Show HN: Comparing stock returns after cyber incidents

0xad1 pts0 comments

Incident Impact — Share prices after cyber incidents Skip to content<br>Cyber incidents · what happened next<br>How did companies perform after major cyber incidents?<br>Incident Impact brings together 30 documented cases with the affected company’s share-price performance, SPY and a fixed-panel view of media attention during the first 14 days. Pick a case and see what happened next.<br>Explore 30 cases → See how it works

30<br>Company–incident pairs<br>Scope startsJan 1, 2001<br>Cases in this release2007–2024<br>Listed onNYSE · Nasdaq · Cboe<br>BenchmarkSPY adjusted close

This site shows how share prices moved after an incident became public. It does not prove that the incident caused the move. Company news, sector moves and the wider market can affect every result. Educational only — not investment advice.

Across the catalog<br>The results are mixed

The large number is the median difference between the company return and SPY. “Below SPY” is the share of cases that trailed the benchmark. These figures start at the pre-disclosure baseline rather than one shared post-incident entry point.

First reaction -0.8 pp<br>Below SPY<br>+66.7% below SPY · 30 cases

+7 days -2.0 pp<br>Below SPY<br>+73.3% below SPY · 30 cases

+1 month -6.6 pp<br>Below SPY<br>+83.3% below SPY · 30 cases

+3 months -5.1 pp<br>Below SPY<br>+66.7% below SPY · 30 cases

+6 months -5.6 pp<br>Below SPY<br>+70.0% below SPY · 30 cases

+12 months -3.7 pp<br>Below SPY<br>+60.0% below SPY · 30 cases

Media context across the catalog<br>How the 30 incidents were covered

We recovered written articles whose recorded headlines named the selected company during the first 14 days after disclosure. The fixed seven-family panel is an observed lower bound, not a complete count of US coverage.

Qualifying articles725 Unique article URLs across 30 observations.<br>Published by 72 hours45.2% 328 recovered articles.<br>Published by day 773.9% 536 recovered articles.<br>Published in week 226.1% 189 articles during days 8–14.

Publication pace<br>First 48 hours280 38.6%<br>48–72 hours48 6.6%<br>Days 4–7208 28.7%<br>Days 8–14189 26.1%

Local headline framing<br>Descriptive90 12.4%<br>Adverse event400 55.2%<br>Mitigation or action222 30.6%<br>Favorable13 1.8%

Read with care The median case has 10.5 recovered articles ; 2 cases have a registry zero. Archive quality differs by publisher and year, so volume does not rank incident importance or reputational effect.<br>Framing labels describe headline wording—not reader sentiment, publisher stance or the tone of the full article.<br>Explore the casesRead the method

A useful starting point · CRWD<br>CrowdStrike makes the idea look compelling<br>Buying three days after disclosure and holding for a year would have turned $1,000 into $1,786, versus $1,148 in SPY.<br>It is a strong positive example for buying after an incident. It is not representative of the catalog, and the gain may reflect CrowdStrike’s wider business performance rather than a general post-incident rebound. The other 29 cases are why it is worth looking beyond it.<br>View the CrowdStrike case<br>Buy after 3 days · hold 12 months $638 More than SPY EntryJul 22, 2024<br>ExitJul 22, 2025<br>CrowdStrike value$1,786<br>SPY value$1,148

Hypothetical $1,000<br>What would $1,000 have looked like?

Compare $1,000 in CRWD with $1,000 in SPY, bought and measured on the same dates.

Enter after +1 calendar day +3 calendar days +5 calendar days +7 calendar days Hold for 1 month 3 months 6 months 12 months<br>CRWD value $1,432 CrowdStrike<br>SPY value $1,100 US market benchmark<br>Difference vs SPY $332 Observed result

Entry Jul 22, 2024 →<br>Exit Jan 22, 2025<br>Uses fractional shares and adjusted close. Leaves out taxes, fees and slippage. The holding period starts on the purchase date. This is a historical illustration, not an investment strategy.

Selected cases<br>Pick an incident

View all 30 cases

T Privacy breach<br>Jul 12, 2024<br>AT&T<br>AT&T disclosed that threat actors illegally downloaded call and text interaction records covering nearly all wireless customers for specified periods.

1-month vs SPY +7.2 pp Above SPY<br>Recovery Recovered

UNH Ransomware<br>Feb 21, 2024<br>UnitedHealth Group (Change Healthcare)<br>The Change Healthcare ransomware attack disrupted US claims, pharmacy and payment infrastructure on a national scale.

1-month vs SPY -10.7 pp Below SPY<br>Recovery Recovered

MSFT Security breach<br>Jan 19, 2024<br>Microsoft<br>Microsoft disclosed that Midnight Blizzard accessed and exfiltrated email from a small percentage of corporate accounts, including senior leadership.

1-month vs SPY -2.0 pp Below SPY<br>Recovery Recovered

CZR Ransomware<br>Sep 14, 2023<br>Caesars Entertainment<br>Caesars disclosed a social-engineering attack through an outsourced IT support vendor that led to theft of loyalty-program customer data.

1-month vs SPY -16.0 pp Below SPY<br>Recovery Not recovered within 24 months

MGM Ransomware<br>Sep 11, 2023<br>MGM Resorts International<br>MGM disclosed a cybersecurity issue that forced system shutdowns and disrupted hotel and casino operations across multiple US properties.

1-month vs SPY -11.4 pp Below...

below cases days incident after months

Related Articles