Incident Impact — Share prices after cyber incidents

· Incident Impact

4 min read Original article ↗

Cyber incidents · what happened next

How did companies perform after major cyber incidents?

Incident Impact brings together 30 documented cases with the affected company’s share-price performance, SPY and a fixed-panel view of media attention during the first 14 days. Pick a case and see what happened next.

30

Company–incident pairs

Scope starts
Jan 1, 2001

Cases in this release
2007–2024

Listed on
NYSE · Nasdaq · Cboe

Benchmark
SPY adjusted close

This site shows how share prices moved after an incident became public. It does not prove that the incident caused the move. Company news, sector moves and the wider market can affect every result. Educational only — not investment advice.

Across the catalog

The results are mixed

The large number is the median difference between the company return and SPY. “Below SPY” is the share of cases that trailed the benchmark. These figures start at the pre-disclosure baseline rather than one shared post-incident entry point.

First reaction

+66.7% below SPY · 30 cases

+7 days

+73.3% below SPY · 30 cases

+1 month

+83.3% below SPY · 30 cases

+3 months

+66.7% below SPY · 30 cases

+6 months

+70.0% below SPY · 30 cases

+12 months

+60.0% below SPY · 30 cases

Media context across the catalog

We recovered written articles whose recorded headlines named the selected company during the first 14 days after disclosure. The fixed seven-family panel is an observed lower bound, not a complete count of US coverage.

Qualifying articles725Unique article URLs across 30 observations.
Published by 72 hours45.2%328 recovered articles.
Published by day 773.9%536 recovered articles.
Published in week 226.1%189 articles during days 8–14.

A useful starting point · CRWD

CrowdStrike makes the idea look compelling

Buying three days after disclosure and holding for a year would have turned $1,000 into $1,786, versus $1,148 in SPY.

It is a strong positive example for buying after an incident. It is not representative of the catalog, and the gain may reflect CrowdStrike’s wider business performance rather than a general post-incident rebound. The other 29 cases are why it is worth looking beyond it.

View the CrowdStrike case

Buy after 3 days · hold 12 months $638 More than SPY

Entry
Jul 22, 2024

Exit
Jul 22, 2025

CrowdStrike value
$1,786

SPY value
$1,148

Hypothetical $1,000

What would $1,000 have looked like?

Compare $1,000 in CRWD with $1,000 in SPY, bought and measured on the same dates.

CRWD value $1,432 CrowdStrike

SPY value $1,100 US market benchmark

Difference vs SPY $332 Observed result

Entry Jul 22, 2024 Exit Jan 22, 2025

Uses fractional shares and adjusted close. Leaves out taxes, fees and slippage. The holding period starts on the purchase date. This is a historical illustration, not an investment strategy.

Selected cases

Pick an incident

T Privacy breach

Jul 12, 2024

AT&T

AT&T disclosed that threat actors illegally downloaded call and text interaction records covering nearly all wireless customers for specified periods.

1-month vs SPY +7.2 pp Above SPY

Recovery Recovered

UNH Ransomware

Feb 21, 2024

1-month vs SPY -10.7 pp Below SPY

Recovery Recovered

MSFT Security breach

Jan 19, 2024

Microsoft

Microsoft disclosed that Midnight Blizzard accessed and exfiltrated email from a small percentage of corporate accounts, including senior leadership.

1-month vs SPY -2.0 pp Below SPY

Recovery Recovered

CZR Ransomware

Sep 14, 2023

Caesars Entertainment

Caesars disclosed a social-engineering attack through an outsourced IT support vendor that led to theft of loyalty-program customer data.

1-month vs SPY -16.0 pp Below SPY

Recovery Not recovered within 24 months

MGM Ransomware

Sep 11, 2023

MGM Resorts International

MGM disclosed a cybersecurity issue that forced system shutdowns and disrupted hotel and casino operations across multiple US properties.

1-month vs SPY -11.4 pp Below SPY

Recovery Recovered

CLX Disruptive cyberattack

Aug 14, 2023

The Clorox Company

Clorox disclosed unauthorized activity that forced systems offline and later caused widescale operational, order-processing and product-availability disruption.

1-month vs SPY -7.2 pp Below SPY

Recovery Recovered

One important limit

After is not the same as because.

Earnings, company news and the wider market do not pause for a cyber incident. SPY gives us a consistent comparison, not a causal answer.

  • Each case is qualified before looking at its returns.
  • Adjusted close includes splits and reinvested dividends.
  • The catalog is curated, not complete.
  • The historical comparisons are not investment advice.

Read the method and its limits →