At 25-1005b this desk recorded that the JLR supply-chain firms entered the public record through proximity to a large incident, and called that a sixth route — an accident rather than a mechanism.
The MSP cases supply a seventh: shared provider compromise. Twenty asset managers and an unenumerated set of DragonForce victims became visible because a single provider was named.
It Works Better Than The Accidental Route
Proximity to a large incident requires the upstream event to be enormous. Provider compromise requires only that researchers identify the provider — which they generally do, because a shared vector is the most publishable part of the story.
So a small firm compromised through its MSP has a meaningfully higher chance of appearing in the record than one compromised directly, at identical severity.
Which Distorts The Record In A Specific Direction
If small-firm incidents become visible mainly when a provider is involved, then the visible portion over-represents provider-mediated compromise and under-represents everything else.
The national survey at 25-0615b found 84% of organisations reporting phishing as their most common attack — a direct route with no provider to name. That is the invisible majority, and this database contains almost none of it.
The Corpus Has Now Named Seven Routes
Mandatory notification, collective redress, research industry coverage, English-language publication, securities listing, proximity to a large incident, shared provider compromise.
Only the first five are mechanisms anyone designed. The last two are consequences of how research and journalism work, and they are the only ones reaching organisations below a certain size.
Graded medium: this is a structural argument about the database, extending 25-0502, 25-0924b and 25-1005b.
It extends the record-formation argument in this database using the MSP incidents above. Corrections: corrections@forensicpost.com.
- Qilin ransomware turns South Korean MSP breach into 28-victim Korean Leaks data heistThe Hacker News
- MSPs: the increasing targets in supply chain attacksMSP Channel Insights