Cyber incidents · what happened next
How did companies perform after major cyber incidents?
Incident Impact brings together 30 documented cases with the affected company’s share-price performance, SPY and a fixed-panel view of media attention during the first 14 days. Pick a case and see what happened next.
Company–incident pairs
- Scope starts
- Jan 1, 2001
- Cases in this release
- 2007–2024
- Listed on
- NYSE · Nasdaq · Cboe
- Benchmark
- SPY adjusted close
This site shows how share prices moved after an incident became public. It does not prove that the incident caused the move. Company news, sector moves and the wider market can affect every result. Educational only — not investment advice.
Across the catalog
The results are mixed
The large number is the median difference between the company return and SPY. “Below SPY” is the share of cases that trailed the benchmark. These figures start at the pre-disclosure baseline rather than one shared post-incident entry point.
Media context across the catalog
How the 30 incidents were covered
We recovered written articles whose recorded headlines named the selected company during the first 14 days after disclosure. The fixed seven-family panel is an observed lower bound, not a complete count of US coverage.
Publication pace
- First 48 hours
- 280 38.6%
- 48–72 hours
- 48 6.6%
- Days 4–7
- 208 28.7%
- Days 8–14
- 189 26.1%
Local headline framing
- Descriptive
- 90 12.4%
- Adverse event
- 400 55.2%
- Mitigation or action
- 222 30.6%
- Favorable
- 13 1.8%
A useful starting point · CRWD
CrowdStrike makes the idea look compelling
Buying three days after disclosure and holding for a year would have turned $1,000 into $1,786, versus $1,148 in SPY.
It is a strong positive example for buying after an incident. It is not representative of the catalog, and the gain may reflect CrowdStrike’s wider business performance rather than a general post-incident rebound. The other 29 cases are why it is worth looking beyond it.
View the CrowdStrike case- Entry
- Jul 22, 2024
- Exit
- Jul 22, 2025
- CrowdStrike value
- $1,786
- SPY value
- $1,148
Hypothetical $1,000
What would $1,000 have looked like?
Compare $1,000 in CRWD with $1,000 in SPY, bought and measured on the same dates.
Entry Jul 22, 2024 Exit Jan 22, 2025
Uses fractional shares and adjusted close. Leaves out taxes, fees and slippage. The holding period starts on the purchase date. This is a historical illustration, not an investment strategy.
Selected cases
Pick an incident
AT&T
AT&T disclosed that threat actors illegally downloaded call and text interaction records covering nearly all wireless customers for specified periods.
UnitedHealth Group (Change Healthcare)
The Change Healthcare ransomware attack disrupted US claims, pharmacy and payment infrastructure on a national scale.
Microsoft
Microsoft disclosed that Midnight Blizzard accessed and exfiltrated email from a small percentage of corporate accounts, including senior leadership.
Caesars Entertainment
Caesars disclosed a social-engineering attack through an outsourced IT support vendor that led to theft of loyalty-program customer data.
MGM Resorts International
MGM disclosed a cybersecurity issue that forced system shutdowns and disrupted hotel and casino operations across multiple US properties.
The Clorox Company
Clorox disclosed unauthorized activity that forced systems offline and later caused widescale operational, order-processing and product-availability disruption.
One important limit
After is not the same as because.
Earnings, company news and the wider market do not pause for a cyber incident. SPY gives us a consistent comparison, not a causal answer.
- Each case is qualified before looking at its returns.
- Adjusted close includes splits and reinvested dividends.
- The catalog is curated, not complete.
- The historical comparisons are not investment advice.