Itron, Inc. (NASDAQ: ITRI), a Liberty Lake, Washington manufacturer of electricity, gas and water meters and the grid software that runs them, was notified on April 13, 2026 that an unauthorized third party had gained access to certain of its systems. Eleven calendar days later, on April 24, 2026, Itron filed a Form 8-K with the Securities and Exchange Commission under Item 8.01 (Other Events).
On May 1, 2026, Itron filed a Form 8-K/A superseding that claim. " Five business days separated the two statements. The amendment's Explanatory Note says only that it "is being filed solely to provide an update to the disclosure on Form 8-K filed by Itron, Inc. (the 'Company') with the Securities and Exchange Commission on April 24, 2026." Itron offered no explanation for why the original finding did not survive its own investigation. This article is about that sequence. It is not an allegation that Itron misled anyone, and ZERO|TOLERANCE makes no such claim.
KEY FACTS
- WhatA public company filed an 8-K stating no unauthorized activity was seen in customer hosted systems, then filed an amendment seven calendar days later identifying limited unauthorized access to certain customer-hosted systems.
- WhoItron, Inc., CIK 0000780571, Commission File 000-22418, NASDAQ Global Select Market ticker ITRI. Per BleepingComputer, roughly 5,600 employees, $2.4 billion in 2025 revenue, 7,700 customers across 100 countries, and 112 million managed endpoints. Itron's own filings describe its customer base as utilities and municipalities.
- HowNot disclosed. No filing describes the initial access vector, the intruder's dwell time, or how the customer-hosted access was ultimately identified.
- DataNot disclosed. No filing names a single data category, record count, or affected customer.
- ActorNone named. No group has claimed the intrusion and no formal technical attribution has been issued.
- ImpactItron maintained across both filings that the incident is not reasonably likely to have a material impact. It expects insurers to reimburse a significant portion of direct costs.
WHAT HAPPENED
Both filings report the same date of earliest event: April 13, 2026, a Monday. The original 8-K states that on that date Itron "was notified that an unauthorized third party had gained access to certain of its systems," language indicating the company learned of the intrusion from an outside party rather than detecting it itself. Itron activated its cybersecurity response plan, engaged external advisors, and proactively notified law enforcement.
The Form 8-K was accepted by EDGAR at 12:30 UTC on April 24, 2026, nine business days after the notification date, under accession number 0001193125-26-175249. " It then drew a boundary between corporate and customer environments and asserted that the customer side was clean.
On April 28, 2026, Itron filed two documents that did not mention the incident at all. The first was its Form 10-Q for the quarter ended March 31, 2026. The second was an earnings Form 8-K under Items 2.02 and 9.01, whose Exhibit 99.1 press release also contains zero occurrences of "cyber," "unauthorized," "breach," or "incident." Neither omission is remarkable on its own: the quarter had closed on March 31, before the April 13 intrusion, and a subsequent event requires disclosure only if material.
On May 1, 2026, at 12:30 UTC, Itron filed the Form 8-K/A under accession number 0001193125-26-199316. It reported no further unauthorized activity, restated that operations continued in all material respects, and then reversed the customer-hosted finding. It added a second sentence that is easily misread: "The Company has not observed any evidence that customer-facing system functionality was materially affected." Both filings were signed by Joan S. Hooper, Senior Vice President and Chief Financial Officer.
The more telling filing came later. On July 28, 2026, Itron filed its Form 10-Q for the quarter ended June 30, 2026, accession 0000780571-26-000178. " Part II, Item 1A adds no incident-related risk factor, stating in full: "For a complete list of Risk Factors, refer to Part I, Item 1A: Risk Factors of our Annual Report on Form 10-K for the fiscal year ended December 31, 2025, which was filed with the Securities and Exchange Commission on February 17, 2026." Itron applied its non-materiality conclusion consistently across every filing in the period.
Consistency is not the same as correctness, but it is the opposite of opportunism, and it should be weighed in the company's favor.
TECHNICAL ANALYSIS: THE LANGUAGE THAT CHANGED
The precision of the two sentences is the entire story, so both are reproduced in full.
April 24, 2026, Form 8-K, Item 8.01: "The Company took action to remediate and remove the unauthorized activity and has not observed any subsequent unauthorized activity within its corporate systems. Further, no unauthorized activity was observed in the customer hosted portion of its systems."
