Why BreachHistory?
Public breach disclosures are scattered across regulators, press rooms, and security blogs. BreachHistory exists to turn that noise into a structured, searchable record you can trust for due diligence, education, and incident response context.
The problem we solve
When a vendor, school district, or healthcare provider is hit by ransomware, the facts rarely arrive in one place. A state AG filing may appear weeks before a company blog post; criminal leak sites market claims before forensic reports land. Security teams, journalists, procurement officers, and researchers all need the same baseline questions answered: what happened, when, how many people were affected, and what data classes were involved?
BreachHistory aggregates those answers into company timelines and individual incident pages so you do not have to rebuild context from scratch every time a headline breaks.
Who uses BreachHistory
- Security and GRC teams — vet third-party risk, compare recurrence patterns, and support questionnaires with cited disclosures.
- Procurement and legal — review vendor breach history before renewals, M&A diligence, and contract negotiations.
- Journalists and researchers — trace incident timelines with links to primary sources and consistent record counts.
- Developers — integrate breach metadata through our REST API where tier access allows.
- Everyday users — check whether an organization they trust has disclosed incidents and understand scale in plain language.
What makes our approach different
We prioritize disclosed incidents—regulatory notifications, company statements, and reputable reporting—rather than republishing unverified criminal forum claims without context. When OSINT-only rows are included, we label them clearly so you can separate marketing from confirmation.
Each company page combines chronological breaches, estimated records affected, root-cause summaries when known, AI Breach Risk scores as a structural signal, and technical writeups with reference links. That structure helps search engines and humans alike understand how incidents relate over time.
Transparency and responsible use
BreachHistory is an intelligence reference, not legal or insurance advice. We encourage corroboration with primary sources, respectful handling of victim privacy, and ethical use in vendor assessments—not harassment or sensationalism.
See errors? Use Report a breach or Contact with documentation. Explore the full BreachHistory platform, read our blog, or start searching from the homepage.