DisclosureLens
FEDERALHackingTelecom & MediaInformationDDoSLowResolved

BANDWIDTH INC.

bd_569e565499a67b4d · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Feb 28, 2024

To disclose

Affected

Not disclosed

Confidence

73%
Full breach record for BANDWIDTH INC.

Bandwidth Inc.'s Form 10-K Item 1C cybersecurity disclosure describes its enterprise information-security program, governance, vendor-risk management, and ISO/IEC 27001 / SOC 2 Type II certifications. The filing references a single specific incident: a DDoS attack experienced in late 2021 that had a material impact on results of operations. No affected-individual count, data types, threat actor, or financial-impact figure is disclosed within this Item 1C narrative.

Incident timeline

Oct 1, 2021

Begins

Feb 28, 2024

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.No incident reportedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.