Vulnerabilities

Material Breach Tracker

July 20, 2026 20:11 · 10 min read
Material Breach Tracker

Introduction to the Hacker in a Hoodie Index

A longtime cybersecurity executive, Richard Bird, has created a website that tracks disclosed material breaches, aiming to give cybersecurity professionals, journalists, policymakers, and everyday citizens a resource that doesn’t currently exist. The tracker, named The Hacker in a Hoodie (HIH) Index, was built in preparation for Bird's upcoming book — Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It.

The Core of the Site

The core of the site is a pair of ledgers that update on a daily or near-daily basis, pulled by pollers and tracers built and run by Bird. The first ledger draws from SEC EDGAR, the agency’s public filing database, tracking the 8-K disclosures that public companies are required to file when they experience a material cyber incident — a requirement that has existed only since 2023. The second ledger is based on news articles and companies’ own statements.

Grading System

The HIH Index grades every entry by how solid its sourcing is: a primary SEC filing counts as ‘verified’, a company’s own statement as ‘attested’, and a news report as ‘inferred’. This grading lets a reader tell at a glance how much weight a given entry can actually carry.

Context and Argument

Separate from both ledgers, the site includes a static reference chart that pulls annual figures from the FBI’s Internet Crime Complaint Center (which shows nearly $20.9 billion in reported losses for 2025) and IBM’s Cost of a Data Breach report (which shows an average of $4.44 million per breach). These reports provide context for the project’s argument, showing that per-incident cost has barely moved in a decade, even as total reported losses have compounded at roughly 35% a year.

“This means only one thing — the hackers aren’t making more money from the same number of victims,” Bird told SecurityWeek. “More companies are failing (way more) at cybersecurity every year and the bad guys are functionally printing money by capitalizing on how poorly cybersecurity is actually being executed at these companies.”

Avoiding the Sum of Losses

Bird’s case against summing the HIH Index data is straightforward: most of the ledger’s entries are marked ‘not yet quantified,’ and the ones that do carry a figure come from different evidence tiers. Treating those as interchangeable and adding them together would produce a number that looks precise but is not backed by anything solid.

Usefulness of the Ledgers

What makes the ledgers useful isn’t the total — it’s the ability to check. A reporter or analyst can look up what a specific company actually disclosed, how the filing was worded, and what evidence grade it carries. In an industry where cyber loss reporting leans heavily on marketing-driven estimates, having a citable, source-graded reference to check claims against fills a gap that has largely gone unfilled.

Maintenance and Future

Bird maintains the entire project alone — no editorial team, no outside data vendor, just the scrapers he built to keep both ledgers current. He is also upfront about the dataset being young: the SEC requirement it’s built on is relatively new, and he draws a direct comparison to Troy Hunt’s Have I Been Pwned data breach notification service, which also started small and grew because there was nowhere else to look.

Bird argues that everything else in a company gets measured in dollars, except cybersecurity, which has been treated as overhead instead of a tracked outcome. He believes that cybersecurity should be measured in dollars from a performance perspective, rather than being treated as a ‘cost of business’.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free