Live Cuts
Recomputed on every build. As of September 7, 2026.
A live cut is a reading of this index’s own ledger, computed from the incidents tracked here. It is a count, never a sum. It moves as the record does: every figure on this page is recomputed on each build.
Two cuts draw on outside feeds, shown alongside the ledger and never merged with it: the ransomware leak-site activity (ransomware.live) and the ITRC breach-transparency context. For outside primary-source evidence held to the Exhibit Rule, see the Exhibits.
Live Cuts
Most “material” cyber filings report no dollar figure
n = 53 filingsEach cell is one approved primary Item 1.05 filing on this ledger; every one links to its 8-K, and the count is verifiable filing by filing.
Item 1.05 materiality can rest on non-financial factors, and a cost is often unknown when the 8-K is filed. That is the point: the disclosure built to signal significance rarely carries its size.
THE FLOOR · A count of filings tracked to date, not a census of all disclosures.
Most incidents on this ledger carry no dollar figure
n = 187 incidentsThe silence holds across both feeds: a figure appears on 25 of 115 government-record incidents and 2 of 72 beyond the filings. Each is an approved primary record; a count of incidents, never a sum of dollars.
Enforcement and registry records (state-attorney-general notices, regulator actions, the HHS OCR breach portal) are not counted here: their money is a penalty or none at all, not an incident cost, so they are neither priced nor silent. 76 such records are set aside.
A missing figure is not a loss of zero. It means the cost is unknown, not yet disclosed, or never quantified. The absence is the finding: the public record of what cyber costs is mostly blank.
THE FLOOR · A count of incidents tracked to date, not a census of all breaches.
Tracked incidents by sector
n = 263 incidents263 incidents shown, tagged approved primaries. 0 more are pending a sector and are not yet placed. 19 corroborations nest under their primary incidents and are not counted separately. So 263 plus 0 pending is 263 primaries, and the corroborations are nested, not missing.
Share of incidents tracked on this ledger, not of all breaches. Healthcare leads partly because mandatory breach-disclosure rules in that sector put more of its incidents into the public record, not because it is necessarily attacked more often.
THE FLOOR · This count is a floor, the incidents tracked to date, not a census of all breaches.
Ransomware leak sites named 86 organizations in the last 7 days
a sample of one attack type31,532 organizations tracked across 396 groups since 2005, per ransomware.live.
Provided as-is by an independent project; postings can lag or be revised, and a claimed victim is not a confirmed breach. A count of leak-site postings, never summed and never a cost.
A record pace of breaches, and the least disclosed on record
First half of 20262025 set a record at 3,322 U.S. compromises; ITRC has tracked more than 25,200 over its 20-year history.
ITRC counts publicly reported compromises from news, government, and company sources; figures can be revised as more is disclosed. A count of events and notices, never a dollar figure and never merged with this ledger.
Source: Identity Theft Resource Center · H1 2026 Data Breach Report →
Most incidents never say how the attacker got in
n = 261 classifiedThe national picture agrees: ITRC records that only about a quarter of breach notices name how the attacker got in, the lowest on record. See the ITRC context card above.
Initial attack type graded confirmed (the source states it) or inferred (circumstantial); undisclosed is the honest majority. A count of incidents by attack type, never a dollar figure and never summed.
THE FLOOR · Counted from incidents classified to date, not a census of all attacks.