Through July 19, 2026, our SEC EDGAR tracker shows 14 distinct issuers with Form 8-K Item 1.05 material cybersecurity incident families year-to-date — 18 Item 1.05 filings after collapsing amendments, inside a broader set of 31 cyber-related 8-K records (27 families when Item 8.01 keyword hits are included).
This is not a duplicate of our July 17 weekly 8-K roundup. That post covered a single filing day. This is the 2026 YTD rollup of Form 8-K cybersecurity disclosures with emphasis on Item 1.05 (the SEC’s material cyber-incident item — often shorthand “1.05”).
These are investor disclosures by public companies, not state AG consumer notices or HIPAA OCR counts. Item 1.05 is for incidents the issuer determined material; Item 8.01 may disclose cyber events before or without a materiality determination.

YTD Snapshot (Through July 19, 2026)
| Metric | Count |
|---|---|
| Cyber-related 8-K records tracked | 31 |
| Families (amendments collapsed) | 27 |
| Item 1.05 filings (raw) | 18 |
| Item 1.05 families / issuers | 14 |
| Keyword / Item 8.01–only families | 13 |
| Ideal domain audit score | 100% |
| Month | Cyber families | Of which Item 1.05 |
|---|---|---|
| Jan 2026 | 1 | 0 |
| Feb 2026 | 3 | 2 |
| Mar 2026 | 5 | 2 |
| Apr 2026 | 5 | 2 |
| May 2026 | 4 | 3 |
| Jun 2026 | 5 | 2 |
| Jul 2026 (through 19) | 4 | 3 |
Item 1.05 volume has been steady rather than spiky — roughly two to three material cyber families most months, with California (4) and Pennsylvania (3) leading by issuer business state in the Item 1.05 set.

Item 1.05 Issuers YTD
Collapsed by incident family (latest filing in the chain). Open the EDGAR primary document before relying on figures — amendments (8-K/A) can revise narratives.
| Filed | Ticker | Company | State | Form | Filing |
|---|---|---|---|---|---|
| Feb 3 | WYTC | Wytec International | TX | 8-K/A | View |
| Feb 24 | UFPT | UFP Technologies | MA | 8-K | View |
| Mar 20 | TRT | Trio-Tech International | CA | 8-K | View |
| Mar 27 | CCLD | CareCloud | NJ | 8-K | View |
| Apr 8 | BTM | Bitcoin Depot | GA | 8-K | View |
| Apr 9 | SYK | Stryker | MI | 8-K/A | View |
| May 11 | CBFV | CB Financial Services | PA | 8-K | View |
| May 20 | WST | West Pharmaceutical Services | PA | 8-K/A | View |
| May 22 | TOI | The Oncology Institute | CA | 8-K | View |
| Jun 15 | IRTC | iRhythm Technologies | CA | 8-K | View |
| Jun 23 | EGHT | 8x8 | CA | 8-K | View |
| Jul 2 | AHCO | AdaptHealth | PA | 8-K | View |
| Jul 2 | NAVI | Navient | VA | 8-K | View |
| Jul 17 | RVRF | River Financial Corp | AL | 8-K/A | View |
Sector mix: healthcare / life sciences (Stryker, West Pharma, Oncology Institute, iRhythm, CareCloud, AdaptHealth), financial services (CB Financial, Navient, River), tech / communications (8x8, Trio-Tech, Wytec), and specialty (Bitcoin Depot, UFP Technologies).
Wytec note: The company’s Item 1.05 chain describes an August 2025 website defacement of wytecintl.com (repeat defacement after restore; site taken down for security review). That is a public-web compromise story — different from ransomware / production-halt narratives, but still a material cyber disclosure on Form 8-K.
Secondary Signal: Item 8.01 / Keyword Hits
We also retain body-verified keyword hits that land on Item 8.01 (or adjacent cyber language). YTD: 13 such families. These can be voluntary / pre-materiality disclosures — and a minority may still sit near M&A exhibits or risk-factor language despite filters. Treat them as a watch list, not as confirmed Item 1.05 counts.
Notable recognizable names on that secondary list include Hasbro (HAS), Honeywell (HON), and Clover Health (CLOV) — the last also appeared in our July 17 weekly roundup.
Independent Domain Audits
We scanned public marketing / investor domains for Item 1.05 issuers (plus three secondary names) on July 19, 2026. 100% is the ideal. Strong scores do not prevent the underlying incident; weak scores raise the odds of spoofed “investor update” / “incident notice” email while attention is high.
| Rank | Company | Domain | Overall | Identity | Transport | Website | Level |
|---|---|---|---|---|---|---|---|
| 1 | Stryker | stryker.com | 76% | 70% | 15% | 92% | Good |
| 2 | AdaptHealth | adapthealth.com | 73% | 65% | 15% | 87% | Good |
| 3 | River Financial | river.bank | 70% | 90% | 45% | 40% | Good |
| 4 | CB Financial | cb.bank | 65% | 55% | 45% | 70% | Above Average |
| 5 | CareCloud | carecloud.com | 64% | 75% | 15% | 45% | Above Average |
| 6 | UFP Technologies | ufpt.com | 62% | 70% | 40% | 40% | Above Average |
| 7 | Trio-Tech | triotech.com | 62% | 35% | 15% | 92% | Above Average |
| 8 | 8x8 | 8x8.com | 62% | 75% | 15% | 37% | Above Average |
| 9 | Honeywell | honeywell.com | 61% | 70% | 45% | 37% | Above Average |
| 10 | Hasbro | hasbro.com | 58% | 65% | 15% | 37% | Average |
| 11 | Wytec (current site) | wytecintl.ai | 56% | 60% | 15% | 37% | Average |
| 12 | Clover Health | cloverhealth.com | 54% | 50% | 15% | 43% | Average |
| 13 | West Pharma | westpharma.com | 52% | 50% | 15% | 37% | Average |
| 14 | Oncology Institute | theoncologyinstitute.com | 52% | 50% | 15% | 37% | Average |
| 15 | Navient | navient.com | 52% | 50% | 15% | 37% | Average |
| 16 | iRhythm | irhythmtech.com | 50% | 45% | 15% | 37% | Average |
| 17 | Bitcoin Depot | bitcoindepot.com | 48% | 20% | 15% | 65% | Below Average |
| 18 | Wytec (legacy, disclosed) | wytecintl.com | 43% | 25% | 15% | 40% | Below Average |

