Evidence-led intelligence · rolling 90-day view
Cyber Incident Impact Areas
An impact area describes what a cyber incident actually caused, not how the attacker operated. Shadow Tier classifies an impact only when current reporting or precise upstream VERIS evidence confirms the consequence.
Published guides
Which cyber incident impacts can you explore?
Data Exposure & Data Breach News
Track confirmed data exposure, data leaks, data theft and data breaches with current incidents, affected sectors and practical response guidance.
Explore current impact intelligence →Cyber Service Disruption & Outage News
Follow confirmed cyber-related outages, unavailable services and operational interruptions with current evidence and practical resilience guidance.
Explore current impact intelligence →How can you browse other classified impacts?
Use these filters to focus the current incidents on a specific consequence, including data exposure, service disruption, data integrity issues and financial loss.
Current signals
Which financial loss signals are visible now?
No matching classified signals are visible in the current 90-day window.
The view updates when new evidence becomes available.
FAQ
How does Shadow Tier connect incidents to impacts?
What evidence is required?
The title or summary must explicitly confirm the impact, or a precise upstream VERIS attribute must support it.
Why separate attack and impact?
Ransomware, phishing and exploitation describe actions. Exposure and disruption describe consequences and require their own evidence.
Can one incident have several impacts?
Yes. The same incident can expose data, interrupt services, undermine data integrity and cause financial loss when the available evidence supports each consequence.
