Most of the breach registers we cover fail by going dark, going quiet, or deleting their own history. Illinois fails in a way we hadn't catalogued before: its register is alive, well-maintained, and better-populated than most states' — and it is structurally invisible. Not hidden from people; a person with a browser can search it today. Hidden from everything else. No search engine has ever indexed a record. No web archive has ever preserved one. If you have never heard of it, that is the design working.
What's there. The export we obtained in mid-August holds 5,319 notifications from 2,910 companies, spanning September 2001 to early August 2026. Intake is accelerating: 828 filings in 2023, 990 in 2024, 911 in 2025, and 2026 on pace for over a thousand. Two fields stand out. A discovery date — the day the company says it learned of the breach, the field every disclosure-timing question turns on — is present on 99.9% of records, published by the regulator itself. And 81% of records carry the underlying documents, near-total for recent years. This is not an archive slowly rotting on a forgotten server. It is one of the more complete breach registers in the country.
What's in the way. The portal's robots.txt disallows everything for everyone, then names names anyway: Googlebot, Bingbot, GPTBot, CCBot, Amazonbot, each individually told no. The search grid sits behind an interactive “verify you are human” checkbox that the server enforces. The Wayback Machine first reached the portal in May 2025 and has captured exactly zero records — the register loads its data in a way archive crawlers structurally cannot follow — and the state's open-data portal carries no copy. The AG's own pages do link the portal, but through JavaScript click-handlers that no crawler follows as links. Add it up and the register exists only in the moment a human looks at it. Nothing else on the internet can prove what it says, or said.
What the law withholds. One number is missing from every record, and not by accident. Illinois' breach statute spells out what the Attorney General may publish: the company's name, the types of personal information compromised, and the date range of the breach. That list is the portal, exactly. The number of people affected is in the AG's files — the same statute requires companies to report it — but it is not on the list the office may publish, so no record carries it. Getting that number out of Springfield is a public-records question, not a data question.
The quiet side door. The strangest thing in the register comes from a compliance shortcut. Illinois law lets a HIPAA-covered entity satisfy the state by simply forwarding a copy of the breach report it already sent to federal regulators — and that pathway has no size threshold. Federal law requires reporting every health-data breach, but HHS's public “Wall of Shame” only shows breaches of 500 people or more; in our entire HHS corpus of nearly 8,000 records, the smallest count is exactly 500. The Illinois filings we examined under this pathway were stamped “Fewer Than 500 Individuals” — one Chicago-area health system's report covered a single person. In other words, Illinois holds copies of the sub-500 health-data breaches that are invisible even on the federal register built to disclose them. How much of the 5,319 that pathway accounts for, nobody outside the AG's office knows — the register carries no filer-type flag, and we won't guess.
The terms forbid nothing. Here is the oddity we keep turning over: the portal publishes no terms of use. Every terms, disclaimer, and policy path we tried comes back empty; the only binding language anywhere is a boilerplate clause requiring use to conform to applicable law. No anti-scraping term, no bulk-access term, no commercial-use restriction — nothing. The robots.txt and the human-check express an intent that no rule the state actually wrote ever codified. A member of the public pressing the site's own export button breaks no term the site asks anyone to accept.
How we're watching. We do not crawl Illinois, and we won't: defeating a bot check is a line we don't cross, whatever the terms fail to say. What we hold is a register snapshot exported by hand through the site's own export button — the source of every figure above — and when we compared its companies against our corpus in mid-August, roughly 1,250 of them appeared in no other register we track. That is a lot of disclosure that exists nowhere else. So Illinois sits on our watch list: we re-check the portal's posture on a standing schedule, and if the gate ever opens — a robots change, a bulk channel, an API — it goes straight into collection. Until then, this page is the only place most of the internet will learn the register exists.