PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
ALPHV/BlackCat said it reported MeridianLink to the U.S. Securities and Exchange Commission (SEC) in November 2023, accusing the company of failing to disclose a breach. That was an extortion tactic and an attacker’s allegation—not an SEC finding. The SEC’s new four-business-day cyber-disclosure requirement was not yet in effect when the group made its claim.
What happened between ALPHV/BlackCat and MeridianLink?
In November 2023, the ALPHV/BlackCat ransomware operation claimed MeridianLink was a victim and posted a screenshot of what it said was a complaint submitted through the SEC’s complaint portal. The group threatened to publish allegedly stolen data unless MeridianLink paid. The claim that data was stolen, and the group’s description of the incident, remain allegations by the attackers; the available reporting does not establish the full scope of any data theft. Contemporary reporting described the complaint and the group’s threat.
MeridianLink confirmed a cybersecurity incident and said it acted to contain the threat and engaged third-party experts to investigate. At the time of its statement, the company reported no evidence of unauthorized access to its production platforms and minimal business interruption. It said it was still determining whether consumer personal information was involved. Ars Technica reported MeridianLink’s statement.
The distinction matters: a complaint submitted by an attacker is not proof that the complaint’s claims are true, nor evidence that the SEC found a company in violation. The sources available for this case do not establish substantive SEC action resulting from the reported complaint.
#1 Best Overall
Does the SEC require companies to report a hack within four days?
Not within four days of the attack or its discovery. Under Item 1.05 of Form 8-K, a public company generally must disclose a cybersecurity incident within four business days after it determines the incident is material to investors. The company must make that materiality determination without unreasonable delay after discovering the incident. The SEC’s July 2023 announcement describes the adopted rules.
Materiality is the trigger. A cyber incident is not automatically reportable under Item 1.05 simply because it occurred; the company assesses its circumstances and potential impact on investors. The SEC’s adoption materials explain that the required disclosure covers material aspects of the incident’s nature, scope and timing, as well as its material or reasonably likely material impact. The final rule sets out those requirements.
What does a company have to disclose?
An Item 1.05 filing must describe the material aspects of the incident’s nature, scope and timing, and its material or reasonably likely material impact. If some information is not available when the company files, it can say so and provide an amendment as required when the information becomes available. The rule does not require disclosure of technical details at a level that would impede the company’s response or remediation. The SEC’s final rule also provides for an Attorney General-authorized delay if immediate disclosure would pose a substantial risk to national security or public safety.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsWas MeridianLink subject to the new rule when ALPHV made its claim?
No. The SEC’s incident-disclosure requirements began on December 18, 2023, or a later applicable date under the rule. ALPHV’s reported complaint surfaced in mid-November, before the new requirement took effect. Its accusation that MeridianLink had missed the new rule’s four-day deadline therefore should not be treated as an established violation. The SEC’s rule announcement gives the effective timing.
Rank #3
Can a company disclose an incident before deciding it is material?
Yes. In a May 2024 staff statement, SEC Division of Corporation Finance Director Erik Gerding clarified that Item 1.05 is for incidents a registrant determines are material. A company can disclose an incident earlier under another Form 8-K item, such as Item 8.01, before making that decision. If it later determines the incident is material, the staff said it should file an Item 1.05 report within four business days of that determination. This was staff guidance explaining the rule, not a new rule. Read the SEC staff statement.
Quick Recap
Best Value
Rank #4
What the four-day rule means in practice
- Discovery is not the four-day starting point. It begins the company’s assessment process; the filing clock starts when the company determines the incident is material.
- The assessment cannot be put off unreasonably. The company must reach its materiality decision without unreasonable delay after discovery.
- The filing is about investor-relevant impact. Item 1.05 calls for material information, not a forensic account of every technical detail.
- An accusation is not a regulatory decision. A ransomware group can submit a complaint, but submission alone does not establish a violation or show that the SEC has taken substantive action.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

