Desk live·
ForensicPost
Breaches/Analysis/File 25-1225

An Accounting of What This Database Is Not

Three hundred and forty files, overwhelmingly American and British, overwhelmingly about organisations rather than people, and overwhelmingly about incidents that were disclosed.

Constructed geometry · not a chart of case data
TargetThis database
ActorUnattributed
D. Kennedy & S. Rosler13 min readConfidence: medium2 sources reviewed

This file states what the rest of the database cannot be used to show. It is filed because a corpus that spends its time discounting other people’s figures owes the same treatment to itself.

Geographic

The overwhelming majority of files concern the United States and the United Kingdom. The reasons are set out at 25-0502 and none of them are that incidents happen there more.

Regional data at 25-1202 records cybercrime running at around 30% of all recorded crime in over half the countries surveyed across Asia and the South Pacific. This corpus contains a handful of files about that region.

Selection

Every file here describes an incident that became known. Contained incidents produce no record — the point made at 25-0807, where a company detected and isolated a ransomware intrusion on the day and appears in this database only because a sector report mentioned it.

So the database is a sample selected for failure. Generalisations here about how organisations respond are drawn from organisations whose response did not work.

Category

Availability incidents are under-covered because they produce no notification, per 26-0209. Workforce data is under-covered because no register exists, per 25-0704. Corporate information with no data subject is invisible, per 25-1204. Fraud and scams against individuals — the largest category by volume — are almost entirely absent, per 25-1122.

What remains is confidentiality incidents involving personal data at organisations subject to disclosure law. That is a narrow slice presented as a survey of a field.

Outcome

The database records what was taken and almost never what happened to the people it was taken from, because no mechanism connects the two — 25-1219.

Its central premise, that exposure produces harm, is assumed rather than demonstrated.

What It Is Good For

Structure. The concentration of data in suppliers, the identity-led route into organisations, the availability of manual fallback, the gap between compliance and security — these are structural findings that recur across sectors and jurisdictions, and they do not depend on the sample being representative.

What the corpus cannot support is any quantitative claim about where, how often, or how badly. Every number in it came from somewhere with its own agenda, and the files that survive scrutiny are the ones making arguments about how things work rather than about how much.

This is an analysis file

It describes the limitations of this database, drawing on the measurement files within it and the sources listed below. Corrections: corrections@forensicpost.com.

Sources
  1. Asia and South Pacific cyber threat assessment report 2025/2026INTERPOL
  2. Wrapping up 2025: global data breach statisticsSurfshark
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary