Back to news
Cybersecurity Alert
July 19, 2026 by EmailMeNow IT Consulting

SEC Form 8-K Item 1.05 Cyber Disclosures YTD 2026: 14 Issuers Through July 19

EmailMeNow’s SEC EDGAR tracker finds 14 Item 1.05 cybersecurity issuer families YTD through July 19, 2026 (18 filings / 31 cyber-related 8-Ks). Domain audits of filers: Stryker 76% leads; none reach the 100% ideal; most score 15% transport.

Source: SEC EDGAR — Form 8-K

NewsCybersecurityData BreachSECForm 8-KPublic Companies
SEC Form 8-K Item 1.05 cybersecurity disclosure screen for year-to-date 2026 filings

Through July 19, 2026, our SEC EDGAR tracker shows 14 distinct issuers with Form 8-K Item 1.05 material cybersecurity incident families year-to-date — 18 Item 1.05 filings after collapsing amendments, inside a broader set of 31 cyber-related 8-K records (27 families when Item 8.01 keyword hits are included).

This is not a duplicate of our July 17 weekly 8-K roundup. That post covered a single filing day. This is the 2026 YTD rollup of Form 8-K cybersecurity disclosures with emphasis on Item 1.05 (the SEC’s material cyber-incident item — often shorthand “1.05”).

These are investor disclosures by public companies, not state AG consumer notices or HIPAA OCR counts. Item 1.05 is for incidents the issuer determined material; Item 8.01 may disclose cyber events before or without a materiality determination.

SEC Form 8-K Item 1.05 cybersecurity disclosure screen for year-to-date 2026 filings

YTD Snapshot (Through July 19, 2026)

MetricCount
Cyber-related 8-K records tracked31
Families (amendments collapsed)27
Item 1.05 filings (raw)18
Item 1.05 families / issuers14
Keyword / Item 8.01–only families13
Ideal domain audit score100%
MonthCyber familiesOf which Item 1.05
Jan 202610
Feb 202632
Mar 202652
Apr 202652
May 202643
Jun 202652
Jul 2026 (through 19)43

Item 1.05 volume has been steady rather than spiky — roughly two to three material cyber families most months, with California (4) and Pennsylvania (3) leading by issuer business state in the Item 1.05 set.

Calendar timeline of SEC cybersecurity disclosure markers from January through July

Item 1.05 Issuers YTD

Collapsed by incident family (latest filing in the chain). Open the EDGAR primary document before relying on figures — amendments (8-K/A) can revise narratives.

FiledTickerCompanyStateFormFiling
Feb 3WYTCWytec InternationalTX8-K/AView
Feb 24UFPTUFP TechnologiesMA8-KView
Mar 20TRTTrio-Tech InternationalCA8-KView
Mar 27CCLDCareCloudNJ8-KView
Apr 8BTMBitcoin DepotGA8-KView
Apr 9SYKStrykerMI8-K/AView
May 11CBFVCB Financial ServicesPA8-KView
May 20WSTWest Pharmaceutical ServicesPA8-K/AView
May 22TOIThe Oncology InstituteCA8-KView
Jun 15IRTCiRhythm TechnologiesCA8-KView
Jun 23EGHT8x8CA8-KView
Jul 2AHCOAdaptHealthPA8-KView
Jul 2NAVINavientVA8-KView
Jul 17RVRFRiver Financial CorpAL8-K/AView

Sector mix: healthcare / life sciences (Stryker, West Pharma, Oncology Institute, iRhythm, CareCloud, AdaptHealth), financial services (CB Financial, Navient, River), tech / communications (8x8, Trio-Tech, Wytec), and specialty (Bitcoin Depot, UFP Technologies).

Wytec note: The company’s Item 1.05 chain describes an August 2025 website defacement of wytecintl.com (repeat defacement after restore; site taken down for security review). That is a public-web compromise story — different from ransomware / production-halt narratives, but still a material cyber disclosure on Form 8-K.

Secondary Signal: Item 8.01 / Keyword Hits

We also retain body-verified keyword hits that land on Item 8.01 (or adjacent cyber language). YTD: 13 such families. These can be voluntary / pre-materiality disclosures — and a minority may still sit near M&A exhibits or risk-factor language despite filters. Treat them as a watch list, not as confirmed Item 1.05 counts.

Notable recognizable names on that secondary list include Hasbro (HAS), Honeywell (HON), and Clover Health (CLOV) — the last also appeared in our July 17 weekly roundup.

Independent Domain Audits

We scanned public marketing / investor domains for Item 1.05 issuers (plus three secondary names) on July 19, 2026. 100% is the ideal. Strong scores do not prevent the underlying incident; weak scores raise the odds of spoofed “investor update” / “incident notice” email while attention is high.

RankCompanyDomainOverallIdentityTransportWebsiteLevel
1Strykerstryker.com76%70%15%92%Good
2AdaptHealthadapthealth.com73%65%15%87%Good
3River Financialriver.bank70%90%45%40%Good
4CB Financialcb.bank65%55%45%70%Above Average
5CareCloudcarecloud.com64%75%15%45%Above Average
6UFP Technologiesufpt.com62%70%40%40%Above Average
7Trio-Techtriotech.com62%35%15%92%Above Average
88x88x8.com62%75%15%37%Above Average
9Honeywellhoneywell.com61%70%45%37%Above Average
10Hasbrohasbro.com58%65%15%37%Average
11Wytec (current site)wytecintl.ai56%60%15%37%Average
12Clover Healthcloverhealth.com54%50%15%43%Average
13West Pharmawestpharma.com52%50%15%37%Average
14Oncology Institutetheoncologyinstitute.com52%50%15%37%Average
15Navientnavient.com52%50%15%37%Average
16iRhythmirhythmtech.com50%45%15%37%Average
17Bitcoin Depotbitcoindepot.com48%20%15%65%Below Average
18Wytec (legacy, disclosed)wytecintl.com43%25%15%40%Below Average

Email domain security gauges incomplete versus a 100 percent ideal target

Audit takeaways

FindingDetail
Ideal reached0 of 18 domains at 100% overall
Best overallStryker (stryker.com) — 76% (Good)
Best identityRiver Bank (river.bank) — 90%
Best transport in setRiver / CB Financial / Honeywell / UFP — 40–45% (still well below ideal)
Shared gapMost domains score 15% Transport — missing effective MTA-STS enforce / TLS-RPT signals in this pass
Weakest overallwytecintl.com — 43% (the domain named in Wytec’s defacement disclosure); bitcoindepot.com — 48% with 20% Identity

Audit links: stryker.com · adapthealth.com · river.bank · cb.bank · carecloud.com · 8x8.com · bitcoindepot.com · wytecintl.com

Website stack note

Passive website-tech probes on July 19, 2026 completed for 18 of 18 audited domains. 4 returned notable public CMS freshness signals:

DomainNotable signal
triotech.comWordPress reports 3.7.1 (wordpress.org latest 7.0.2) — far behind current core
wytecintl.aiWordPress reports 3.7.1 (latest 7.0.2) — same extreme lag on Wytec’s current public site
wytecintl.comWordPress reports 3.7.1 (latest 7.0.2) — the legacy host named in Wytec’s Item 1.05 website-defacement disclosure
bitcoindepot.comWordPress reports 6.8.6 (latest 7.0.2) — one major behind current

The remaining 14 domains showed no notable public CMS, PHP, CVE-hint, or short-horizon TLS signals in this pass (examples: Shopify on AdaptHealth; Nuxt on Navient; Next.js on Hasbro; current WordPress 7.0.2 on CareCloud).

For Wytec, an ancient public WordPress fingerprint on both the legacy and current hosts is consistent with a company that already disclosed website defacement — even though these probes do not prove that WordPress version caused the 2025 incident.

These passive observations are point-in-time public signals. They do not prove exploitability, identify a breach path, or establish that a detected major version is unsupported. They also do not replace reading the underlying Form 8-K.

What This Means for Operators

If you are an investor, vendor, or customer of a YTD Item 1.05 filer:

  • Prefer the EDGAR primary document and the company’s IR site over forwarded “incident update” emails.
  • Expect phishing and BEC that impersonate IR, legal, or IT during the disclosure window — especially when Transport scores sit at 15%.

If you are a public-company IR / security team:

  • Treat Item 1.05 readiness as an operational playbook (materiality clock, outside counsel, law-enforcement notice, customer/vendor comms), not only a disclosure template.
  • Close the easy secondary risk: bring public domain identity + transport toward the 100% ideal so spoofed “8-K follow-up” mail is harder to deliver.

Source: SEC EDGAR full-text search — Form 8-K Item 1.05 · Dataset: data/sec-8k-cyber-reports.json (extracted July 19, 2026; window 2026-01-01 → 2026-07-19)

Not legal advice — independent summary of public SEC filings and EmailMeNow domain audits.