May 1, 2026, Form 8-K/A, Item 8.01: "Since the filing of the Original Report, the Company has not observed any further unauthorized activity in its systems. Its operations have continued in all material respects. Based on the investigation to date, the Company has identified limited unauthorized access to certain customer-hosted systems. The Company has not observed any evidence that customer-facing system functionality was materially affected."
Three observations follow, and the third is the one that matters most to Itron's customers.
First, the operative sentence was unqualified. "No unauthorized activity was observed" is an affirmative negative finding stated flatly, eleven days into an investigation, about the one environment utility customers care most about. Two counterweights belong here in fairness. Itron qualified its materiality conclusion in the same filing, writing "While the Company's investigation and assessment of this incident is ongoing" before assessing impact.
And both 8-Ks carry a forward-looking statements section that expressly lists as a risk factor "the results of the Company's analysis of the scope and details of the incident and the discovery of new or additional information," which is precisely the eventuality that materialized. Neither counterweight fully answers the point. The Private Securities Litigation Reform Act safe harbour protects forward-looking statements, not statements of present or historical fact, and "no unauthorized activity was observed" is a statement of historical fact about what an investigation had found.
The caveats attached to the parts of the filing that were predictive. They did not attach to the part that was declarative. An investigation producing new findings is ordinary and expected, and incident response routinely overturns early conclusions. The defensible criticism is not that the finding changed. It is that this particular sentence was cast in a form that did not anticipate its changing, while the sentences around it were.
Second, the amendment is narrower than the sentence it replaces. "Limited" and "certain" are undefined. Neither the number of customer-hosted environments nor the identity of any affected customer appears anywhere.
Third, the closing sentence addresses availability, not confidentiality. "Customer-facing system functionality was materially affected" is a statement about whether systems kept working. It is not a statement about whether data in those systems was accessed, viewed, copied, or exfiltrated. Those are different questions, and as of the amendment only the first has been answered. A reader who takes the sentence as reassurance about customer data is reading something the filing does not say.
TECHNICAL ANALYSIS: ITEM 8.01 VERSUS ITEM 1.05 Both filings were made under Item 8.01. EDGAR's own items metadata field for each accession reads "8.01" and nothing else. Item 1.05 was never invoked.
The distinction matters and is widely misunderstood. Under SEC Release Nos. 33-11216 and 34-97989, effective September 5, 2023, Item 1.05 of Form 8-K applies where "the registrant experiences a cybersecurity incident that is determined by the registrant to be material." Form 8-K General Instruction B.1 provides: "A report pursuant to Item 1.05 is to be filed within four business days after the registrant determines that it has experienced a material cybersecurity incident." The clock runs from the materiality determination, not from the incident or its discovery.
Filing under Item 8.01 was therefore not improper. Item 1.05 applies by its own terms only to incidents the registrant determines to be material. Itron determined this one was not, so no Item 1.05 clock ever started, and the nine business days between notification and the original filing violated no deadline. Item 8.01 is the catch-all and carries no trigger.
Two structural consequences follow, and the first is narrower than it is usually described. Item 1.05 carries a completion duty, not a rolling duty to update. " That duty fills in information a registrant flagged as unavailable when it filed. It does not require amendment every time findings evolve.
So Itron's May 1 amendment was not compelled by Item 1.05's completion instruction, which was never engaged. That is worth recording in the company's favor. " Those duties arise from the antifraud provisions and attach to what a company said, not to the Item number above it. Filing the amendment was the right call on any reading.
The second consequence goes to the corporate-versus-customer boundary the original filing drew. In the adopting release, the Commission addressed incidents on third-party systems: "we note the centrality of the materiality determination: whether an incident is material is not contingent on where the relevant electronic systems reside or who owns them.
That passage cuts both ways, which is why it belongs here in full. The Commission was addressing registrants whose own data sits on someone else's system. Itron is in the opposite posture: it is the service provider. The reasoning still travels, because the principle is that architecture does not settle materiality, and the express contemplation that disclosure may be required "by neither" is a direct acknowledgment that a provider-side incident can be immaterial to the provider.
