BreachCensus

About Breach Census

A global, entity-centred register of cyber attacks and data breaches — building toward company and vendor pages, ransomware group profiles, regulator actions and disclosure timelines across the US, UK and EU, each claim backed by a citable source.

What this is

Breach Census is an entity-centred register: one page per organisation, built from public regulator filings, court records and company disclosures rather than press summaries alone. Every confirmed incident, cost figure and regulator action shown on the site carries a citation back to a source document.

Who runs it

Breach Census is run by the Breach Census team as an independent, ad-hoc research project — not affiliated with, endorsed by, or sponsored by any regulator, court, company, or the vendors of the feeds it reads. Automated ingest jobs read public sources on a daily schedule; the resulting records are published as-is, with the confirmation status each one earned.

How to read a page

A page on this site is only ever as certain as its source. See Methodology for the full confirmation ladder — the short version is that a claim (a ransomware group’s leak-site listing, a rumour) is never rendered the same way as a self-report, a regulator filing or a court record, and an unconfirmed claim never earns an organisation its own page.

Data and API

The underlying register is free to reuse under Derived signals, narratives and aggregates: CC BY 4.0 with attribution to breachcensus.com. Underlying regulator filings, court records and disclosures remain the property of their original publishers. Read more, and get JSON/CSV endpoints with no key required, on Developers.