FEDERALItem 8.01 · voluntaryHackingData ExfiltratedCustomer Data InvolvedPIIOTHERLowContained
Surmodics, Inc.
bd_487fbb8692a3fd5a · schema v1 · pii pii-v1
Full breach record for Surmodics, Inc. →Surmodics, Inc. (SRDX) filed an 8-K on July 2, 2025, disclosing a cybersecurity incident discovered on June 5, 2025. A third-party threat actor gained unauthorized access to certain IT systems, causing temporary unavailability. The company took systems offline, engaged third-party experts, and notified law enforcement. Critical systems were restored, and operations continued via alternatives. The company states the threat actor has not released data to its knowledge, though it continues to analyze the scope of accessed data.
SEC clockMateriality determined Jun 5, 2025 → Filed Jul 2, 202527d ✗ SEC 4-day late27 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/924717/000095017025092526/srdx-20250605.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 2, 2025
- Raw hash
- d1cf48949160c24d6333df7e33d21790e17d2c5b72175d05f784bc3bc4a9cc19
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Surmodics, Inc.norm: surmodics
- SEC CIK
- 0000924717
Victim entity
- Name
- Surmodics, Inc.norm: surmodics
Incident
- Discovered
- Jun 5, 2025
- Materiality determined
- Jun 5, 2025
- Notification sent
- Jul 2, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIOTHER
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- SEC 4-day late · 27d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 5, 2025→ Filed: Jul 2, 202527d cal. 4 business days SEC 4-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.