Alleged breaches are unconfirmed breach claims that SecurityScorecard surfaces on scorecards to provide early-warning visibility. These signals come from two sources: news reporting from outlets SecurityScorecard already monitors for confirmed breach coverage, and ransomware.live, a leak-site tracker that aggregates claims made by ransomware groups (including reporting from dark web and forum activity). No official or regulatory disclosure has confirmed the event at this stage.
We use these sources because they're prevalent in the cyber community, have a history of early breach reporting that was later confirmed, and aggregate more dispersed claims sites. If you would like to submit an additional source for consideration, please reach out to Support!
Alleged breaches do not affect your security score. If corroborating evidence emerges (e.g., additional reputable news sources report the same event, or a government authority issues a disclosure), SecurityScorecard automatically promotes the alleged breach to a confirmed breach. At that point, the standard breach scoring penalty applies.
Types of alleged breaches
SecurityScorecard distinguishes between two types:
- Alleged First-Party Breach: Evidence suggests the organization itself may have been breached by a threat actor, though this has not yet been confirmed by official or regulatory disclosure.
- Alleged Third-Party Breach: Evidence suggests the organization may have been impacted as a result of a breach in their supply chain, though this has not yet been confirmed by official or regulatory disclosure.
View an alleged breach in the platform
Alleged breaches are surfaced in the Issues table so you can monitor and investigate emerging threats before they are formally confirmed.
To check whether your organization or a vendor has an alleged breach:
- Your organization: Go to My Organization > My Scorecard > Issues and look for the Alleged Breach Originator or Alleged Breach Impacted row.
- A vendor: Go to Companies, select the company you want to review, and select Issues, then look for the Alleged Breach Originator or Alleged Breach Impacted row.
The Findings tab lists the underlying finding, including its status, a description of the alleged incident, and the impacted domain. Similarly to other issue types, clicking the row opens a detailed view of the incident, showing the threat level, breach risk, and overall score impact, which will show as 0.0, confirming the alleged breach has no effect on your score.
What you should do
If an alleged breach appears on your scorecard or a vendor's scorecard:
- Investigate the claim - Review the source information provided with the finding to determine if the claim can be substantiated.
- Monitor for corroboration - Watch for additional reporting from reputable sources, government disclosures, or the affected organization's own acknowledgment.
- Assess supply chain impact - If the alleged breach involves a vendor in your supply chain, consider reaching out to that vendor to determine whether your data may be affected.
- Dispute if inaccurate - If the finding is attributed to the wrong organization or is demonstrably false, you can submit a dispute using the resolution options: misattribution or false positive.