Severity Daily

IT and AI security incidents, checked against the primary source

Tag: cyber insurance

  • United Natural Foods books its cyberattack as a $21 million credit — insurance recoveries beat costs, and the two-year total is $5 million

    United Natural Foods books its cyberattack as a $21 million credit — insurance recoveries beat costs, and the two-year total is $5 million

    The June 2025 attack that halted a $31 billion food distributor now shows up in its annual results as a negative adjustment, because $45 million of insurance arrived in a later fiscal year than the costs it covers.

    What happened

    United Natural Foods, Inc. filed a Form 8-K under Items 2.02, 8.01, and 9.01 on Tuesday, September 8, 2026, accession number 0001020859-26-000022, accepted by EDGAR at 7:02:12 a.m. ET. The Item 8.01 is a $200 million share repurchase authorization and has nothing to do with security. The security content is in the Item 2.02 exhibit: the fourth-quarter and full-year earnings release for the fiscal year ended August 1, 2026.

    UNFI is the largest publicly traded grocery wholesaler in North America and reported full-year net sales of $31,152 million. It disclosed a cybersecurity incident in June 2025, in the fourth quarter of its fiscal 2025, that disrupted ordering and distribution across its network. Today’s release carries the first full fiscal year of that incident’s accounting tail, and the shape of it is worth reading closely.

    In the reconciliation from net income to Adjusted EBITDA, the line is labeled “Cybersecurity incident.” For fiscal 2025 it carried $26 million, all of it in the fourth quarter. For fiscal 2026 it carries $(3) million in the fourth quarter and $(21) million for the full year, shown in parentheses. The sign is not a typo. Footnote 5 explains it, and the wording is the story:

    “Fiscal 2026 includes $45 million of insurance recoveries, which are included within Operating expenses in the Consolidated Statements of Operations, partially offset by $24 million of costs and charges related to the June 2025 cybersecurity incident, of which $20 million is included within Gross profit and $4 million is included within Operating expenses in the Consolidated Statements of Operations. Fiscal 2025 includes costs and charges related to the cybersecurity incident, of which $15 million is included within Gross profit and $11 million is included within Operating expenses in the Consolidated Statements of Operations.”

    So: $26 million added back in fiscal 2025, $21 million subtracted out in fiscal 2026. Across the two fiscal years the “Cybersecurity incident” line nets to roughly $5 million. Full-year Adjusted EBITDA was $701 million in fiscal 2026 against $552 million in fiscal 2025, and GAAP net income was $84 million.

    On sales, the release says only this: “Sales in the fourth quarter of fiscal 2025 were impacted by the previously disclosed cybersecurity incident experienced in the fourth quarter of fiscal 2025,” and elsewhere refers to “lapping last year’s cybersecurity event.” No dollar figure is attached to that impact anywhere in the document. Fourth-quarter fiscal 2026 net sales were $7,642 million, down 0.7 percent against the quarter the incident depressed. The release states no cumulative cost of the incident, and the fiscal 2027 outlook does not mention it.

    Why it matters

    Severity Daily reported yesterday on Ardent Health’s ransomware carve-out, where a 2023 incident’s financial consequence surfaced thirty-four months later inside a non-GAAP definition. UNFI is the same mechanism running faster, and it exposes the part that a single-year read gets wrong: the sign.

    Anyone who pulls UNFI’s fiscal 2026 results and looks for the cyber line finds a negative number. Read alone, that number says the incident helped. Anyone who pulled fiscal 2025 found $26 million of pure cost. Neither year is the answer, and neither year is wrong — they are two halves of one event separated by an accounting boundary, because insurance claims settle on a slower clock than the costs they reimburse. A screen, a model, or a peer comparison that samples one fiscal year of a multi-year incident will get a number whose sign depends entirely on which year it sampled. That is not a UNFI problem. It is the structural shape of every cyber incident large enough to trigger a material insurance claim.

