Glossary
Plain-language definitions for the terms used across the site. See Methodology for the full confirmation ladder and source list.
Attack types (26)
Every attack-type classification tracked, each mapped to MITRE ATT&CK technique IDs and, where available, a VERIS category. See Attack types for incident counts per type.
- Backup Destruction
- Cloud Storage Breach
- Code Injection
- Credential Theft
- Data Destruction
- Data Exfiltration
- Data Interception
- Denial of Service
- Hacking/IT Incident
- Improper Disposal
- Lateral Movement
- Loss
- Malware Deployment
- Phishing Attack
- Privilege Abuse (Insider)
- Privilege Escalation
- Ransomware Attack
- SQL Injection
- Session Hijacking
- Social Engineering
- Supply Chain Compromise
- Theft
- Unauthorized Access/Disclosure
- Unknown
- Unsecured Credentials
- Web Application Exploitation
Data types
The categories an incident’s reported data types can fall into. Four of the ten (address, date of birth, name, other) have no incident-specific guidance step on a Was I affected? page beyond the generic advice every incident already shows; the other six do.
ssnfinancial-accountdrivers-licensegovernment-idmedicalhealth-insuranceaddressdobnameother
Regulators (24)
Data protection and financial regulators tracked. See Regulators for published enforcement-action counts per regulator.
- Agencia Espanola de Proteccion de Datos
- Autoriteit Persoonsgegevens
- Bundesbeauftragte fuer den Datenschutz und die Informationsfreiheit
- California Attorney General
- Commission Nationale de l'Informatique et des Libertes
- Cybersecurity and Infrastructure Security Agency
- Data Protection Commission
- Datatilsynet
- European Data Protection Board
- Financial Conduct Authority
- Garante per la protezione dei dati personali
- Information Commissioner's Office
- Maine Attorney General
- Massachusetts Attorney General
- National Cyber Security Centre
- New Hampshire Attorney General
- Oregon Attorney General
- Prudential Regulation Authority
- Texas Attorney General
- US Department of Health and Human Services Office for Civil Rights
- US Federal Trade Commission
- US Securities and Exchange Commission
- Vermont Attorney General
- Washington Attorney General
Confirmation levels
The five confirmation levels, in ascending order of certainty. See Methodology for the full confirmation ladder, including which levels actually confirm an incident.
- Claim
- Press reported
- Self report
- Regulator
- Court