Every figure this index publishes is held to a standard. This page states those standards plainly, so a reader can check the work rather than take it on trust.
The index exists because the headline numbers put on cyber loss do not hold up when you follow them to their source. The answer here is not a better estimate. It is a stricter record. Two rules govern everything below: a figure is only as good as the document behind it, and figures from different incidents are never added together.
This index never sums dollar losses across incidents. Add them together and you get a number that means nothing: the figures come from different companies, periods, definitions, and standards of proof, and a total silently treats them as one measurement.
So the index counts incidents and shows each figure on its own, next to the source that stated it. Where you see a count, it is a count of events. Where you see a dollar figure, it belongs to one incident. There is no grand total on this site, and there never will be.
Every figure carries one of three grades, shown as a badge beside it. The grade is about provenance, not size: it says how well the number is sourced, and nothing about how large or how severe the loss is.
Verified figures live On the Government Record. Attested and Inferred figures live Beyond the Filings, and never borrow the Verified grade: that grade is reserved for the primary filings and enforcement records, and is not extended to a company statement or a news report.
A figure on a card is one incident’s own disclosed number, read from the source and linked to it. When a company later states a typed cost (a direct expense, a business-interruption loss, remediation spend, or a stated total), that figure enriches the card; it never replaces the disclosure with a guess. A single incident may carry more than one figure, for instance a direct cost and a revenue impact. They are shown side by side, each labeled, and never summed into one.
Numbers move. A cost figure arrives after an incident is disclosed and changes as stronger sources report it; early estimates usually run below the figure a company eventually files. Each card shows its most recent figure, and beneath it, on the ledger, the full revision trail: every prior claim in order, each with its date, its source, and its grade. Nothing is quietly overwritten.
This ledger is a floor, not a census. Where there is no measurement, there is no number here, only its absence: an incident with no disclosed figure reads “Not yet quantified,” never a filled-in estimate. Most cyber incidents never reach a public filing or notice at all. What is tracked here is a lower bound on the record, not a count of everything that happened.
Beyond the incident ledger, the index shows charts. They come in two kinds, kept apart on purpose and each labeled so a reader always knows which is which. One carries evidence from the world; the other carries readings of this record.
An exhibit is a figure from outside this index: a public, primary-source number a reader can verify against the original document, chosen because it shows an instrument that should track loss failing to. Every exhibit must pass four tests, all four required.
Two conditions ride on every exhibit: the basis is pinned before publication (where a source has more than one version of a figure, the canonical one is named on the card), and any known discrepancy is footnoted, not hidden. And one disqualifier overrides a pass on all four: if a figure’s movement could be a reporting-method change rather than a real-world change, it is held until that is resolved with the source directly.
A live cut is a reading of this index’s own ledger, such as the breakdown of tracked incidents by sector. It is labeled “From the ledger,” and it answers to one rule above all: the never-sum rule. A live cut may count incidents, or show their share, but it may never add up dollar losses. It shows what the ledger holds, a floor, and never reads as covering the whole. A live cut draws only on records that already cleared grading and provenance; the standard is never relaxed to fill a slice.
Aggregate figures are reproduced as single, attributed data points, and each links to its originating report: the FBI Internet Crime Complaint Center (IC3), Chainalysis, the NAIC cybersecurity-insurance supplement, and the IBM / Ponemon Cost of a Data Breach. Source figures remain the property of their publishers and are shown here as attributed data points for commentary and research.
Forward projections are noted, never charted as measured loss. The widely cited “$10.5 trillion by 2025,” for one, is a projection compounded from a base whose methodology is not disclosed. A projection is not evidence, and this index does not draw it on the same axis as measured figures.
The full incident record is published as open data: one row per distinct incident, the same records and the same order as the ledgers, each with a link back to its card and to its primary source. Reuse it for reporting or research. Attribution to The Hacker in a Hoodie Index is appreciated.
organization and breached_entity, feed (government record or beyond the filings), disclosed_date, grade, sector, the typed figure_type, source_url (the primary document), and record_url (a deep link back to the card).amount_usd is one incident’s own figure, and is blank where no single figure applies (a multi-figure set, a blended figure, or an unquantified incident). It is not summed here, and it should not be summed there.New incidents enter the record from SEC 8-K filings and from state-regulator and federal breach notifications, each reviewed before it is published. The per-feed ledgers are the complete, uncapped record; the front page shows only the most recent few of each.
Every figure links to the source it was read from. If we have read one wrong, that is worth knowing: tell us at info@hackerinahoodie.com. An index whose argument is that published numbers do not hold up should invite scrutiny of its own.