Desk live·
ForensicPost
Breaches/Verification/File 25-0502

Why the Incident Record Is Mostly American

Four structural filters decide which incidents anywhere in the world become part of the public record. All four favour the same handful of jurisdictions.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetIncident record formation
ActorUnattributed
D. Kennedy12 min readConfidence: medium2 sources reviewed

This method file sets out why an incident in one country enters the public record and an equivalent incident in another does not.

First: A Disclosure Obligation Must Exist

Mandatory breach notification with defined triggers and public filing is not universal. Where it does not exist, disclosure is voluntary, and organisations that suffer incidents rarely volunteer.

The healthcare register at 25-0630 is the clearest demonstration: a sector produces 343 filings in six months because it is compelled to, while equivalently affected sectors produce nothing.

Second: Somebody Must Be Able To Sue

The 1,900 US class actions at 25-1228 generate court filings, settlement notices and legal reporting — a substantial secondary record built on top of the notification.

Jurisdictions without collective redress produce a notification and then silence, so an incident of identical severity leaves a fraction of the documentary trace.

Third: A Security Research Industry Must Be Watching

Much of this corpus rests on vendor research, leak-site monitoring and threat intelligence — commercial activity concentrated where the customers are.

A leak-site listing naming a company in a market those vendors sell into gets written up. One naming a company elsewhere frequently does not, which is why the file at 25-0528 has a group name, a month and nothing else.

Fourth: It Must Be Reported In A Language The Record Is Kept In

This desk reports in English and reads sources in English. An incident covered thoroughly in Japanese, Hindi or Bahasa Indonesia is invisible to this corpus unless somebody translates it.

That is the plainest limitation of all and the one least often stated by databases of this kind.

The Compounding Effect

Each filter individually is defensible. Together they mean the world’s incident record is approximately the incident record of the jurisdictions that legislate disclosure, litigate breaches, host security vendors and publish in English.

The correct inference from a sparse national record is that the country lacks the four filters, not that it lacks incidents. Nothing in this corpus should be read as evidence about relative national exposure.

This is a method file

It describes how the public incident record forms, supported by the sources listed below and by the composition of this database. Corrections: corrections@forensicpost.com.

Sources
  1. Wrapping up 2025: global data breach statisticsSurfshark
  2. Asia-Pacific strives to keep pace with cyber threatsCrowell & Moring
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary