This hub covers significant breaches with attention to what the incident actually means for the people whose data was exposed and for the organizations that must now notify them. Reporting is sourced from regulator filings and breach registries rather than secondhand accounts.
Data Breaches
September 1, 2026
Item 1.05 of Form 8-K is an investor-disclosure obligation, not a breach-notification law: it is triggered by a registrant's determination that a cybersecurity incident is material, runs four business days from that determination, and asks about impact rather than incident detail.
Read more →
GLBA
September 1, 2026
Amendments adopted in May 2024 rewrote 17 CFR 248.30 to require broker-dealers, investment companies, registered advisers and transfer agents to maintain an incident response program and to notify affected individuals within 30 days. Both compliance dates have now passed.
Read more →
Breach Notification
August 24, 2026
Every state has a breach notification statute, and no two set the same combination of deadline, regulator and threshold. This guide charts the individual-notice deadline and the regulator notice rule for the 48 states whose statutes are documented against a primary source in the research behind this site.
Read more →