DisclosureLens
Feed News/Feed status · Illinois AG

Illinois Keeps a 5,300-Record Breach Register. No Search Engine Has Ever Seen It.

Illinois runs a live breach-notification register — 5,319 records and growing by nearly a thousand a year — behind a wall that turns away every crawler, archive, and AI on the internet. A person can read it. A machine cannot. We obtained the register; here is what's inside.

By DisclosureLens · August 23, 2026
Watch · live status unavailableSource: state_ag_illinois
Last capture
August 17, 2026
Poller
Live and growing — closed to machines
Holdings
0 records
Last checked

The badge and figures above are read live from /v1/health/sources on each render. Monthly re-probe of the portal's robots.txt and human-check posture; if the gate opens, Illinois goes straight to collection.

Most of the breach registers we cover fail by going dark, going quiet, or deleting their own history. Illinois fails in a way we hadn't catalogued before: its register is alive, well-maintained, and better-populated than most states' — and it is structurally invisible. Not hidden from people; a person with a browser can search it today. Hidden from everything else. No search engine has ever indexed a record. No web archive has ever preserved one. If you have never heard of it, that is the design working.

What's there. The export we obtained in mid-August holds 5,319 notifications from 2,910 companies, spanning September 2001 to early August 2026. Intake is accelerating: 828 filings in 2023, 990 in 2024, 911 in 2025, and 2026 on pace for over a thousand. Two fields stand out. A discovery date — the day the company says it learned of the breach, the field every disclosure-timing question turns on — is present on 99.9% of records, published by the regulator itself. And 81% of records carry the underlying documents, near-total for recent years. This is not an archive slowly rotting on a forgotten server. It is one of the more complete breach registers in the country.

What's in the way. The portal's robots.txt disallows everything for everyone, then names names anyway: Googlebot, Bingbot, GPTBot, CCBot, Amazonbot, each individually told no. The search grid sits behind an interactive “verify you are human” checkbox that the server enforces. The Wayback Machine first reached the portal in May 2025 and has captured exactly zero records — the register loads its data in a way archive crawlers structurally cannot follow — and the state's open-data portal carries no copy. The AG's own pages do link the portal, but through JavaScript click-handlers that no crawler follows as links. Add it up and the register exists only in the moment a human looks at it. Nothing else on the internet can prove what it says, or said.

What the law withholds. One number is missing from every record, and not by accident. Illinois' breach statute spells out what the Attorney General may publish: the company's name, the types of personal information compromised, and the date range of the breach. That list is the portal, exactly. The number of people affected is in the AG's files — the same statute requires companies to report it — but it is not on the list the office may publish, so no record carries it. Getting that number out of Springfield is a public-records question, not a data question.

The quiet side door. The strangest thing in the register comes from a compliance shortcut. Illinois law lets a HIPAA-covered entity satisfy the state by simply forwarding a copy of the breach report it already sent to federal regulators — and that pathway has no size threshold. Federal law requires reporting every health-data breach, but HHS's public “Wall of Shame” only shows breaches of 500 people or more; in our entire HHS corpus of nearly 8,000 records, the smallest count is exactly 500. The Illinois filings we examined under this pathway were stamped “Fewer Than 500 Individuals” — one Chicago-area health system's report covered a single person. In other words, Illinois holds copies of the sub-500 health-data breaches that are invisible even on the federal register built to disclose them. How much of the 5,319 that pathway accounts for, nobody outside the AG's office knows — the register carries no filer-type flag, and we won't guess.

The terms forbid nothing. Here is the oddity we keep turning over: the portal publishes no terms of use. Every terms, disclaimer, and policy path we tried comes back empty; the only binding language anywhere is a boilerplate clause requiring use to conform to applicable law. No anti-scraping term, no bulk-access term, no commercial-use restriction — nothing. The robots.txt and the human-check express an intent that no rule the state actually wrote ever codified. A member of the public pressing the site's own export button breaks no term the site asks anyone to accept.

How we're watching. We do not crawl Illinois, and we won't: defeating a bot check is a line we don't cross, whatever the terms fail to say. What we hold is a register snapshot exported by hand through the site's own export button — the source of every figure above — and when we compared its companies against our corpus in mid-August, roughly 1,250 of them appeared in no other register we track. That is a lot of disclosure that exists nowhere else. So Illinois sits on our watch list: we re-check the portal's posture on a standing schedule, and if the gate ever opens — a robots change, a bulk channel, an API — it goes straight into collection. Until then, this page is the only place most of the internet will learn the register exists.

Update log

  1. August 23, 2026
    Filed

    Register posture re-verified on publication day: robots.txt still disallows all crawlers by name, the human-check still gates the search grid, the Wayback Machine still holds zero record captures, and the state open-data catalog still returns nothing for the register. And the census check passed: a person at the search grid read its own total — 5,337 records, eighteen more than our 2026-08-17 export, exactly the ~3-filings-a-day growth the intake rate predicts. The export was a complete copy as of its date.

DisclosureLens tracks the state of every source it collects, not just the records. When this feed changes — restored, relocated, or gone for good — we log it here and notify subscribers. Browse the preserved per-state archives under /breach-notifications.

The Disclosure Clock · weekly briefing

Everything on this page starts as a weekly measurement: the race between the criminals who post a breach and the regulators who record it, and the health of the registries themselves. Get the reading in your inbox.

Weekly. Double opt-in, one-click unsubscribe, and the address goes nowhere else.