DisclosureLens

Weekly briefing

The Disclosure Clock

There is a race in the breach record that nobody times. A ransomware crew lists a company on its leak site; weeks or months later, that company files a notice with a state attorney general, HHS, or the SEC. We link the two records and time the gap — every week, on the whole record, with the method shown.

Weekly. Double opt-in, one-click unsubscribe, and the address goes nowhere else.

The clock, re-timed

How often the criminals’ post came before the first filing, and by how many days — this week’s reading against last week’s, on one stated method.

What landed

The cyber 8-Ks, state AG notices, HHS reports and enforcement decisions that arrived, and the leak-site claims that were finally answered by a filing.

One thing worth forwarding

A single measured finding from the corpus — who names the attacker, which regulator hears first, how a supplier breach drips downstream — with the caveats attached.

What it reads like

The small print, up front

A leak-site entry is a criminal group’s claim, not a confirmed breach; the briefing says “posted” and “listed” and reserves “breach” for the filings. Counts are floors: only records our matching links across sources are counted, and most companies listed on leak sites never appear in any filing we observe. Nothing here is a lateness verdict on any company — state clocks run from discovery, not from a crew’s post. Leak-site data credit: ransomware.live.

You can leave with one click from any issue. Privacy.