Disclosure · 11 filers

Data Breach

11 companies wrote this into a filing in the last 7 days, down from 20. Below: which of them, and what the corpus says they now owe.

Data measured , page built 22 September 2026 at 16:18 UTC.

11filers, current period
20the period before
121controls it touches
90frameworks
first appears May 2008 2008 2026 71 filings in the busiest month
Data Breach in 10-K and 10-Q filings, by month. The marked line is the first month any public company in our record used the phrase; everything left of it is nobody writing it down.
Companies disclosing it 11 wrote this into a filing with the SEC
What it obligates 121 controls across 90 frameworks whose text speaks to it
Employers hiring for it 796 open US roles name it, and the ones below are hiring now

The long view, in 8-K filings

An 8-K is filed within four business days of an event, so this counts filings made because something happened. Every month since 2008. The last point is the current month and is still filling, so it always looks lower than it will be.

 
03671
2008 peak 71 in November 2025 2026

Who disclosed it

From SEC full-text search over 8-K filings. Every row links to the filing itself.

CompanyFormFiled
Algorhythm Holdings, Inc. RIME8-K2026-09-21filing
5E Advanced Materials, Inc.8-K2026-09-15filing
Clene Inc. CLNN8-K2026-09-16filing
ACP Holdings Acquisition Corp.8-K2026-09-16filing
DataMeds AI, Inc. MEDS8-K2026-09-16filing
Axe Compute Inc. AGPU8-K2026-09-17filing
ChampionsGate Acquisition Corp8-K2026-09-18filing
Mistras Group, Inc. MG8-K2026-09-18filing
Aperture AC8-K2026-09-16filing
Lexeo Therapeutics, Inc. LXEO8-K2026-09-22filing
AETHLON MEDICAL INC AEMD8-K2026-09-17filing

The full search on EDGAR

Who is hiring for it

A sample of the open roles naming this phrase. An employer paying a salary against something is the least ambiguous demand signal there is, and every row links to the posting so the claim can be checked rather than believed. The total above is the whole US market; these are the ones we hold the posting for.

RolePosted
Sr Princ Product Manager - Digital Footprint Control
Gen Digital Inc. · USA - Mountain View, CA
2026-09-03
Senior Technical Support Engineer
Ping Identity Holding Corp. · USA - Remote
2026-08-27
Senior Counsel, Cyber Security and Incident Response
CoreWeave, Inc. · Livingston, NJ
2026-08-25
Senior Technical Support Engineer - Shifted Workweek
Ping Identity Holding Corp. · USA - Remote
2026-07-27
Cloud Security Engineer II (AWS, SecOps)
TripAdvisor, Inc. · Kraków
2026-07-23
DevSecOps Engineer (Cloud Security, AWS)
TripAdvisor, Inc. · Kraków
2026-07-17

How it actually arrives

An 8-K's meaning is in its item number, not its text. These are the items the filings containing this phrase were filed under. The first group is something that happened to the company. The second is the phrase turning up in the ordinary course of reporting, most often in an earnings release, which is a very different thing and is usually the larger number.

Filed because something happened Companies
Other material event
Item 8.01
693
Director or officer departure
Item 5.02
372
Change of accountant
Item 4.01
35
Delisting or listing rule failure
Item 3.01
32
Bankruptcy or receivership
Item 1.03
18
Material impairment
Item 2.06
4
Financial statements no longer reliable
Item 4.02
2
Mentioned in routine reporting Companies
Financial statements and exhibits
Item 9.01
1789
Entry into a material agreement
Item 1.01
1641
Regulation FD disclosure
Item 7.01
967
Completion of an acquisition
Item 2.01
303
Results of operations, the earnings release
Item 2.02
172
Shareholder vote
Item 5.07
40

This is why a headline count on its own overstates the case. Where the routine number dominates, the phrase is being tracked as language rather than as events.

Which industries file it

Companies grouped by the industry classification on their own filing. A count, not a survey.

IndustryCompanies
Holding and investment offices283
Chemicals and pharmaceuticals258
Software and IT services208
Banking109
Instruments and medical devices99
Services and entertainment86
Electronics and electrical equipment81
Industrial machinery68
Retail61
Insurance53

What it obligates

Our corpus holds 121 controls across 90 frameworks whose text speaks to this. Not a judgement: these controls say so, and each is one lookup from its source document. Ordered by how much each framework has to say about it, so the one that will cost you the most work is first. Every name opens that framework in the corpus.

FrameworkControls
Notifiable Data Breaches Scheme (Australia) verified
Australia
6
Japan FSA Cybersecurity Guidelines for Financial Institutions verified
Japan
5
India DPDP Act verified
India
4
Brunei Personal Data Protection Order 2022 (PDPO) verified
Brunei Darussalam
4
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) verified
Hong Kong
3
GDPR verified
European Union
2
CIS Controls v8 verified
International
2
Privacy Act 1988 (Australia) verified
Australia
2
ISO 27018
International
2
NIS2 Directive verified
European Union
2
Family Educational Rights and Privacy Act (FERPA) verified
United States
2
Ghana Data Protection Act 2012 (Act 843) verified
Ghana
2
India CERT-In Cyber Security Directions 2022 verified
India
2
Jamaica Data Protection Act 2020 verified
Jamaica
2

What an auditor will ask you to produce

The artefacts named on those controls, most frequently cited first.

