Skip to main content

folkfox

Skip to main content
Skip to content
Compliance & Certification

The 8-K That Said, Officially, Not Material Yet

A Fortune-10 healthcare giant discovered a breach on Monday, watched a crime group claim 284 million patient records by Friday, and filed the disclosure that says, in regulatory language, that nothing has officially happened yet. Both things can be true, and that gap is this week's most instructive document.

Quick answerA materiality assessment decides whether a cyber incident must be disclosed under Item 1.05 of Form 8-K within four business days. McKesson's filing shows the strategy: disclose early under the voluntary Item 7.01, while the assessment stays officially open.
Section 01

The materiality assessment behind the item number#

The company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company.
McKesson Corporation, Form 8-K, Item 7.01, filed 28 August 2026

Sit with the placement before the wording. McKesson's Form 8-K of 28 August discloses a cybersecurity incident discovered on 25 August. It is filed under Item 7.01, Regulation FD Disclosure, the voluntary channel, and signed by the company's chief legal officer. It is pointedly not filed under Item 1.05, the line the SEC created specifically for material cybersecurity incidents. In securities practice, the item number is the message.

The rule behind that choice is worth knowing cold. Since the SEC's 2023 cybersecurity disclosure rules took effect in December 2023, a public company must file under Item 1.05 within four business days of determining an incident is material. The clock starts at the determination, not the discovery. So the materiality assessment itself becomes the strategic terrain: while the materiality assessment remains open, the four-day fuse remains unlit.

This is not a loophole someone found. It is the architecture the regulator built, then explicitly signposted. In May 2024 the SEC's Director of Corporation Finance, Erik Gerding, encouraged companies to disclose incidents not yet determined material under a different item, noting that Item 1.05 is not a voluntary disclosure and is by definition material. McKesson's filing walks that guidance almost line by line. A patient prowl through the paperwork, not a bolt for the hedgerow.

Section 02

Meanwhile, outside the filing: a 284 million claim#

The regulatory calm sits beside an extraordinary noise. As BleepingComputer reported on 28 August, the ShinyHunters extortion group claims it voice-phished McKesson employees through a spoofed help-desk domain, moved through single sign-on into Salesforce and Snowflake environments, and exfiltrated roughly a terabyte of data between 21 and 25 August.

The group claims around 284 million patient records and has demanded $55,236,150 with a 72-hour deadline. McKesson, for its part, is publishing updates at its own incident page and, notably, is not proactively disconnecting systems, a posture that itself feeds the open materiality assessment: an operationally intact company has a weaker case for material impact than one rebuilding its network.

Treat the number the way a fox treats a too-easy trail. The 284 million figure is the attacker's count of record lines, not a verified count of people, and this same group's recent claims have shrunk dramatically under scrutiny. The practitioner corner of the internet made that point within hours.

u/lead_oxide2
ShinyHunters Claims to have Voice-Phished 2 McKesson Employees and Extracted 284 Million Patient Records Including: Predictive health data, Identity, and Healthcare Identifiers. McKesson Confirms Breach but not severity.
r/cybersecurity, 29 August 2026View on Reddit

That last clause, confirms breach but not severity, is the whole story in eight words, and it is why the scale claim needs context rather than amplification. In the same group's Carhartt dump this week, analysis discussed on r/InfoSecNews found the apparent 24.9 million victims nearly halved once synthetic test records were stripped out. A dataset can be enormous without every row being a person.

The claim, against the confirmed giants
McKesson (claimed)
284m claimed
Change Healthcare
192.7m confirmed
Anthem 2015
78.8m confirmed
ShinyHunters' 284 million figure is an unverified claim of record lines; Change Healthcare's 192.7 million is HHS OCR's confirmed count, and Anthem's 78.8 million is the long-standing record per HIPAA Journal's breach statistics.

If the claim held at face value it would be the largest healthcare breach ever recorded. That conditional is doing heavy lifting, and honest security marketing keeps it visible.

Section 03

How companies actually route cybersecurity disclosure#

Zoom out from one filing and the pattern is stark. Two years into the regime, the market has quietly voted on where cyber incidents get disclosed, and it did not vote for the headline item.

Debevoise's Form 8-K tracker, updated at the rule's two-year mark, counts 29 issuers filing under Item 1.05 against 50 disclosing incidents under Item 8.01, the general channel that works like Item 7.01 in practice. Only five issuers appear under both, each starting in the voluntary lane and upgrading after a materiality determination. Most voluntary-lane incidents never migrate at all.

Where cyber 8-Ks actually land
Bar chart of SEC cyber disclosure routing since December 2023: 50 issuers used Item 8.01, 29 used Item 1.05, 5 filed under bothItem 8.01: 50Item 1.05: 29Both: 5604020050Item 8.0129Item 1.055Both
Issuers have chosen the voluntary disclosure lanes far more often than the mandatory Item 1.05 since December 2023: 50 under Item 8.01 against 29 under Item 1.05, with only 5 upgrading between them, per Debevoise's tracker as of May 2026.

So McKesson is not an outlier gaming the system. It is the system, working as signposted, at the sharpest scale yet. The mandatory lane was built for certainty, the voluntary lane absorbs the fog, and the fog is where most incidents live for their first weeks. Anyone selling into security and compliance teams should internalise that: the sec cybersecurity disclosure regime runs on judgement calls, and judgement calls are exactly what boards buy help with. Every 8-k cybersecurity disclosure is, underneath the form number, a public artefact of one company's materiality assessment at a moment of maximum fog.