    The second thing to hold onto is what the line is and is not. It is incremental costs and charges, net of insurance recoveries. It is not the cost of the incident. Three categories sit outside it and are visible nowhere in this document. Lost sales, which the company says occurred and does not quantify. Security spending that became ordinary course after the incident and therefore stopped being an adjustment. And customer and contract effects that show up, if at all, in the top line rather than in an add-back. The fourth-quarter number makes the point: net sales fell 0.7 percent against a quarter the company itself describes as depressed by the attack. That is a comparison flattered by a weak base and still down, and no line in the reconciliation captures whatever explains it.

    Third, the disclosure is complete on its own terms and thin on the one number a reader most wants. UNFI names the incident, names its month, splits the costs between gross profit and operating expenses, and states the insurance figure. That is more granularity than most registrants give. It still does not say what the incident cost in total, and because the two fiscal years point in opposite directions, the cumulative figure is the only one that means anything — and the reader has to build it themselves from two documents filed a year apart. There is no rule requiring a cumulative disclosure, which is precisely why the absence is worth naming.

    Finally, the insurance number deserves its own attention: $45 million recovered against $24 million of same-year costs and $26 million the year before. Recoveries of that size, arriving roughly a year after the event, are the strongest public evidence to date on what a large cyber policy actually pays and when. It is one data point, and the policy terms, retention, and sublimits are not public. But it is a real number attached to a named incident at a named company, which is rarer in this field than it should be, and it is a better input to a cyber-insurance conversation than any vendor survey.

    What to do

    If you model or benchmark cyber incident costs, take the cumulative, never the annual. For UNFI that is $26 million in fiscal 2025 less $21 million in fiscal 2026, or about $5 million net, and it is net of $45 million in insurance rather than gross of it. Any benchmark built from single-year add-backs is measuring the timing of insurance settlements, not the severity of incidents.

    If you are building a business case for cyber insurance, this is a usable data point. A distribution-halting incident at a $31 billion wholesaler produced $45 million in recoveries booked in the following fiscal year. Note the lag as carefully as the amount: the costs hit one year and the recoveries the next, so the cash-flow and covenant picture in the incident year is the gross number, not the net.

    If you sit in finance or FP&A at a company that has had an incident, decide now how you will present year two. The reversal in year two is arithmetically correct and reads badly if it arrives without explanation. A single sentence giving the cumulative figure costs nothing and removes the ambiguity that this filing leaves open.

    If you are a UNFI customer or supplier, the operational story is over and the disclosure story is not. There is nothing to patch and nothing to act on defensively here. The open item is what the incident actually cost, which remains unstated and is not derivable from any single filing.

    Sourcing note

    Checked. United Natural Foods’ Form 8-K, accession number 0001020859-26-000022, read from SEC EDGAR; the acceptance timestamp of 7:02:12 a.m. ET and the item designations come from the filing index and directory. All quoted language and every figure above come from the exhibit filed with it, the fourth-quarter and fiscal-year 2026 earnings release, including footnote 5 to the non-GAAP reconciliation, quoted in full. Fiscal 2026 is the 52 weeks ended August 1, 2026; fiscal 2025 is the 52 weeks ended August 2, 2025. The Item 8.01 in this filing concerns a $200 million share repurchase authorization and is unrelated to the incident.

    Could not reach. cisa.gov returns HTTP 403 to automated fetching. No agency advisory relates to this filing and none was sought beyond that.

    Unresolved. The total cost of the June 2025 incident, which the company has not stated and which cannot be derived from this release alone. The dollar value of sales lost in fiscal 2025, which the release says occurred and does not quantify. The terms, retention, and limits of the insurance that produced the $45 million recovery. Whether further recoveries are expected. And whether the 0.7 percent fourth-quarter sales decline against a cyber-depressed prior-year quarter reflects any residual effect of the incident — the release does not say, and this page does not assert that it does. The $5 million two-year net figure above is arithmetic performed by this publication on the company’s two reported annual figures, not a number the company has published.

  • The SEC made Ardent Health drop $97.7 million in non-GAAP add-backs. Its 2023 ransomware carve-out survived.

    The SEC made Ardent Health drop $97.7 million in non-GAAP add-backs. Its 2023 ransomware carve-out survived.

