DXC TECHNOLOGY COMPANY
ent_019de1dc109340b35425223bc94f1c2b
Disclosures
4
SEC 10-K Item 1C · Leak Site · HHS OCR · 3 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
1,090
as filed · HHS OCR KY
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- DXC TECHNOLOGY COMPANY
- Normalized
- dxc technology— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DOVZ3EDJB7O259
- SEC EDGAR CIK
- 0001688568
- Domain
- dxc.com
Disclosure history (4)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-05-08
DXC Technology's 10-K Item 1C cybersecurity disclosure describes their NIST CSF-aligned risk management program, ERM integration, Board-level oversight via the Nominating/Corporate Governance Committee, and a Security Steering Committee led by the Global CISO. The filing states no prior cybersecurity incidents have materially affected operations, and does not disclose any specific breach or incident.
- GLOBALLeak Siteas victim2025-02-10
DXC Technology is a leading global IT services company that specializes in helping businesses drive digital transformation. Originally formed as a result of the merger between CSC and the Enterprise Services business of Hewlett Packard Enterprise (HPE) in 2017, DXC provides end-to-end IT services in over 70 countries, catering to various industries and sectors. It offers a broad range of services including analytics, consulting, application development, and security.
- FEDERALSEC 10-K Item 1Cas victim2024-05-17
DXC Technology's 10-K Item 1C describes its cybersecurity risk management program (NIST CSF-aligned), governance structure (Nominating/Corporate Governance Committee oversight, Global CISO reporting), and Security Steering Committee. The filing states no prior cybersecurity incidents have materially affected the company. This is a programmatic disclosure, not an incident disclosure — no specific breach is reported.
- KYHHS OCRas victim2012-12-28
HP Enterprise Services (Business Associate, KY) reported to HHS on 2012-12-28 a Theft affecting 1,090 individuals. An employee of a subcontractor responded to a telephone phishing (vishing) attack and permitted a hacker to remotely access the subcontractor's laptop, which improperly stored PHI including names, dates of birth, diagnosis codes, SSNs, and treatment descriptions. The subcontractor terminated the responsible employee, initiated laptop PHI audits, and retrained staff. OCR obtained assurances that corrective actions were completed. Breached information located on Laptop.
Subsidiary disclosures (3)filed by group companies
◈ These filings were made by or about subsidiaries of DXC TECHNOLOGY COMPANY — not by DXC TECHNOLOGY COMPANY itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🦫Oregon State AGvia Century, LLC2017-03-10
Century, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2017-03-10. The breach occurred during 2/1/2016 - 12/31/2016. The breach was discovered on 2/8/2017. Notice was sent on 2/19/2017.
- 🦬Montana State AGvia Century, LLC2017-02-19
Century, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2017-02-19. The breach occurred from 2/1/2016 to 12/31/2016. 107 Montana residents were affected.
- 🐻California State AGvia COMPUTER SCIENCES CORPORATION2013-04-03
Computer Sciences Corporation (CSC) lost a thumb drive containing Medicare Exclusion Database records, including names, SSNs, EINs, and dates of birth, in Raleigh, NC, in late February 2013. CSC notified the State of North Carolina and offered one year of free credit monitoring and identity protection via Equifax to affected individuals. The incident involved physical loss of a portable device containing government and personal data.