How it usually fails

Recorded when each control was verified against its source. This is where programmes that think they are covered turn out not to be.

114If you already run ISO 27001:2013, that is the 114 controls behind this disclosure, already evidenced.
584And ISO 27701:2019 is not a separate programme. 584 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
371And ISO 27002:2022 is not a separate programme. 371 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
248And ISO 22301:2019 is not a separate programme. 248 of its controls are the same controls. If it is on next year's plan, that part of it is already done.

Run as two programmes

698 controls

ISO 27001:2013 and ISO 27701:2019 scoped separately, each with its own evidence, its own owner and its own budget line. This is how almost everybody does it.

Run once, counted twice

584 already done

584 of ISO 27701:2019's controls are controls you evidenced for ISO 27001:2013. Same artefacts, same owner, no second effort. The mapping is the only reason anybody knows.

first appears May 2008 2008 2026 71 filings in the busiest month
Data Breach in 10-K and 10-Q filings, by month. The marked line is the first month any public company in our record used the phrase; everything left of it is nobody writing it down.

What this actually means

Why now
11 public companies wrote this into an 8-K in the last seven days, 45% fewer than the seven before. That is not sentiment or a survey. It is a count of companies choosing to put a phrase into a document they are legally accountable for.
Who already cares
796 open US roles name this work today, which suggests increased attention to it beyond what any filing says. A job advertisement clears a budget holder and a filing clears legal, so the two answer to different people. We have not measured which moves first, only that both are moving.
What comes into scope
Once the phrase is on the record it maps to obligations within ISO 27001:2013, ISO 27001:2022, HIPAA Security Rule. 370 controls behind those, and the difference between asserting them and evidencing them is the whole of the work.
Who is quietly ahead
Anyone already running ISO 27001:2013 has done 584 of the controls that carry ISO 27701:2019 too. Same evidence, second standard. Most organisations run those as two programmes with two budgets because nobody told them the mapping existed.
Who is exposed
80 companies disclosed this for the first time in the last ninety days, out of 1815 in total. A first mention is a company deciding it can no longer not say it. Whoever has not yet is either genuinely unaffected or has not looked, and nothing here distinguishes the two.

What this obligates

The instruments in our corpus that govern this disclosure, and how many controls sit behind each. This is not a filing count. It is what applies once a company has written the phrase down.

8 frameworks, 370 controls between them.

What closing it also moves

The same controls appear in other frameworks through mappings held in our corpus. Work done here is already progress there. This is the part that is not in EDGAR and not in any public dataset: it comes from mappings built and verified by hand, control by control.

ISO 27701:2019584
ISO 27002:2022371
ISO 22301:2019248
ISO/IEC 42001:2023170
PCI DSS 4.0151
COBIT 2019148
NIS2 Directive109

Counted as controls reached through cross-framework mappings. It measures overlap of work, not compliance with the named framework.

Run as two programmes

698 controls

ISO 27001:2013 and ISO 27701:2019 scoped separately, each with its own evidence, its own owner and its own budget line. This is how almost everybody does it.

Run once, counted twice

584 already done

584 of ISO 27701:2019's controls are controls you evidenced for ISO 27001:2013. Same artefacts, same owner, no second effort. The mapping is the only reason anybody knows.

114If you already run ISO 27001:2013, that is the 114 controls behind this disclosure, already evidenced.
584And ISO 27701:2019 is not a separate programme. 584 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
371And ISO 27002:2022 is not a separate programme. 371 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
248And ISO 22301:2019 is not a separate programme. 248 of its controls are the same controls. If it is on next year's plan, that part of it is already done.

If that number surprised you, the same measurement across every topic we track:
What changed this week →

This is what it looks like when the same failure is named by standards bodies who never spoke to each other:
How compliance programmes fail →

And the companies that have already written this into a filing:
Data Breach filers →

Tell me when Data Breach files something new

One email when a public company newly discloses this, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

Where this comes from

The left half is public record: SEC full-text search over 8-K filings, counted across a 7 day window against the equivalent window before it. You can check every row.

The right half is ours: 723 frameworks and 20,473 controls, 531 of those frameworks verified against their source documents, with the auditor evidence and common failure modes recorded control by control. Controls appear here because their own text names this term.

Cite this

The Art of Service Signals. Data Breach corporate disclosure activity: 11 filers against 20 in the prior period, in 8-K filings over seven days against the seven before. Accessed 23 September 2026. https://signals.theartofservice.com/t/data-breach/

Free to use with attribution, no permission needed. The chart downloads as an SVG with the source printed on it. If you cite it we would like to know, but you do not need to ask.

Today's edition · How programmes fail · The obligation index