    Ardent Health’s Friday 8-K removes two adjustments after talks with the SEC’s Division of Corporation Finance, and leaves untouched a cybersecurity line that has run $35.6 million net positive since the November 2023 attack.

    What happened

    Ardent Health, Inc. (NYSE: ARDT) filed a Form 8-K on Friday, September 4, 2026, under Item 8.01, Other Events, and Item 9.01. It is not an incident disclosure. It revises the non-GAAP financial measures in the company’s Form 10-K for the year ended December 31, 2025, filed March 16, 2026 — at the SEC’s prompting.

    The filing removes two adjustments from Adjusted EBITDA and Adjusted EBITDAR: “the Company’s (i) change in accounting estimate related to the collectability of accounts receivable” and “(ii) New Mexico professional liability accrual.” Both were confined to the third quarter of 2025. Together they came to $97.7 million. Ardent states the reason in one sentence: “these revisions are being made in connection with the Company’s discussions with the staff of the Securities and Exchange Commission’s Division of Corporation Finance to no longer include these adjustments.”

    The effect is large. Adjusted EBITDA for the year ended December 31, 2025 falls from $545.0 million to $447.3 million. Adjusted EBITDAR falls from $709.3 million to $611.6 million. The 2023 and 2024 figures are unchanged, 2026 results are unaffected, and the company is explicit that “the removal of these two adjustments has no impact on the Company’s GAAP consolidated financial statements, financial condition, results of operations or cash flows, which remain unchanged.” Nothing audited moved. What moved is the number analysts quote and, as the exhibit notes, the number some of Ardent’s landlords measure it against.

    What did not get removed is the part worth reading. Exhibit 99.1 restates the Adjusted EBITDA definition in full, and it still excludes “Cybersecurity incident recoveries, net of incremental information technology and litigation costs.” The reconciliation carries that line across three years, in thousands of dollars:

    • Year ended December 31, 2023: 8,495
    • Year ended December 31, 2024: (21,477)
    • Year ended December 31, 2025: (22,655)

    Footnote (b) explains it: “Cybersecurity incident (recoveries) expenses, net represent insurance recovery proceeds, net of incremental information technology and litigation costs, related to a cybersecurity incident that impacted our operations and information technology systems in November 2023.”

    The signs matter. In 2023 the line is a positive add-back — a net cost of $8.5 million, added back to net income. In 2024 and 2025 it is negative, a gain being removed from net income, because insurance proceeds that year exceeded the incremental IT and litigation spend. Across the three years the line nets to $35.6 million in Ardent’s favor. The quarterly column in the same exhibit shows the line at zero for the three months ended December 31, 2025, so the recoveries had run out by the end of last year.

    The incident behind the line is public and old. Ardent detected it “on the morning of November 23, 2023,” took its network offline, “suspending all user access to its information technology applications,” and said in a statement dated November 27, 2023 that the event “has since been determined to be a ransomware attack.” The same statement said: “At this time, we cannot confirm the extent of any patient health or financial data that has been compromised.” Ardent was privately held at the time; it priced its initial public offering in July 2024. The exhibit describes a company operating 30 acute care hospitals, 12 of them leased from two real estate investment trusts.

    Why it matters

    Non-GAAP adjustments are where a company tells investors which of its costs do not count. Corp Fin reviews them, and this filing is a dated window into what that review will and will not tolerate — on a document that also carries one of the longest-running public accountings of a hospital ransomware attack anyone has filed.

    Look at the direction of travel. The two adjustments the SEC discussions removed were expenses being added back: a change in estimate on receivables collectability and a liability accrual, both of which raised Adjusted EBITDA, both confined to a single quarter, together worth $97.7 million. Add-backs that flatter a metric are the category regulators have been skeptical of for a decade. The cybersecurity line in 2024 and 2025 runs the opposite way — it takes a gain out, and excluding a windfall is harder to object to than excluding a cost. That is not proof the staff blessed the cyber line; the filing does not say the staff reviewed it. But the carve-out survived a round of scrutiny that $97.7 million of other adjustments did not.