What the passage forecloses is treating the corporate-versus-customer line as though it answered the question by itself. Materiality turns on impact on the registrant, and Itron has consistently answered that in the negative.
WHAT WAS EXPOSED
Nothing has been disclosed. This section exists to state that plainly rather than to fill it.
- No data category has been named in any filing. Not customer records, not utility operational data, not meter telemetry, not employee information, not credentials, not source code.
- No record count, file count, or data volume has been given by Itron or any other party.
- No affected customer has been identified, and the number of customer-hosted environments involved is undisclosed.
- No filing states whether data in the customer-hosted systems was accessed, viewed, copied, or exfiltrated. The amendment addresses functionality only.
- Itron said on April 24 that it was "evaluating what legal filings and regulatory notifications might be required," and the amendment repeated that this evaluation "remains ongoing." No notification determination has since been announced in its EDGAR filings.
Readers should treat the absence of figures as absence of disclosure, not as evidence of small scale. Neither inference is available on this record.
INDICATORS OF COMPROMISE
No threat actor IOCs have been published by Itron, by any government agency, or by any security vendor. No malware family, C2 infrastructure, file hash, IP address, domain, or CVE has been associated with this incident by any source retrieved for this report. The verifiable artifacts are the filings themselves.
- CIK 0000780571 (ITRON, INC.), EIN 91-1011792, incorporated in Washington, SIC 3825
- Form 8-K accession 0001193125-26-175249, filed and accepted April 24, 2026 at 12:30:06 UTC, items field "8.01"
- Form 8-K/A accession 0001193125-26-199316, filed and accepted May 1, 2026 at 12:30:18 UTC, items field "8.01"
- Form 10-Q accession 0000780571-26-000110, filed April 28, 2026, quarter ended March 31, 2026, no incident reference
- Form 8-K accession 0001171843-26-002750, filed April 28, 2026, Items 2.02 and 9.01, Exhibit 99.1 earnings release, no incident reference
- Form 10-Q accession 0000780571-26-000178, filed July 28, 2026, quarter ended June 30, 2026, no incident reference and no added risk factor
- Date of earliest event reported, both cybersecurity filings: April 13, 2026
REGULATORY EXPOSURE
- Exchange Act Section 13(a) and Form 8-K Item 8.01 (Other Events)Voluntary item with no filing trigger and no codified update obligation. Its use here is permissible.
- Form 8-K Item 1.05 (Material Cybersecurity Incidents), SEC Release Nos. 33-11216 and 34-97989 - Not invoked. Applies only on a registrant determination of materiality, which Itron has not made. Should that determination change, the four-business-day clock in General Instruction B.1 begins at the determination, and Instruction 2 then governs completion of any information flagged as unavailable.
- Form 8-K General Instruction B.2 - Only Items 2.02 and 7.01 are deemed furnished rather than filed and thereby placed outside Section 18 of the Exchange Act. Item 8.01 is neither. Disclosure made under Item 8.01 is filed, and Section 18 liability attaches to it. Choosing the voluntary item does not make the resulting statement consequence-free.
- Antifraud provisions and the duty to correct - Rule 12b-20 by its terms supplements "the required statements" in a report, so it is an imperfect fit for a voluntary Item 8.01 disclosure. The accuracy obligation for a voluntary statement runs instead through Section 10(b) and Rule 10b-5 and the duty-to-correct and duty-to-update doctrines the Commission restated in the adopting release. The practical consequence is unchanged: electing to speak under Item 8.01 does not carry a lower accuracy standard than speaking under Item 1.05, and correction is the mechanism through which the record is fixed. Itron used it.
- State breach notification statutes - Triggered by defined categories of personal information. Whether any trigger applies is unresolved because no data category has been disclosed. Itron's own filings confirm the analysis was still open.
- Downstream customer obligations - Utilities and municipalities operating Itron-hosted environments carry their own vendor-incident and regulatory reporting duties, assessed against their own regulators and not against Itron's materiality conclusion. A vendor's determination that an incident is immaterial to the vendor does not resolve whether it is reportable by the customer.
INTELLIGENCE GAPS
The Explanatory Note states the amendment was "filed solely to provide an update" and gives no account of whether the April 24 statement was wrong when made, rested on incomplete telemetry, or was overtaken by evidence recovered later. Itron did not address it in either filing.
