FEDERALItem 1.05 · mandatoryMalwareTechnologyInformationTest & MeasurementRansomwareVulnerability ExploitSupply Chain (Dependency)OpportunisticData EncryptedMediumResolved
Data I/O Corporation
bd_803553648eb7fe25 · schema v1 · pii pii-v1
Full breach record for Data I/O Corporation →Data I/O Corporation, a Redmond, WA-based technology company, disclosed in a supplemental Form 8-K that an August 16, 2025 ransomware incident on internal IT systems originated from a vulnerability in a commercially available third-party firewall service. The incident was not targeted, temporarily impacted communications, shipping, receiving, and manufacturing, and has been fully contained and remediated. Estimated Q3 2025 remediation, restoration, and investigation costs total approximately $388,000.
SEC clockMateriality determined Aug 21, 2025 → Filed Sep 10, 202520d ✗ SEC 4-day late25 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/351998/000165495425010613/daio_8k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 10, 2025
- Raw hash
- 34f454688fa1d5793cce4a0c4b0ee37e4fd4ef7c6da30661e8ce519cc249fa9a
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Data I/O Corporationnorm: data i o
- SEC CIK
- 0000351998
- Domain
- dataio.com
Victim entity
- Name
- Data I/O Corporationnorm: data i o
- SEC CIK
- 0000351998
- Domain
- dataio.com
- Industry
- TechnologyllmNAICS 334515 · Instrument Manufacturing for Measuring and Testing Electricity and Electrical Signals
Incident
- Discovered
- Aug 16, 2025
- Materiality determined
- Aug 21, 2025
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- —
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed Form 8-K with the SEC under Item 1.05 Material Cybersecurity Incidents
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- SEC 4-day late · 20d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Aug 21, 2025→ Filed: Sep 10, 202520d cal. 4 business days SEC 4-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.