Audit takeaways
| Finding | Detail |
|---|---|
| Ideal reached | 0 of 18 domains at 100% overall |
| Best overall | Stryker (stryker.com) — 76% (Good) |
| Best identity | River Bank (river.bank) — 90% |
| Best transport in set | River / CB Financial / Honeywell / UFP — 40–45% (still well below ideal) |
| Shared gap | Most domains score 15% Transport — missing effective MTA-STS enforce / TLS-RPT signals in this pass |
| Weakest overall | wytecintl.com — 43% (the domain named in Wytec’s defacement disclosure); bitcoindepot.com — 48% with 20% Identity |
Audit links: stryker.com · adapthealth.com · river.bank · cb.bank · carecloud.com · 8x8.com · bitcoindepot.com · wytecintl.com
Website stack note
Passive website-tech probes on July 19, 2026 completed for 18 of 18 audited domains. 4 returned notable public CMS freshness signals:
| Domain | Notable signal |
|---|---|
triotech.com | WordPress reports 3.7.1 (wordpress.org latest 7.0.2) — far behind current core |
wytecintl.ai | WordPress reports 3.7.1 (latest 7.0.2) — same extreme lag on Wytec’s current public site |
wytecintl.com | WordPress reports 3.7.1 (latest 7.0.2) — the legacy host named in Wytec’s Item 1.05 website-defacement disclosure |
bitcoindepot.com | WordPress reports 6.8.6 (latest 7.0.2) — one major behind current |
The remaining 14 domains showed no notable public CMS, PHP, CVE-hint, or short-horizon TLS signals in this pass (examples: Shopify on AdaptHealth; Nuxt on Navient; Next.js on Hasbro; current WordPress 7.0.2 on CareCloud).
For Wytec, an ancient public WordPress fingerprint on both the legacy and current hosts is consistent with a company that already disclosed website defacement — even though these probes do not prove that WordPress version caused the 2025 incident.
These passive observations are point-in-time public signals. They do not prove exploitability, identify a breach path, or establish that a detected major version is unsupported. They also do not replace reading the underlying Form 8-K.
What This Means for Operators
If you are an investor, vendor, or customer of a YTD Item 1.05 filer:
- Prefer the EDGAR primary document and the company’s IR site over forwarded “incident update” emails.
- Expect phishing and BEC that impersonate IR, legal, or IT during the disclosure window — especially when Transport scores sit at 15%.
If you are a public-company IR / security team:
- Treat Item 1.05 readiness as an operational playbook (materiality clock, outside counsel, law-enforcement notice, customer/vendor comms), not only a disclosure template.
- Close the easy secondary risk: bring public domain identity + transport toward the 100% ideal so spoofed “8-K follow-up” mail is harder to deliver.
Related Trackers
- SEC 8-K cyber week — July 17, 2026
- All state AG trackers
- Have I Been Pwned 2026 tracker
- Breach monitoring guide
- Ransomware threat landscape
Source: SEC EDGAR full-text search — Form 8-K Item 1.05 · Dataset: data/sec-8k-cyber-reports.json (extracted July 19, 2026; window 2026-01-01 → 2026-07-19)
Not legal advice — independent summary of public SEC filings and EmailMeNow domain audits.