Alleged breaches are unconfirmed breach claims that SecurityScorecard surfaces on scorecards to provide early-warning visibility. These signals originate from unverified sources, such as social media posts, hacker forums, ransomware feeds, and dark web threat-actor claims, where no official or regulatory disclosure has confirmed the event.
Alleged breaches do not affect your security score. If corroborating evidence emerges (e.g., additional reputable news sources report the same event, or a government authority issues a disclosure), SecurityScorecard automatically promotes the alleged breach to a confirmed breach. At that point, the standard breach scoring penalty applies.
Types of alleged breaches
SecurityScorecard distinguishes between two types:
- Alleged First-Party Breach - Evidence suggests the organization itself may have been breached by a threat actor, though this has not yet been confirmed by official or regulatory disclosure.
- Alleged Third-Party Breach - Evidence suggests the organization may have been impacted as a result of a breach in their supply chain, though this has not yet been confirmed by official or regulatory disclosure.
View an alleged breach in the platform
Alleged breaches are surfaced in the Issues table so you can monitor and investigate emerging threats before they are formally confirmed.
To check whether your organization or a vendor has an alleged breach:
- Your organization: Go to My Organization > My Scorecard > Issues and look for the Alleged Breach Originator row.
- A vendor: Go to Companies, select the company you want to review, and select Issues, then look for the Alleged Breach Originator row.
The Findings tab lists the underlying finding, including its status, a description of the alleged incident, and the impacted domain. Similarly to other issue types, clicking the row opens a detailed view of the incident, showing the threat level, breach risk, and overall score impact, which will show as 0.0, confirming the alleged breach has no effect on your score.
What you should do
If an alleged breach appears on your scorecard or a vendor's scorecard:
- Investigate the claim - Review the source information provided with the finding to determine if the claim can be substantiated.
- Monitor for corroboration - Watch for additional reporting from reputable sources, government disclosures, or the affected organization's own acknowledgment.
- Assess supply chain impact - If the alleged breach involves a vendor in your supply chain, consider reaching out to that vendor to determine whether your data may be affected.
- Dispute if inaccurate - If the finding is attributed to the wrong organization or is demonstrably false, you can submit a dispute using the resolution options: misattribution or false positive.