When a company discloses a data breach, its stock usually falls. We hear, “the breach wiped X billions off the company's value”. The reported figure as stated is almost always wrong, albeit satisfying to a casual observer. In effect, it credits the breach with the sector selloff that week, the macro backdrop, and whatever trajectory the stock was already on. To know what a breach actually cost shareholders, you need the one thing a price chart cannot show you: what the stock would have done if the breach had never happened.
In the age of Mythos in 2026, this has never been more important. To understand the future, we start by understanding what’s happened historically.
We set out to recover that causal counterfactual properly, across the largest breaches at US-listed companies over the past decade.
How the obvious number misleads
Equifax is a textbook case. After its September 2017 disclosure, the stock fell roughly 35 percent. If one were to attribute that all to the breach, that also blames the breach for a financial-data sector under pressure that autumn, a market melt-up that made the relative underperformance look larger, and a stock that had outrun its peers for eighteen months and had room to revert.
The standard tool here, the cumulative-abnormal-return event study, subtracts the market's move using a single beta. It cannot see a sector-wide shock hitting every peer at once, a risk exposure that drifts over two years, or a company that was already decelerating before the breach. So it over-blames the breach when the sector was weak, and under-blames it when a bull market was lifting everything.
The method in a nutshell
Synthetic control, introduced by Abadie, Diamond and Hainmueller, takes a different route. Instead of modelling the counterfactual with a formula, it builds one from data. You take peer companies that were not breached, and find the weighted blend of them whose combined stock history most closely tracks the breached company in the years before disclosure. That blend is the synthetic twin. After disclosure, the gap between the real company and its twin is the causal cost. The sector and the macro are already absorbed, because the twin lived through the same conditions.
We pair this with the classical event study for the immediate reaction, and we stress every estimate: permutation tests against each peer, placebo tests in space and in time, and consistency across six, twelve, and twenty-four month windows.
This is where the textbook and the practice part ways. A clean diagram on a slide hides a fight with the data. Peers that track a company in calm markets can diverge under a shock for reasons that have nothing to do with a breach. Capital One looked like a significant result until we noticed its synthetic twin was built from diversified banks, which do not amplify the consumer-credit cycle the way Capital One does. Once the peer set was tightened to pure-play card lenders, the effect vanished. Catching that is “the work”, and every such correction is documented.
What we found

Four breaches left a durable mark.
- Equifax repriced about 25 percent immediately, then drifted to roughly 39 percent underperformance over two years, an estimated six billion dollars, as the FTC fine, the class-action settlement, and state proceedings landed one after another.
- Sony's PlayStation Network breach in 2011 is the largest in the set, an estimated twenty billion dollars. Seventy-seven million accounts were exposed and the network went dark for twenty-three days. Data loss and an operational shutdown together.
- MGM Resorts in 2023 showed nothing at disclosure, then sank to a roughly forty percent gap over two years as operational damage, lost high-end custom, and remediation accumulated.
- Comcast's 2023 breach registered at the two-year horizon, with a large exposure and a pending settlement behind it.
Just as informative are the breaches that left no lasting damage. Target, Home Depot, Capital One, Anthem, and UnitedHealth all generated headlines at disclosure and recovered to their counterfactual.

The cleanest evidence is Sony, breached twice. The PlayStation Network outage left a deep, lasting gap. The 2014 Sony Pictures hack, a document leak with no service interruption, was the cleanest example of no measurable market impact in the entire dataset. The same company, with opposite outcomes.
We also report where the method fails. The 2022 Okta breach cannot be measured: the technology selloff that year dragged every peer down at the same time, so no clean counterfactual exists. We mark that as a measurement failure, not as evidence of no effect.
The pattern
One rule fits the results. The market durably penalises a breach when it impairs the core franchise or creates open-ended liability, and it absorbs the rest. Two consequences follow.
The immediate reaction is not the long-run cost. UnitedHealth fell sharply at disclosure and recovered. MGM did the reverse. Reading either from the announcement-week move alone gives the wrong answer.
For large, diversified firms, a breach that is small relative to the company, or that leaves operations running, does not register in the stock. The costs are substantive but they sit inside normal earnings variance and leave no durable market signal.
Why it matters
Securities plaintiffs, regulators setting fines, and boards sizing cyber insurance all need the same quantity: the counterfactual cost of the breach, not the headline drop. A defensible number changes the analysis in every one of those rooms.
The full study, underlying data, and reproducible analysis are available on GitHub. Read the full technical report.
What comes next
This analysis looks backward. We’re more interested in what happens next.
The PolyBridge Cyber Situation Room is a live environment for breach risk. It turns the historical transfer function above into a forward-looking signal: the probability of a breach disclosure in a given sector over the coming weeks, the expected market and dollar impact if a named firm is hit, and the accumulation risk across a portfolio of exposures. Because it sits on a causal model, you can also ask intervention questions, for example how much a mandated control changes sector breach hazard.
Live Cyber coverage: Request early access.