About Breach Intelligence

Breach Intelligence is a feed for third party risk teams to identify, track, and respond to breach-related incidents based on public news sources as well as the threat underground. Events are shown chronologically for only the organizations you are subscribed to in your portfolio.

Availability

Breach Intelligence is available in both Continuous Monitoring (CM) and in all packages in Security Performance Management (SPM) except for Core.

Please note that alerts are not available in SPM for Breach intelligence at this time.

Recommended Steps

Recommended steps are generated based on a combination of event type and severity. Users should use these as a guide as they do not override their organization’s breach-responses processes. 

Screenshot of a Breach Intelligence detail panel showing an "Attack on AWS and Cloudflare by unidentified group under #OpUSA" event with recommended response steps

Filters

User are able to filter this feed on the following data sets:

Screenshot of the Breach Intelligence dashboard list view with filters and breach entries
 

Severity Types Event Types Source Types

Severity levels are assigned based on the nature of the event, as well as the volume and sensitivity of the records disclosed. Because Breach Intelligence aggregates data from both official disclosures and unofficial sources (like Telegram and Ransomware Leak Sites), these severities serve as a guide for when to trigger your internal breach response processes.

  • Critical: Evidence suggests there is a high probability that a breach has occurred and data has been exfiltrated, compromised, or encrypted. This is typically assigned when a threat actor provides "proof of work" (e.g., sample files on a leak site), when a vendor/government body confirms a large-scale compromise. Cases in which large numbers of records, particularly those that are sensitive (such as PII/PHI) also contribute to events entering this tier, and it is recommended that a breach response is triggered.
  • High: The vendor is being actively targeted by sophisticated actors (e.g., State-Sponsored or organized Cybercrime) or a critical, exploitable vulnerability is present in their environment where there may be evidence that a threat actor is targeting. While a data dump may not be public yet, the probability of compromise is high, and warrants an action on behalf of that vendor or client.
  • Medium: Events where the scope is currently "Undisclosed" or "Unknown," or where a security lapse (like an Unsecured Database) was identified but malicious exfiltration is not yet proven. These represent a failure of hygiene or a "near-miss" that suggests a degrading security posture.
  • Low: Isolated incidents with extremely limited scope (e.g., a single misdirected email) or internal incidents that were remediated without external compromise. These are indicators of human error rather than systemic infrastructure failure
Publish Date or Recent Edits
  • April 8, 2026: Expanded severity types description.
  • February 20, 2026: Published.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.