New ledger tracks SEC cyberbreaches; won’t total losses
Richard Bird launched the Hacker in a Hoodie Index to catalog material cyberbreaches from SEC 8‑K filings and other reports; the site grades sources and does not sum reported losses.
Richard Bird has launched the Hacker in a Hoodie Index, an online ledger that records disclosed material cyberbreaches drawn from SEC 8‑K filings, company statements and news reports. The index is searchable, assigns a credibility grade to each entry and does not aggregate reported dollar losses.
The site maintains two primary ledgers. One pulls 8‑K disclosures from the SEC’s EDGAR database, the public filings companies file after material cyber incidents. The second ledger collects company statements and news accounts. Entries are labeled “verified” for SEC filings, “attested” for company statements and “inferred” for news reports to indicate source type.
Bird built automated pollers and tracers that fetch raw filing text and reports and updates the ledger on a near‑daily basis. At launch the index listed more than 100 incidents, including recent breaches tied to Fairlife, Centers Lab, Mount Royal University and Accenture. Many entries are marked “not yet quantified,” and reported dollar figures appear across different evidence tiers.
Bird said he declined to sum reported losses because combining figures from mixed evidence tiers would create a misleading total. He argued that adding verified SEC figures to inferred news estimates would give a false sense of precision and criticized broad industry totals that reach into the trillions.
The site provides a static reference chart that cites annual industry measures: the FBI’s Internet Crime Complaint Center, which records nearly $20.9 billion in reported losses for 2025, and IBM’s Cost of a Data Breach, which lists an average breach cost of $4.44 million. The ledger allows users to inspect the exact language of filings and statements alongside the evidence grade for each entry.
Bird developed the project independently while serving as chief strategy and chief security officer at Singulr AI and describes the work as separate from his corporate role. He is writing a book titled Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It. Bird maintains the index himself and operates the scrapers without an editorial team.








