BreachCensus

Terms

Read-only site

Breach Census is operated by the Breach Census team as a read-only site: every page and every API route is a GET request, there is no account system, and the site’s middleware rejects any write request (POST, PUT, PATCH, DELETE) outright.

What the site says, and what it doesn’t

Every confirmed incident, claim, cost figure and regulator action is a citable reading of a public source — a regulator filing, a court record, a company disclosure, a ransomware group’s own leak-site post. An incident is only shown as confirmed where a self-report, regulator or court source backs it; anything short of that bar is labelled as an unverified claim, not asserted as a breach. See Methodology for the full rule. Nothing on this site is legal advice, and nothing asserts wrongdoing beyond what the cited source states.

Accuracy and corrections

Automated ingest can misread a source or a resolution step can misattribute a record. If something is wrong, see Contact for the correction and right-of-reply process.

Licence for reuse

Derived signals, narratives and aggregates: CC BY 4.0 with attribution to breachcensus.com. Underlying regulator filings, court records and disclosures remain the property of their original publishers.

See Developers for the JSON/CSV endpoints and full dataset export this licence applies to.

No warranties, limitation of liability

The site and its data are provided as-is, without warranty of any kind, express or implied, including as to accuracy, completeness or fitness for a particular purpose. Use of the site or its data is at your own risk.