This file records the most consequential missing piece in the corpus. Three hundred files describe data leaving organisations. A separate body of statistics describes fraud reaching people. Nothing connects them.
The Trace Does Not Exist At Any Point
A person defrauded in November cannot know which of the dozen breaches they were notified about supplied the details. The bank processing the disputed transaction has no visibility into it. The breached organisation learns nothing about downstream outcomes and has no obligation to look.
Even where data is later published, matching a leaked record to a specific fraudulent act would require access to both, held by parties with no relationship and every reason not to share.
Which Leaves The Central Claim Unproven
The entire justification for breach notification, for regulatory penalties, for the settlements at 25-1228, rests on the proposition that exposure produces harm.
That proposition is almost certainly true and it is not demonstrated. This desk believes it — the corpus would be pointless otherwise — and has to record that the belief rests on plausibility rather than evidence, because saying so is the difference between reporting and advocacy.
The Gap Is Exploited In Both Directions
A breached organisation can honestly say no confirmed misuse has been identified, because identification is impossible. That is technically accurate and functions as reassurance it has not earned.
And the security industry attributes fraud growth to breach volume without evidence, because the correlation is convenient. Both sides are arguing from the same absence.
What Would Close It
A fraud report that captured which breaches the victim had been notified of. A requirement that issuers record suspected source. A longitudinal study following notified populations against matched controls.
None is technically difficult. All require somebody to decide the question is worth answering, and the parties positioned to answer it — banks, breached organisations, credit bureaux — are the parties least served by the answer.
This desk records it as the open question the corpus cannot close, and the one that would change most of what is in it.
It describes a limitation of this database and of the evidence base generally. Sources below support the two datasets it contrasts; the absence of a bridge between them is not something any source measures. Corrections: corrections@forensicpost.com.
- Consumer Sentinel Network data bookFederal Trade Commission
- 2025 identity theft statistics: a record year for fraudOmniwatch
- Identity theft statisticsReview42