Abstract
This study investigates the financial impact of cybersecurity breach announcements on the shareholder value of publicly traded companies in the United States from 2020 to 2025. Background: As corporations have become increasingly reliant on digital infrastructure, the frequency and cost of cybersecurity breaches have escalated, posing a material risk to firm value. This research examines the market's reaction to such events in a period marked by pandemic-accelerated digitalization and evolving cyber threats. Methods: Using a sample of 412 breach announcements from firms listed on the NYSE and NASDAQ, we employ a standard event study methodology to measure the abnormal stock returns around the announcement date. The market model is used to estimate expected returns, and a cross-sectional regression analysis is conducted to identify the determinants of the market's reaction. Results: The event study reveals a statistically significant negative cumulative average abnormal return (CAAR) of -2.87% over the two-day (0, +1) event window following the breach announcement. The negative market reaction is swift and largely completed within two trading days. Our cross-sectional analysis indicates that the negative returns are more severe for breaches involving the compromise of personally identifiable information (PII), for smaller firms, and for companies in the technology and financial sectors. Conversely, a prompt and transparent disclosure appears to mitigate the negative impact. Conclusion: The findings confirm that cybersecurity breaches result in a substantial and immediate destruction of shareholder value. The magnitude of this loss underscores the materiality of cybersecurity risk and highlights the financial imperative for robust corporate governance and investment in information security. The results provide valuable insights for managers, investors, and policymakers regarding the financial consequences of data security failures in the contemporary economy.