Breach taxonomy
Summary
Analog Devices identified unauthorized access to certain company systems on June 23, 2026, activated its incident response protocols, engaged external cybersecurity experts, and notified law enforcement. The investigation found that certain files were exfiltrated from the affected systems, though the nature and scope of that data remained under investigation and the company had no knowledge of the data being publicly released or misused. Operations were not interrupted at any point. Filed under Item 8.01; materiality not yet determined as of the filing date, and the company stated it does not believe the incident is reasonably likely to be material. The filing separately notes that on July 26, 2026 the company became aware of public reports of an unrelated cybersecurity matter it was still assessing.
Tagging rationale
ThreatUnknown
Filing refers only to 'unauthorized access to certain Company systems' and names no actor or actor category → UNKNOWN.
MethodsData Exfil
Filing confirms files 'were exfiltrated from the affected systems' with no encryption, ransom, or outage described → DATA-EXFIL; initial access vector is not disclosed.
AssetsConfidential Biz
Filing states 'certain files were exfiltrated from the affected systems' with the nature and scope still under investigation and no specific data type identified → CONFIDENTIAL-BIZ.
EffectsInfo Privacy Loss
Filing states 'The Company's operations were not interrupted throughout the duration of the incident' but that files were exfiltrated and the company 'will provide notifications to affected parties and applicable regulators' → INFO-PRIVACY-LOSS only.
Business continuityNot Required
Filing states operations 'were not interrupted throughout the duration of the incident' — a data-only incident requiring no continuity procedures → Not Required.
Impact
Files were exfiltrated from a large semiconductor manufacturer, but the filing discloses no record count, no operational interruption, no ransom, and no evidence of public release or misuse → score 2.
InsuranceNot disclosed
Filing makes no mention of insurance → null.
Read the original SEC filing excerpt
Item 8.01. Other Events On June 23, 2026, Analog Devices, Inc. (the “Company”) identified unauthorized access to certain Company systems. Following detection of the unauthorized access, the Company immediately activated its incident response protocols and engaged external cybersecurity experts to assist with containment and investigation activities. The Company has also notified and is coordinating with law enforcement authorities. The Company’s operations were not interrupted throughout the duration of the incident. The Company’s investigation has found that certain files were exfiltrated from the affected systems. The Company’s investigation into the nature and scope of the exfiltrated information remains ongoing. To the Company’s knowledge, the data has not been publicly released or used for fraudulent purposes. The Company will continue to monitor for any indication of misuse and will take appropriate action if warranted. The Company will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law. While the Company’s investigation continues, based on information currently known, and the containment and mitigation measures taken, the Company does not believe the June 23, 2026 incident is reasonably likely to materially impact its business, operations, or financial condition. Separately and unrelated, on July 26, 2026, the Company was made aware of public reports regarding a disparate cybersecurity matter and is currently assessing its validity, scope, and any potential impact.