The Wider Record
This index is one record. These are others worth knowing, for anyone seeking transparency in what is really happening with hacks, breaches, and incidents. They are grouped by what they are, because a primary filing, an aggregator’s tracker, and a commercial report are three very different kinds of truth, and knowing which you are reading is the whole game.
Primary and official records
The same tier this index draws from: the document itself, or a government register. Verifiable at the source.
Search every public-company filing, including the 8-K Item 1.05 cyber-incident disclosures this index is built on. Straight from the source.
The federal record of healthcare data breaches affecting 500 or more people. Required reporting, publicly listed.
Breach notifications filed with California's Attorney General, one of several state registries that put incidents on the public record.
The U.S. government's authoritative catalog of vulnerabilities confirmed exploited in the wild. Not incidents or costs, but the doorways attackers are actually using.
Aggregators and trackers
Useful for discovery and scale, but a step removed from the source. Read the provenance line on each.
A live tracker of ransomware victims named on the groups' own leak sites. Attacker-sourced: a claim of a breach, not a confirmed loss, and useful for exactly that.
Check whether your own accounts appear in known breaches. A public service built from breach data.
A nonprofit that compiles notified U.S. breaches and publishes periodic counts and analysis.
Long-running independent journalism on breaches, leaks, and the disclosures around them.
A searchable database aggregating breach filings from fourteen state attorneys general and HHS, back to 2005.
An open, machine-readable dataset of 8,000-plus publicly disclosed breaches, each coded to a common schema from HHS, state AGs, and media reports.
Research and economic reports
The scale-and-cost context: how large the problem is and what it costs. Several are the sources behind this index's own exhibits; two (Coveware and Sophos) are commercial, listed here for their figures, not their framing.
The FBI's annual tally of cybercrime complaints and reported losses. The loss series this index charts against the market.
An annual, methodology-forward analysis of thousands of confirmed breaches.
IBM and Ponemon's annual study of the average cost of a breach. The per-breach figure this index shows for shape.
Blockchain analysis of ransomware payments and illicit crypto flows. The ransom-payment series this index cites.
The National Association of Insurance Commissioners on the cyber-insurance market, where the cost of incidents surfaces as premiums and claims.
An independent research institute quantifying cyber-loss frequency and severity over more than fifteen years. Methodology-first, not a product vendor.
Fifteen years of real cyber-insurance claims, over 10,000 of them: what incidents actually cost once they reach an insurer. Loss data from the payout side.
A ransomware-negotiation firm publishing quarterly data on actual ransom payments, demand versus paid, and downtime. Commercial, but the most concrete ransom-payment data anywhere.
An annual survey of thousands of organizations on ransom paid and recovery cost. A vendor survey, read for its figures.
Vendor threat reports
The Built Wrong methodology does not support the vendor-incentive model behind reports that represent a commercial view of the problem, and it does not admit them as evidence in this index. We do not link them as a worldview to adopt. We list them here, deliberately set apart, for one reason: incentive aside, each collects real, provable telemetry at a scale and from a vantage no one else has, data that simply is not gathered anywhere else. Read them for what they measure, not the conclusions they sell.
Adversary tracking and intrusion trends drawn from one of the largest endpoint fleets in the industry. Read past the framing for the telemetry.
Frontline incident-response data, attacker dwell times, and behavior from Mandiant (now Google Cloud) breach investigations. Among the most concrete field data published anywhere.
Frontline incident-response findings from more than 750 engagements a year across 50-plus countries.
Nation-state and cybercrime telemetry gathered at Microsoft's scale, one of the widest vantages in the industry.
Threat research and quarterly incident-response trends from one of the largest commercial intelligence teams.