    The second thing worth taking away is the timing shape. Cyber incident costs land immediately; insurance recoveries land one to three years later, after the claim is adjudicated. Ardent’s own numbers make the point cleanly: a net cost in the year of the attack, then two consecutive years of net recoveries roughly two and a half times that cost, then zero. Anyone who models the financial impact of a ransomware event from a single year’s disclosure — in either direction — will get the wrong answer, and the error flips sign depending on which year they happen to pick.

    That leads directly to what the line is not. It is insurance proceeds minus incremental IT and litigation costs. It is not the cost of the attack. The revenue that did not arrive in the fourth quarter of 2023, the clinical disruption, and the permanent security spending that became ordinary-course rather than incremental are all outside it, and Ardent has not broken any of it out. A reader who sees a three-year net of positive $35.6 million and concludes the company came out ahead on a ransomware attack has misread the label. What the number actually measures is that the insurance worked.

    The last point is about where the record lives. Ardent’s incident happened in November 2023, while the company was private and roughly three weeks before Item 1.05 of Form 8-K — the SEC’s material cybersecurity incident item — took effect for most registrants. There was no Item 1.05 filing because there could not have been one. So the durable, filed public record of this incident’s financial consequence is not an incident report at all. It is a footnote in a non-GAAP reconciliation, restated on a Friday nearly three years later, in a document whose stated purpose is something else. This site has spent much of its Breach coverage on the difference between Item 1.05 and Item 8.01. Here neither item is the point: the incident is disclosed, durably and specifically, by an accounting definition that has outlived the attack by thirty-four months.

    What to do

    If you are on the finance side: know whether your own non-GAAP definitions carry a cyber carve-out, which direction it points in each period presented, and how long you intend to keep it. A carve-out that flips from cost to recovery is the normal shape of an insured incident, not an anomaly — but it needs an explanation ready before an analyst asks why an adjustment reduced adjusted earnings. And note that Ardent’s exhibit says “financial covenants in certain of our lease agreements, including the Ventas Master Lease, use Adjusted EBITDAR as a measure of compliance.” A non-GAAP adjustment a regulator disallows is not cosmetic when a covenant is computed on it.

    If you are on the security side: this line is the number your board eventually sees, and its accuracy depends on bookkeeping that starts on day one. Ardent can report incremental IT and litigation costs separately from ordinary spend because someone tagged them at the time. Incident cost tracking that begins after the recovery is over produces a number no one can defend to an auditor, and an insurance claim that is harder to substantiate.

    If you are reading someone else’s filings: read the reconciliation, not the headline metric. A cyber line inside an Adjusted EBITDA definition tells you an incident happened, roughly what it cost, and whether the insurer paid — often in more usable detail than the incident disclosure itself.

    Sourcing note

    Checked: Ardent Health, Inc.’s Form 8-K filed September 4, 2026, accession number 0001628280-26-060735, CIK 0001756655, read directly from SEC EDGAR — both the primary document and Exhibit 99.1, which is the source for every dollar figure, the Adjusted EBITDA and Adjusted EBITDAR definitions, the three-year reconciliation table, and footnote (b). Ardent’s own statement of November 27, 2023 is the source for the detection date and the ransomware confirmation, and the company’s pricing and closing announcements for the July 2024 IPO.

    Could not reach: EDGAR’s company-browse interface disallows automated fetching, so the filing was located through EDGAR full-text search and read from its archive path. Ardent’s 2025 Form 10-K as originally filed on March 16, 2026 was not retrieved; the pre-revision figures of $545.0 million and $709.3 million are taken from the 8-K’s own description of what it is changing.

    Unresolved: The 8-K does not say whether the SEC staff reviewed the cybersecurity adjustment, or whether it was discussed and retained. It says only that the two named adjustments are being removed in connection with those discussions. Nothing here should be read as the staff endorsing the cyber carve-out. Ardent has not published a total cost for the November 2023 incident inclusive of lost revenue, and no figure for that appears in this filing. The company has not stated whether further insurance recoveries are expected; the line reads zero for the fourth quarter of 2025, which is consistent with the claim being closed but does not confirm it.