Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1989+ Articles
151+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. New Index Tracks Material Breaches — And Refuses to Add Up the Losses
New Index Tracks Material Breaches — And Refuses to Add Up the Losses
NEWS

New Index Tracks Material Breaches — And Refuses to Add Up the Losses

Richard Bird, Chief Strategy and Security Officer at Singulr AI, has built the Hacker in a Hoodie (HIH) Index — an evidence-graded ledger tracking SEC-mandated breach disclosures and public statements. Deliberately, it never sums the losses, because doing so would turn data into myth.

Dylan H.

News Desk

July 20, 2026
4 min read

A Breach Ledger That Tells the Truth

Most breach tracking resources fall into one of two failure modes: they either sum up losses into attention-grabbing headline figures that can't be substantiated, or they bury incidents in dense regulatory filings that only lawyers read. The Hacker in a Hoodie (HIH) Index is a deliberate attempt to avoid both traps.

Built by Richard Bird, Chief Strategy and Security Officer at Singulr AI, the HIH Index tracks material cybersecurity incidents through two independent ledgers — and it will never print a total losses figure.


Two Ledgers, One Standard

The index maintains two distinct data sources:

Ledger 1: SEC EDGAR

Tracks 8-K disclosures filed by public companies reporting material cyber incidents. Since the SEC's 2023 rule requiring timely cyber incident disclosure, this has become the closest thing to a ground truth for corporate breaches — because companies face legal liability for what they file.

Automated pollers check EDGAR on a daily or near-daily basis.

Ledger 2: News and Company Statements

Aggregates incidents from news reports and official company communications — a broader but less authoritative source.


Credibility Grading: Not All Evidence Is Equal

Every entry in the HIH Index carries a credibility grade:

GradeSourceWeight
VerifiedPrimary SEC 8-K filingsHighest
AttestedCompany statementsMedium
InferredNews reportsLowest

Current tracked incidents include breaches at Coca-Cola's Fairlife, Centers Lab, Mount Royal University, and Accenture, among 100+ total entries.


Why the Index Refuses to Sum Losses

This is the design choice that sets the HIH Index apart. Bird explains the reasoning plainly:

"Summing the numbers creates a myth — it is no longer data."

Most entries are marked "not yet quantified." Those that do carry a financial figure draw from different evidence tiers — meaning a Verified SEC disclosure and an Inferred news report might sit side-by-side in the ledger, but combining their figures would mix fundamentally incomparable data sources.

Adding them up produces a headline. It doesn't produce knowledge.


What the Data Actually Shows

The most revealing insight from the HIH Index isn't a single number — it's the pattern. Annual cybercrime losses compound at roughly 35% per year, yet per-incident costs remain stubbornly static at around $4.44 million.

If individual incidents cost about the same year over year, but total losses keep compounding, the conclusion is uncomfortable: organizations aren't being hit by increasingly destructive attacks. They're simply failing to learn. The systemic dysfunction isn't improving.


Context: The Book Behind the Index

The HIH Index supports Bird's forthcoming book: Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It. The index is designed to serve security professionals, journalists, policymakers, and members of the public who want a clear-eyed, evidence-graded view of the breach landscape without the mythology that typically surrounds cybercrime statistics.


Why This Matters

Cybersecurity decision-making is routinely distorted by inflated or unverifiable loss figures. When industry groups announce trillion-dollar annual cybercrime costs derived from surveys and extrapolations, security leaders can't translate those numbers into board-level decisions. The HIH Index takes a different stance: track what's actually disclosed, grade the evidence honestly, and refuse to manufacture precision where none exists.

For practitioners who need to brief executives or regulators, an evidence-graded, auditable breach ledger is more useful than any headline figure.


Related Reading

  • CrowdStrike 2026 Global Threat Report: AI Adversaries
  • Cloudflare 2026 Threat Report: 230 Billion Daily Threats
  • WEF Global Cybersecurity Outlook 2026
#Data Breach#SEC Disclosure#Threat Intelligence#Cybersecurity Industry

Related Articles

Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours

A single threat actor leveraged AI workflows, chained cloud misconfigurations, and stolen credentials to breach a large Amazon Web Services customer...

4 min read

Why Patch Directives Only Go So Far

Six weeks of undetected access through a compromised VPN appliance exposes a hard truth: patching is necessary but not sufficient. Organisations already...

6 min read

Scope of Salesforce Attacks Expands as Icarus Leaks Stolen Data

More victims have surfaced after attackers breached application vendor Klue and abused its OAuth tokens to access customers' Salesforce environments. The...

4 min read
Back to all News