Debevoise's trackers also note the quieter pattern in what happens next: most incidents disclosed in the voluntary lane never migrate to Item 1.05 at all. The materiality assessment, in other words, usually ends in a shrug the market accepts. The exceptions, the five two-lane filers, are the cases where new facts forced the upgrade, and they are studied precisely because they are rare.

Section 04

Four days in August: the timeline that boards will study#

Lay the week out flat and the compression is the lesson. This is the tempo a modern incident disclosure process has to survive, with the extortionists running their own communications strategy against yours.

Note what the vishing route implies for every large organisation's brush-and-undergrowth defences. The claimed entry was not an exotic exploit but a spoofed help-desk domain and two phone calls, straight through the human layer into single sign-on. The same social-engineering wave has been washing over enterprise Salesforce and Snowflake estates all year, and this morning's companion piece on automated penetration testing showed the machine side of the same arms race.

For McKesson the materiality assessment now runs on real questions with real deadlines shadowing them. What was actually taken, of what sensitivity, affecting how many verifiable people, with what plausible effect on operations, litigation and revenue. If the answer tips material, the four-day fuse lights and an Item 1.05 filing follows, joining the five two-lane filers in Debevoise's count. If it never tips, the 7.01 filing stands as the entire federal securities record of a claimed 284 million-record event. Either outcome will be taught.

Section 05

What security vendors should say while this unfolds#

A live mega-incident makes marketing teams itch, and most of the scratching does damage. The den-wisdom here is that restraint reads as competence. Five moves work; the sixth, ambulance-chasing with the attacker's unverified number in a subject line, marks you as prey to every sophisticated buyer.

First, sell the materiality assessment itself. Boards do not experience breaches as malware; they experience them as disclosure decisions under time pressure. GRC advisers, vCISO services and incident-response retainers that rehearse the materiality assessment workflow are selling exactly what this week made vivid. Second, teach the two-lane system in your content: the 50-versus-29 routing data is more persuasive than any fear appeal, and it is verifiable. Third, make the vishing kill-chain concrete for identity and help-desk security offers: spoofed support domain, phone call, SSO, SaaS estate.

Fourth, healthcare-specific vendors should anchor to the confirmed record, Change Healthcare's 192.7 million, not the claimed one; a healthcare marketing programme built on verified numbers survives the correction cycle that always follows these claims, a lesson the CareCloud notification saga taught in miniature. Fifth, remember compliance is a sales asset when it is specific: the same buyers reading this 8-K are the ones who reward a no-exceptions SOC 2 with shorter procurement cycles.

A watercolour fox pausing over an open ledger with one unticked box, the materiality assessment holding a 284 million record claim at bay
One unticked box, holding back a four-day clock.

The sharp scent of a shifting standard is unmistakable here. The 2023 rules were sold as transparency; the routing data shows they produced a disclosure market with a fast lane almost nobody volunteers for. Watch this one filing over the next fortnight, because if 284 million of anything proves real, the migration from Item 7.01 to Item 1.05 will be the cleanest public lesson yet in how a materiality assessment actually ends. Incident disclosure is becoming a discipline with its own craft, its own case law and its own buying audience, and the vendors who teach it honestly will own the category. If your firm sells the calm inside that storm, our cybersecurity marketing practice and content marketing services build the evidence-led kind, with SEO and GEO that makes the checkable version the one the machines quote.

Questions

Frequently asked questions#

What are the sec cybersecurity disclosure requirements?

Since December 2023, US public companies must disclose a cybersecurity incident under Item 1.05 of Form 8-K within four business days of determining it is material, and describe cyber risk management annually in their 10-K. Incidents not yet determined material can be disclosed voluntarily under other items.

What is Item 1.05 of Form 8-K?

It is the form line the SEC created specifically for material cybersecurity incidents. Filing under it is mandatory once materiality is determined, and by definition it tells the market the company itself judges the incident material.

When is an 8-k cybersecurity disclosure required?

A mandatory Item 1.05 filing is required within four business days of a company determining a cybersecurity incident is material. Before that determination, companies may make a voluntary 8-k cybersecurity disclosure under Item 8.01 or 7.01, which is the route McKesson took.

Why did McKesson file under Item 7.01 instead of Item 1.05?

Because its materiality assessment is still open. The filing states the company has not determined the incident is material, and SEC staff guidance encourages early voluntary disclosure under another item in exactly that situation.

What is a materiality assessment for a cyber incident?

It is the documented process of judging whether an incident would matter to a reasonable investor: what was taken, how many people are affected, and the plausible effect on operations, finances and litigation. Its conclusion, not the breach itself, starts the mandatory disclosure clock.

How fast must a company disclose a material cybersecurity incident?

Within four business days of the materiality determination. The clock starts at the determination rather than discovery, but regulators warn that an unreasonably delayed determination is itself a violation.

Is the 284 million records claim about McKesson verified?

No. It is ShinyHunters' own count of record lines, not a confirmed count of individuals, and the same group's Carhartt claim shrank by nearly half under analysis. The largest confirmed healthcare breach remains Change Healthcare at 192.7 million individuals.

Keep reading

Read more on this topic#

Selling calm in the storm?

folkfox builds cybersecurity and compliance marketing on verified numbers and regulatory literacy: content that boards can forward to counsel without wincing.