DisclosureLens
FEDERALMalwareTechnologyManufacturingInformationRansomwareVulnerability ExploitTargetedSupply Chain (3P Vendor)Data EncryptedMediumResolved

Data I/O Corporation

bd_c9378aea9247a943 · schema v1 · pii pii-v1

Severity

Medium

Financial impact

$388K

Discovered

Aug 16, 2025

Filed

Apr 16, 2026

To disclose

35 weeks

Affected

Not disclosed

Confidence

84%
Full breach record for Data I/O Corporation3 incidents on file

On August 16, 2025, Data I/O Corporation was hit by a targeted ransomware incident that originated through a vulnerability in a third-party firewall service provider. The Company shut down most global operating systems to contain the incident, engaged cybersecurity experts, and by September 2025 had fully contained and remediated the incident, incurring approximately $388,000 in one-time costs. The incident was disclosed via Form 8-K on August 21, 2025.

Incident timeline

discovery → filing · 35 weeks / 243 days

Aug 16, 2025

Begins

Aug 16, 2025

Discovered

Aug 21, 2025

Scope determined

Apr 16, 2026

Filed

vs. sector median

+16 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.No incident reportedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.