# AnswerPool Cyber Incidents

> AnswerPool Cyber Incidents is a paid API for AI agents from answerpool.io, paid per call via x402, $0.02/call, status unknown (last checked 2026-09-16).

Lists SEC 8-K filings disclosing material cybersecurity incidents (Item 1.05) market-wide, with company identifiers, timestamps, and filing links.

## Facts

- Endpoint: GET https://answerpool.io/v1/sec/8k/cyber
- Price: $0.02/call
- Payment: x402
- Status: unknown
- Last checked: 2026-09-16
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/answerpool-cyber-incidents-81bd002d
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_vR0qUV8LqY-k15sRe7gAM

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability answerpool-cyber-incidents-81bd002d
```

Example prompt: Pull the last 50 8-K filings disclosing material cybersecurity incidents filed since August 1, 2026 — I need the company names, tickers, and filing links.

## When to prefer this

Use this endpoint when you need a ready-made, filtered feed of only Item 1.05 cybersecurity incident 8-Ks without having to parse all SEC full-text filings yourself. Ideal for breach monitoring workflows, insurance underwriting pipelines, or security intelligence dashboards that need market-wide coverage with minimal processing. Prefer this over EDGAR full-text search when you specifically want cyber incidents pre-classified and structured, rather than running keyword queries across all form types.

## Known failure modes

- No events returned if no cybersecurity 8-Ks have been filed in the requested window (empty events array with count 0)
- since parameter must be a valid ISO 8601 datetime string or null; malformed dates may return an error
- limit must be between 1 and 200; out-of-range values will be rejected
- Payment required (402) if x402 payment header is missing or USDC balance is insufficient
- Data freshness depends on SEC EDGAR indexing lag — very recent filings may not yet appear

## How this service works

AnswerPool turns SEC EDGAR, the Federal Register, USAspending, NIH, BLS and OpenAlex into structured JSON answers that AI agents and developers fetch in one call. 69 endpoints free, no account; derived analyses $0.02–$0.05 per call by card credits or USDC (x402). MCP server, full provenance.

## Output

Returns a JSON object containing a list of cybersecurity incident events, each with event_id, accession number, CIK, ticker, company name, form type, event_type, occurred_at timestamp, flags array, relevance score, payload details, and a direct filing_url. Also includes metadata: as_of timestamp, since cursor, count of results, and index_started_at.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET",
      "HEAD",
      "DELETE"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "title": "WindowIn",
     "properties": {
      "limit": {
       "type": "integer",
       "title": "Limit",
       "default": 50,
       "maximum": 200,
       "minimum": 1,
       "description": "Maximum 8-K events of this view's event type returned, newest first; 1 to 200, default 50."
      },
      "since": {
       "anyOf": [
        {
         "type": "string",
         "maxLength": 32
        },
        {
         "type": "null"
        }
       ],
       "title": "Since",
       "default": null,
       "description": "Earliest event time, ISO 8601 date or timestamp (e.g. 2026-08-01 or 2026-08-01T00:00:00Z); UTC if no offset, capped at 90 days back. Omit for this view's own default window of 7 to 30 recent days."
      }
     },
     "additionalProperties": false
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "as_of": "2026-08-31T14:00:00Z",
  "count": 0,
  "since": "2026-08-01T00:00:00",
  "events": [],
  "next_cursor": "2026-08-01T00:00:00",
  "index_started_at": "2026-08-27T00:00:00Z"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/answerpool-cyber-incidents-81bd002d/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from answerpool.io](https://www.zero.xyz/host/answerpool.io/llms.txt)
