HackMyIP
← Back to News
2026-07-20 SecurityWeek

HIH Index: New Tracker Catalogs Material Breaches Without Adding Up the Losses

Data BreachRegulation

Cybersecurity veteran Richard Bird has launched The Hacker in a Hoodie (HIH) Index, a public website that tracks disclosed material breaches pulled directly from SEC EDGAR 8-K filings and corroborated news reports. Bird, currently Chief Strategy and Chief Security Officer at Singulr AI and a former JPMorgan Chase security leader, built the project independently in preparation for his upcoming book, "Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It." The index maintains two ledgers: one sourcing 8-K disclosures that public companies have been required to file for material cyber incidents since 2023, and a second aggregating company statements and media coverage. Each entry is graded by source quality — SEC filings are marked "verified," company statements "attested," and news reports "inferred" — giving readers a transparent view of evidentiary weight. The index already lists more than 100 incidents, with the latest entries covering breaches at Coca-Cola's Fairlife, Centers Lab, Mount Royal University, and Accenture.

What separates the HIH Index from other trackers is what it deliberately omits. The site publishes no aggregate dollar figure, no running total, and no trend chart summing losses across entries — and that is the point. Bird's static reference page instead draws context from two established sources: the FBI's Internet Crime Complaint Center, which reported nearly $20.9 billion in losses for 2025, and IBM's Cost of a Data Breach report, which pegs the average breach at $4.44 million. Bird argues that per-incident cost has been essentially flat for a decade while total reported losses are compounding at roughly 35% annually, a pattern he attributes to widening failure rates across enterprise security programs rather than escalating attacker sophistication. Readers concerned about their own exposure can cross-reference disclosed incidents using a email breach checker to see whether their credentials appear in known compromises.

Bird's central thesis is blunt: the economics of cybercrime are working in attackers' favor because too many organizations keep getting the basics wrong. Quoting him directly, the hackers "are functionally printing money by capitalizing on how poorly cybersecurity is actually being executed at these companies." He frames the project and his forthcoming book as diagnostic rather than accusatory, arguing that the industry's current posture is rational but built on the wrong priorities. For practitioners mapping incident-response posture or journalists seeking sourced breach data, the index arrives as a notable independent resource in a field long dominated by vendor-sponsored reports. Anyone auditing their own defenses after reviewing disclosed incidents can run a privacy checkup alongside a password checker to identify weak or leaked credentials before attackers do.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →