01 · Unit
One company, one event, one observation
The unit is a company-event observation. A campaign affecting several issuers—such as NotPetya—receives a shared cluster identifier, but each issuer keeps its own baseline, returns and recovery outcome. This avoids treating one campaign as one tradable security while preserving the relationship between cases.
The catalog is curated. It does not claim to contain every qualifying event since 2001, and the absence of a company does not imply that no material incident occurred.
02 · Qualification
All six conditions must be met
- US-listed security. At disclosure, the instrument traded on NYSE, Nasdaq or Cboe. ADRs qualify; OTC instruments do not. Later acquisitions or delistings are allowed only when usable price history exists.
- Digital-trust event. Eligible categories include security or privacy breaches, ransomware, destructive or disruptive cyberattacks, supply-chain compromise, data misuse, and material software or digital-service failures. Physical recalls and general quality incidents are excluded.
- Direct issuer relationship. The issuer is the victim, responsible vendor or operator, or affected parent company—not a company mentioned only indirectly.
- Documented first public disclosure. One primary source or two independent credible secondary sources must anchor the moment the information became public.
- At least one materiality signal. A materiality statement, disruption of critical operations, quantified financial or consumer impact, significant regulatory action, or systemic reach.
- 90-day admission delay. Editorial acceptance occurs no earlier than 90 calendar days after the first public disclosure date in America/New_York.
After the admission delay, the inclusion rationale and review date are recorded before price performance is examined. That ordering reduces selection based on an interesting market outcome.
Item 1.05 of Form 8-K is an important source for recent US issuers, but it is not a universal eligibility requirement. The SEC’s material cybersecurity disclosure requirements took effect in late 2023, long after this catalog’s start date. See the SEC adoption release.
03 · Evidence
Sources are attached to claims, not merely listed
Each case bibliography labels a source as primary or secondary and records whether it supports disclosure, timing, listing, impact or description. Listing evidence includes the checked date and a note specific to the event period. SEC issuer and filing data provide a validation point; historical exchange status is confirmed for the disclosure date rather than inferred from the company’s current venue. The SEC explains programmatic and archival filing access in its EDGAR data guide.
New observations require manual qualification and review. The scheduled market-data refresh cannot discover or publish a new event.
Market data and derived metrics are refreshed periodically through reviewed data-only updates. Incident Impact is not a real-time data service; the current data-through date is displayed on this page and throughout the site.
04 · Time convention
The baseline precedes the market’s first opportunity to react
Every record stores an ISO 8601 disclosedAt value with an offset and a disclosurePrecision value of exact or date. Exact timestamps are converted to America/New_York for session selection.
| Disclosure circumstance | Baseline | Reaction close |
|---|---|---|
| Before or during a trading session | Previous session close | Current session close |
| After 4:00 p.m. ET | Current session close | Next session close |
| Weekend or market holiday | Last available close | Next available close |
| Date known, time unknown | Previous session close | First close on or after the date |
CrowdStrike is the reference fixture: its content update was released at 04:09 UTC on July 19, 2024, so the baseline is July 18 and the first reaction close is July 19. See CrowdStrike’s preliminary post-incident review.
05 · Measurement
Adjusted-close total returns versus SPY
Build-time daily adjusted close comes from Yahoo Finance for the issuer and SPY. Adjusted close is used as a total-return series that accounts for splits and reinvested distributions. Raw prices are not published in the site; only normalized series and derived results are included in the static build.
company total return % = (company end / company baseline − 1) × 100SPY total return % = (SPY end / SPY baseline − 1) × 100market-relative return pp = company total return % − SPY total return %The six primary windows are the first reaction session, +7 calendar days, and +1, +3, +6 and +12 calendar months. Except for the reaction close, the endpoint is the final trading session no later than the target calendar date.
We deliberately say market-relative return, not abnormal return. A formal event study estimates expected return rather than simply subtracting a benchmark. For that distinction, see A. Craig MacKinlay’s “Event Studies in Economics and Finance”.
06 · Recovery
A mechanical price threshold, not a causal conclusion
Recovery analysis begins only if the company’s adjusted close falls below baseline between the first reaction session and the end of +7 calendar days. The result is the first later close at or above baseline, observed for at most 24 months.
no-initial-drop: no close below baseline in the initial interval.recovered: a later close reached or exceeded baseline within 24 months.not-recovered-24m: 24 months elapsed without recovery.ongoing: the 24-month observation period has not finished.censored-delisted: price history ended before the outcome could be observed.
A recovery close does not show that the market forgot the incident, that reputational damage ended, or that the incident caused the earlier drop.
07 · Hypothetical $1,000
The clock starts at purchase
The user chooses entry at +1, +3, +5 or +7 calendar days. Purchase occurs at the first close on or after that target. Holding periods of 1, 3, 6 or 12 months are then measured from the actual purchase session, and exit uses the last close no later than the resulting target date.
The comparison invests $1,000 in the company and $1,000 in SPY on identical sessions. Fractional shares are allowed; taxes, fees and slippage are omitted; adjusted close assumes reinvested distributions. There is no combined “incident portfolio.”
08 · Aggregation
Median first, with an explicit n
For every window, the landing reports the median market-relative return, the percentage of complete observations below zero and the sample size n. The mean appears as context on case pages. A pending observation is published but excluded from every aggregate whose window has not matured.
09 · Limitations
What these numbers cannot establish
- No causality. Timing and co-movement do not isolate an incident’s effect from earnings, company news, sector changes or macroeconomic events.
- SPY is one benchmark. It does not control for sector, size, factor exposure or a company-specific expected-return model.
- Daily resolution. Adjusted close cannot describe intraday reactions or separate information arriving during the same session.
- Disclosure uncertainty. Date-only records use a conservative previous-close rule and are visibly marked lower precision.
- Selection is editorial. Materiality signals standardize review, but judgment remains. The catalog is neither exhaustive nor random.
- Survivorship and history. Delisting, ticker changes and limited vendor history may censor outcomes.
- No investment use. Historical illustrations omit real-world execution, tax and liquidity considerations.
Other projects have studied a broader set of data breaches, including Comparitech’s share-price analysis. Incident Impact does not claim uniqueness or completeness; its scope includes several digital-trust categories and emphasizes record-level traceability.
10 · Change history
Method changes are versioned
Established company-event observations; a 90-day admission delay; US-listing scope; disclosure-time session rules; SPY market-relative returns; periodic reviewed refreshes; six windows; 24-month recovery states; and purchase-anchored hypothetical $1,000.
Future changes that alter historical results require a methodology version increment, regenerated snapshot and documented migration note. Ordinary price refreshes retain the methodology version.