Neither "limited" nor "certain" is quantified, and no affected customer is named.
The amendment speaks to functionality only. Confidentiality is a separate question that no filing addresses.
No filing describes how the third party gained access, and no vendor advisory or CVE has been tied to the incident.
Itron was "notified" on April 13, 2026 by an unnamed party. The date of the actual compromise, and therefore the interval before discovery, has not been disclosed.
Per BleepingComputer, no ransomware group has claimed the attack, and no formal technical attribution has been issued by any government or vendor.
Itron said the evaluation of required filings and notifications "remains ongoing" as of May 1, 2026, and no subsequent determination appears in its EDGAR filings through July 28, 2026, the date of its most recent filing.
No comment letter concerning these filings appears in Itron's public EDGAR record as of this writing.
ZERO|TOLERANCE Advisory
The single controllable failure in this sequence is the form of the April 24 sentence, not the fact that the conclusion later changed. "No unauthorized activity was observed in X" reads as a conclusion. "Our investigation has not to date identified unauthorized activity in X, and that assessment may change as the investigation continues" reads as a status. The second is equally informative, costs nothing, and does not require a correcting amendment a week later. Note that a forward-looking statements section does not fix this, because safe harbour protection does not extend to statements of present or historical fact. Route every affirmative negative in a securities filing through counsel and the incident commander jointly, and require the investigation lead to confirm that the evidentiary basis supports the tense used.
A statement that no activity was observed in customer-hosted systems is only as good as the logging, retention, and coverage in those systems. Before making such a statement, confirm in writing which environments have authentication, process-execution and egress telemetry, what the retention window is, and which environments have none. Where coverage is absent, the honest disclosure is that the environment could not be assessed, not that nothing was found.
"Functionality was not materially affected" and "data was not accessed" are different claims resting on different evidence. Readers conflate them, and a filing that answers only the first while the second remains open should say so explicitly rather than let the silence do the work.
Item 8.01 is a legitimate vehicle for an incident determined immaterial, and the SEC's adopting release makes clear that materiality turns on investor-relevant impact rather than on which systems were touched or who owns them. Item choice does not alter the antifraud duty to correct a statement later found untrue when made. Boards should require a written, dated materiality memo supporting the Item selection, refreshed whenever new facts arrive, so the determination is defensible if the facts move.
Ask Itron in writing which of your hosted environments were in scope, what log sources were available, whether any data in those environments was accessed rather than merely reachable, and over what date range. Your own regulatory reporting duties are assessed against your regulator and are not discharged by your vendor's conclusion that the incident was immaterial to the vendor.
Contracts should require notification of confirmed unauthorized access to your hosted environment within a fixed number of hours, independent of the vendor's own materiality assessment, and should entitle you to the underlying scoping artifacts rather than a summary conclusion.
SOURCES
Itron, Inc., Form 8-K filed April 24, 2026 (Item 8.01), accession 0001193125-26-175249 - https://www.sec.gov/Archives/edgar/data/780571/000119312526175249/d125229d8k.htm Itron, Inc., Form 8-K/A filed May 1, 2026 (Item 8.01), accession 0001193125-26-199316 - https://www.sec.gov/Archives/edgar/data/780571/000119312526199316/d151348d8ka.htm Itron, Inc., Form 10-Q for the quarter ended March 31, 2026, filed April 28, 2026 - https://www.sec.gov/Archives/edgar/data/780571/000078057126000110/itri-20260331.htm Itron, Inc., Form 8-K filed April 28, 2026 (Items 2.02, 9.01), Exhibit 99.1 earnings release - https://www.sec.gov/Archives/edgar/data/780571/000117184326002750/exh_991.htm Itron, Inc., Form 10-Q for the quarter ended June 30, 2026, filed July 28, 2026 - https://www.sec.gov/Archives/edgar/data/780571/000078057126000178/itri-20260630.htm SEC EDGAR submissions metadata, CIK 0000780571 - https://data.sec.gov/submissions/CIK0000780571.json SEC, Form 8-K, General Instructions B.1 and B.2 and Item 1.05 - https://www.sec.gov/files/form8-k.pdf SEC, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, Release Nos.
33-11216; 34-97989, File No.