: Unauthorized occurrences on a portion of its IT systems, theft of personal data of approximately 35.5 million individual consumers. Impact: Disruption to operations including interrupted replenishment of retail store inventory and delayed order fulfillment; impacts are no longer ongoing and are not material to financial condition and results of operations. Company determined it not material. Discovered 2023-12-13.
“As of the date of this Amendment, VF also believes the impacts of the cyber incident are not material and are not reasonably likely to be material to its financial condition and results of operations.”
FAFFirst American Financial Corp
First American Financial Corp disclosed a cybersecurity incident: unauthorized activity on certain of its information technology systems. Impact: material impact on Q4 2023 results of operations; revenue delayed from Q4 2023 to Q1 2024; loss of revenue from transactions moved to other providers; one-time expenses incurred. Materiality is still being assessed.
“As disclosed in the Original Report, the Company identified unauthorized activity on certain of its information technology systems. Upon detection, the Company acted to contain, assess and remediate the incident.”
FAFFirst American Financial Corp
First American Financial Corp disclosed a cybersecurity incident: unauthorized activity on certain information technology systems; perpetrator accessed certain Company systems, exfiltrated data and encrypted data on certain non-production systems. Impact: Company is in the process of restoring access to its systems and resuming normal business operations; material impact cannot be determined yet. Materiality is still being assessed.
“The Company continues to assess whether the incident will have a material impact on the Company’s financial condition or results of operations, which at this point cannot be determined.”
FAFFirst American Financial Corp
First American Financial Corp disclosed a cybersecurity incident: unauthorized activity on certain information technology systems. Impact: cannot estimate duration or extent of disruption; primary website may be inaccessible. Materiality is still being assessed.
“The Company is also assessing the impact of the incident and whether it may have a material impact on its financial condition and results of operations, which at this point cannot be determined.”
VFCV F CORP
V F CORP disclosed a cybersecurity incident: Unauthorized occurrences detected on IT systems, threat actor encrypted some IT systems and stole data including personal data. Impact: Has had and is reasonably likely to continue to have a material impact on business operations; not yet determined whether reasonably likely to materially impact financial condition or results of operations. Materiality is still being assessed. Discovered 2023-12-13.
“The Company has not yet determined whether the incident is reasonably likely to materially impact the Company’s financial condition or results of operations.”
Facts are extracted by an LLM and gated to those whose source quote is present verbatim in the filing text. Coverage is best-effort while backfill and monitoring mature; this is not yet a full-market index. See methodology.