Box
ent_019e5cc88d4a2f185544d70450e773bf
Disclosures
2
SEC 10-K Item 1C · State AG · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
81,664
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Box
- Normalized
- box— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- box.com
Disclosure history (2)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-03-09
Box, Inc. (Box) filed its 2023 Form 10-K disclosing its cybersecurity risk management program. The filing describes governance, risk assessment, and incident response procedures aligned with NIST CSF. Box explicitly states it does not believe its business strategy, results of operations, or financial condition have been materially affected by cybersecurity threats, though it provides no assurance regarding future impacts. No specific incident, breach, or material impact is disclosed.
- 🏎️Indiana State AGas victim2025-12-17
Box Elder County reported a data breach to the Indiana Attorney General. The breach occurred on 2025-05-06 and was reported on 2025-12-17. 15 Indiana residents were affected. 81,664 individuals affected in total.