Case file

Every claim naming one organization, across groups, in chronological order — who claimed it, when, and how long between claims.

Search for an organization to inspect its cross-group claim timeline with claimant groups, observed publication timestamps (UTC), and inter-claim intervals. Timestamps are provider observation times, not attack timing, and no entry is a confirmation.

How the organization case file works

Search resolves an organization to its canonical identity, then lists every provider-observed claim naming it — across all groups — in chronological order of observed publication (UTC), with the claimant group and the interval since the previous claim.

Timestamps are provider observation times, not attack timing: a claim observed today can describe an alleged intrusion from months earlier, and providers can backdate claim dates. The case file keeps discovery time and provider-reported claim dates distinct rather than merging them.

Example: reading this page correctly

Example reading: an organization with claims from two groups eight months apart supports the statement "two groups published claims naming this organization, eight months apart as observed" — re-victimization, data resale, and a false second claim all remain possible and the timeline does not choose between them.

Frequently asked questions

Does a case file confirm an organization was breached?
No. It aggregates unverified allegations. Where a claim carries an authority-confirmed badge, an official breach report exists — which still confirms the official report, not the group's specific claim.
What does the interval between claims tell me?
Only the elapsed time between observed publications. Short intervals across groups often accompany contested claims; long intervals may suggest separate events — the case file surfaces the spacing and asserts nothing further.
An organization I searched for is missing — why?
The case file covers organizations named in provider-observed claims in this dataset. Absence means no tracked provider observation names it, not that it was never attacked.

Data freshness

Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.

Related pages

Explore the tracker

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.