Digibastion collects security incidents and news from the sources below, merges reports of the same incident into one record, and shows the status each source gives. We do not investigate or verify incidents ourselves, so every record links back to where it came from.
What do confirmed and unconfirmed mean? Unconfirmed means the source has reported the incident but has not verified it. The details, the date and the loss figure may change, and some reports are withdrawn. Confirmed means the source has marked the incident as verified. Digibastion shows that status as the source gives it. Items with neither label come from sources that do not publish a verification status.
How are duplicate reports merged? Several trackers often report the same incident. We treat two reports as one incident when the project name matches and either the incident dates are the same day, or they are within two days of each other and the reports agree on the loss amount, the attack method or a reference link. A loss of zero does not count as a match. Each incident keeps one record, and every report we merged into it is listed as a source on that record. When sources disagree, QuillMonitor comes first, then the other incident trackers, then SlowMist.
Which dates does an incident record show? Each incident shows two dates: when it happened, as the source reports it, and when we added it. When a source gives no usable date, the record says the date is unknown rather than guessing.
How do I report a mistake? If something is wrong, email support@digibastion.com with the incident link, what is wrong, and a public source for the correct information. We fix our own errors. When the error comes from a source, we tell that source and update the record when they correct it.