Desk live·
ForensicPost
Breaches/Verification/File 25-1218c

It Reached the Record Through a Stock Exchange Filing

The NHS supplier incident was disclosed in a filing with the stock exchange. That is the fifth filter at 25-0924b, operating in a second jurisdiction.

Constructed geometry · not a chart of case data
JurisdictionUnited Kingdomthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetIncident record formation
ActorUnattributed
D. Kennedy11 min readConfidence: high2 sources reviewed

The DXS International incident at 25-1214b was disclosed through a filing with the stock exchange on 18 December 2025, four days after discovery.

The Corpus Named This Route In September

At 25-0924b this desk added a fifth filter to the record-formation argument at 25-0502: whether the company is listed. Boyd Gaming’s employee-data incident reached the public record through a securities filing rather than through any data-protection route.

That file observed the filter introduces a wealth gradient — a private company with identical exposure has no equivalent trigger — and this is the same mechanism in the UK, at a supplier far smaller than a US casino operator.

Four Days Is Fast By This Corpus’s Standards

Marquis discovered on the day and told client institutions 74 days later, at 25-1027. LVMH brands disclosed a January compromise in May, at 25-0710. Breached in 2024 and disclosed in 2026, at 26-0515.

Four days from discovery to public disclosure is at the fast end of anything in this database — and it happened because a listing obligation applied, not because a health-data regime required it.

Which Is An Argument For The 24/72 Regime

The UK Bill proposes two-stage reporting at 25-1119: initial notice at 24 hours, fuller report at 72. This desk filed that as the fix for the layered-notification gap at 25-1027.

Securities disclosure achieves something similar by accident, for listed companies only. A general obligation would extend the same speed to the private suppliers that produce most of the incidents in this database.

The corpus now has two files — 25-0923b and this one — where the market regulator surfaced an incident the data regulator would not have.

This is an analysis file

It records a disclosure route observed at 25-1214b and connects it to the record-formation argument in this database. Corrections: corrections@forensicpost.com.

Sources
  1. NHS tech supplier probes cyberattack on internal systemsThe Register
  2. Tech provider for NHS England confirms data breachTechCrunch
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary