Cyber incidents · what happened next
How did companies perform after major cyber incidents?
We matched 30 reviewed cases with the affected company’s share-price performance and SPY. Pick a case, choose a time window, and see what happened next.
Reviewed company–incident pairs
- Scope starts
- Jan 1, 2001
- Cases in this release
- 2007–2024
- Listed on
- NYSE · Nasdaq · Cboe
- Benchmark
- SPY adjusted close
This site shows how share prices moved after an incident became public. It does not prove that the incident caused the move. Company news, sector moves and the wider market can affect every result. Educational only — not investment advice.
Across the catalog
What the 30 cases show
The large number is the median difference between the company return and SPY. “Below SPY” is the share of cases that trailed the benchmark. Cases without enough history are left out.
Reference case · CRWD
CrowdStrike: timing matters
A faulty Falcon content update caused Windows crashes across millions of hosts and disrupted critical services worldwide.
CrowdStrike published the update at 04:09 UTC on July 19, 2024, before the US market opened. That makes July 18 the baseline and July 19 the first market session after disclosure.
View the CrowdStrike case- Baseline
- Jul 18, 2024
- Reaction
- Jul 19, 2024
- Company return
- -22.2%
- SPY return
- +1.3%
Hypothetical $1,000
What would $1,000 have looked like?
Compare $1,000 in CRWD with $1,000 in SPY, bought and measured on the same dates.
Entry Jul 22, 2024 Exit Jan 22, 2025
Uses fractional shares and adjusted close. Leaves out taxes, fees and slippage. The holding period starts on the purchase date. This is a historical illustration, not an investment strategy.
Selected cases
Pick an incident
AT&T
AT&T disclosed that threat actors illegally downloaded call and text interaction records covering nearly all wireless customers for specified periods.
UnitedHealth Group (Change Healthcare)
The Change Healthcare ransomware attack disrupted US claims, pharmacy and payment infrastructure on a national scale.
Microsoft
Microsoft disclosed that Midnight Blizzard accessed and exfiltrated email from a small percentage of corporate accounts, including senior leadership.
Caesars Entertainment
Caesars disclosed a social-engineering attack through an outsourced IT support vendor that led to theft of loyalty-program customer data.
MGM Resorts International
MGM disclosed a cybersecurity issue that forced system shutdowns and disrupted hotel and casino operations across multiple US properties.
The Clorox Company
Clorox disclosed unauthorized activity that forced systems offline and later caused widescale operational, order-processing and product-availability disruption.
One important limit
After is not the same as because.
Earnings, company news and the wider market do not pause for a cyber incident. SPY gives us a consistent comparison, not a causal answer.
- We qualify each case before looking at its returns.
- Adjusted close includes splits and reinvested dividends.
- The catalog is curated, not complete.
- The results are educational, not investment advice.