Editorial standards & verification
Recent Breaches is a real-time threat-intelligence news desk. We track data breaches, leaks, and extortion campaigns as they surface — often hours or days before they reach mainstream coverage — and we label every item with how well it is verified so readers can weigh it accurately. This page explains where our information comes from, how we verify and label it, and how we correct the record when we get something wrong.
How we source
Our coverage is assembled continuously from a mix of primary and secondary sources:
- Ransomware and extortion leak sites — the dark-web listings and extortion postings where groups name their victims. We monitor these continuously.
- Verified breach-notification feeds — corroborated consumer breaches we ingest from established breach-notification feeds.
- Official disclosures — company breach notifications, regulator filings, and CISA’s Known Exploited Vulnerabilities catalog.
- Credible public reporting — established security journalism and vendor research.
How our articles are produced
We are a small desk running a large pipeline, and we would rather describe it accurately than imply a newsroom we do not have.
- Automated ingest. Listings, disclosures and filings are pulled continuously from the public sources above. Each record is normalised, deduplicated against incidents we already track, and classified — threat actor, method, sector, exposed data types, severity — by deterministic rules that run off the record’s own fields.
- AI-assisted drafting. Where an incident warrants more than a stub, the article body is drafted with a large language model working from those ingested facts and the public sources attached to the record. The model writes prose; it does not decide what is true. Anything it produces is bounded by the verification label the record already carries, and articles built this way carry a visible note saying so.
- Labelling, not laundering. AI assistance never upgrades a claim. An unverified leak-site listing stays an unverified leak-site listing however well the prose reads, and the tiers below govern how it is presented.
- Human review on the record. Editors review the templates, the classification rules and the tier logic, and they review individual articles when a correction, a dispute or a right-of-reply request comes in — but not every article is read by a person before it publishes. That is the honest position, and it is why the corrections channel below is a real one that we answer.
- What AI is not used for. We do not use it to attribute an attack, to invent record counts or data types, to fabricate quotes, or to write anything about a named individual.
AI-assisted text can be wrong, and machine drafting scales mistakes as easily as it scales output. If you find one, tell us — see corrections and right of reply below. Both channels are open to anyone, and organisations named on this site have a standing right of reply whether the page was drafted by a person or not.
Our verification tiers
Every breach carries a status label near its headline. The tiers, from claim to confirmed:
A ransomware or extortion group has listed an organization on its leak site, or a claim is circulating that we have not yet corroborated. A listing is an allegation made by criminals to pressure a victim — it is not proof a breach occurred, and details (record counts, data types) are often exaggerated. We publish these because they are real-time signals of risk, clearly labelled as unverified until confirmed.
The incident is supported by public reporting — a credible news outlet, a regulator filing, a security-vendor writeup, or the organization’s own notification wording — but has not been independently confirmed by us end to end. Facts are attributed to their source.
The breach is corroborated by an official disclosure from the affected organization or ingested from a verified breach-notification feed. These are the incidents we hold to the highest evidentiary bar.
A listing is an allegation.It is not proof.We publish it as a claim, and we say so on the page.
Ransomware listings are claims, not verdicts
When a group posts a victim to its leak site, that is an unverified extortion claim until it is corroborated. Criminals inflate figures, re-list old victims, and sometimes name organizations they never breached. We report the listing as what it is — an allegation — and we say so plainly. We add context, and we update the page if the organization or credible reporting confirms or refutes it.
Recycled and re-posted data
A large share of “new” leaks are repackaged old ones — combolists and infostealer dumps stitched together from prior breaches. Where we can tell that a dataset is recycled or re-posted, we say so, and we favor the original incident over the repackaging so readers aren’t double-counting the same exposure.
Corrections & retractions
We correct errors promptly and transparently. If reporting turns out to be wrong, we fix it and, for material changes, note what changed. If a claim we reported is credibly refuted, we retract it rather than quietly deleting it. To request a correction, email press@recentbreaches.com.
Right of reply & takedowns
Any organization named on this site has a standing right of reply. We will publish your statement, correct inaccuracies, and — where a page contains personal data, or where we have asserted something we cannot substantiate — remove or de-index it on request. Send takedown and right-of-reply requests to press@recentbreaches.com; see our contact page for the full set of intents.
Reporting that a ransomware or extortion group has publicly listed an organization is a different matter, and we treat it differently. That such a listing was published is a verifiable fact about the group’s conduct, and we label these entries as unverified claims rather than confirmed breaches. We do not delete them on request, because the only remaining public account of events would then be the attackers’ own. What we will do instead, on request and without preconditions: publish the named organization’s response beside the listing, correct any specific statement shown to be inaccurate, and update the page prominently — at the top, not in a footnote — if an investigation, regulator, or forensic finding establishes the position either way, including a finding that no compromise occurred.
Ownership & independence
Recent Breaches is published by GalaxyWarden, a consumer data-removal service. We disclose that relationship on every page. Editorial decisions — what we cover and how we label it — are made independently of our commercial interests.
How we differ from breach-lookup registries
Breach-lookup registries do essential work: they catalog strictly-verified consumer breaches so people can check their exposure with confidence. Recent Breaches plays a complementary role. We are a real-time threat-intelligence news desk: we surface ransomware listings, fresh leaks, and emerging incidents the moment they appear — including unverified claims — and we label each by verification status. A registry answers “is this confirmed breach in my data?”; we answer “what is happening right now, and how sure are we?” Both are valuable.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.
