Skip to content
cisonews.net

Incident · 8-K Item 1.05

Data I/O reports ransomware traced to a third-party firewall vulnerability

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

Data I/O, which makes device programming systems for electronics manufacturers, disclosed on August 21, 2025 that it had suffered a ransomware incident on internal IT systems on August 16. A second Item 1.05 filing on September 10 said the incident was not targeted at the company and put the recovery cost at about $388,000.

First filing

Communications, shipping, receiving and manufacturing were affected. The company said the incident did not appear to have materially affected operations so far, but expected its costs to be material to results.

September update

The follow-up 8-K identified the entry point. Systems were restored and no revenue appeared lost.

Not named

Data I/O did not name the firewall provider or the ransomware group.

Sources

  1. 2025-08-21 · AData I/O Corporation, Form 8-K (SEC EDGAR), published August 21, 2025
  2. 2025-09-10 · AData I/O Corporation, Form 8-K (SEC EDGAR), published September 10, 2025

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.