Last updated Aug. 30, 2026
DysruptionHub reports on cyber incidents and technology outages that disrupt essential services, public institutions and business operations in the United States. These standards describe how we gather, verify, present and correct our reporting.
Accuracy and verification
Accuracy takes priority over speed. We seek confirmation through primary records, direct statements, public filings, official notices, interviews and other reliable evidence.
We distinguish confirmed facts from allegations, preliminary assessments and unresolved questions. When evidence is incomplete or contradictory, we describe the uncertainty instead of presenting a conclusion as established fact.
Cyber incidents frequently evolve after initial disclosure. We update coverage as organizations restore services, investigators release findings or other material facts become available.
Sources and attribution
We identify sources as specifically as circumstances allow and link directly to supporting material when it is publicly available.
Information obtained from government statements, regulatory filings, court records, public meetings, corporate disclosures, social media posts and other documents is attributed to its original source.
When another news organization originates information used in our reporting, we credit and link to that outlet. We write in our own words and seek to add value through verification, operational-impact analysis, additional sourcing, historical context or connections identified through the DysruptionHub Cyber Incident Registry.
Press releases and public statements are treated as sources, not finished journalism. Their claims are evaluated, attributed and supplemented when possible.
Anonymous and confidential sources
DysruptionHub prefers on-the-record sources. We grant anonymity only when the information is important, the source has a valid reason for requesting protection and the source is in a position to know the information.
An editor must know the source’s identity. Stories using anonymous sources explain, as specifically as possible, why anonymity was granted and how the source is positioned to know the information.
We seek independent confirmation of anonymously sourced information whenever possible.
Cybercrime and threat-actor claims
Claims made by ransomware groups, data-leak sites, hackers and other threat actors are treated as allegations unless independently confirmed.
A listing on a leak site does not by itself prove that an intrusion occurred, that particular data was stolen or that a named organization was affected as claimed. Our reporting describes the available evidence, the organization’s response and the limits of what can be verified.
We do not publish stolen personal information, passwords, access credentials or other material that would unnecessarily expose victims or increase security risks. We do not link directly to malicious downloads or active extortion infrastructure.
Fairness and responses
We make a meaningful effort to contact organizations and people facing significant allegations or potentially damaging claims. When they do not respond by publication time, we say so when relevant.
Urgent public-interest reporting may be published before every party responds, but subsequent responses are evaluated and added when they materially advance or correct the story.
We do not give sources the right to approve articles before publication. We may verify technical details, quotations or specific factual information with a source.
Bylines and accountability
Bylines identify the journalist or newsroom unit responsible for an article.
A named byline is used when an individual substantially reports, analyzes or writes an article. Original reporting may include interviews, direct outreach, public meetings, government records, court filings, data analysis, technical evidence or other independently reviewed primary sources. It does not require an interview or an exclusively obtained quotation.
The DysruptionHub Staff byline is reserved for routine briefs based primarily on official announcements or previously published information, recurring newsroom products and collective work for which no individual made the predominant journalistic contribution.
When multiple journalists make substantial, identifiable contributions, DysruptionHub uses joint bylines or contributor credits rather than defaulting to the Staff byline. Personal analysis, commentary and opinion carry the writer’s name.
A byline and an “Original Reporting” designation serve different purposes. The byline identifies who did the work. The designation indicates that DysruptionHub independently uncovered or materially developed information. Reporting may be original even when the underlying meeting, document or dataset was publicly accessible.
The editor approving an article is responsible for its accuracy, sourcing, framing and publication. Artificial intelligence and automated tools are not credited as authors and do not determine the byline.
Corrections, clarifications and updates
We correct factual errors promptly and transparently.
A material correction is labeled “Correction” and explains what was wrong and what has been corrected. We do not use euphemisms such as “update” or “clarification” to conceal an error.
A clarification may be added when the original information was accurate but could be misunderstood or lacked important context. Material developments added after publication may be identified in an update note.
Routine spelling, grammar, formatting and link repairs that do not change meaning may be made without a correction note.
Correction requests should include the article URL, the disputed information and supporting evidence. Send requests to [email protected].
Data and the Cyber Incident Registry
Registry records are built from public sources and are updated as new information becomes available. Status, confidence and attribution labels reflect the evidence available at the time of review and may change.
We evaluate data for reliability, currency, scope and potential bias. When publishing original data analysis, we explain the methodology, important limitations and definitions needed to understand the findings.
The absence of an incident from the registry does not establish that no incident occurred. Inclusion does not necessarily mean every reported claim has been independently confirmed.
Artificial intelligence and automation
DysruptionHub may use automation and artificial intelligence-assisted tools to identify leads, organize research, transcribe material, analyze data, summarize source documents and assist with drafting or editing.
AI-generated output is not treated as a source. Factual claims must be verified against reliable evidence before publication. A human editor reviews all published editorial content and remains responsible for its accuracy, sourcing, context and final presentation.
We disclose the use of automation when it materially shapes a published work in a way readers would reasonably want to know. Artificial intelligence is not credited as an author.
Images and visual material
Images must accurately represent the subject of an article and must not imply that visual evidence exists when it does not.
Our image selection reflects DysruptionHub’s focus on the real-world consequences of cyber incidents and technology outages. Whenever possible, the primary image anchors the reporting to something tangible: a place, building, sign, vehicle, product or other physical subject connected to the disruption. This approach helps readers understand where a digital incident reaches people and operations without suggesting that the photograph depicts the attack itself.
We prefer documentary images connected to the reporting. When no suitable image is available, we may use a clearly identified file photo, map, official record or explanatory graphic, or publish the article without a feature image.
Captions identify what an image shows and provide relevant context. We credit the photographer, creator, agency or source whenever that information is available and identify applicable licensing or usage information.
We do not materially alter documentary photographs. Normal cropping, sizing, color correction and other limited adjustments may be used when they do not change an image’s meaning.
We do not use AI-generated images merely to decorate hard-news articles. Synthetic depictions provide no evidence of what occurred and can leave readers with a false impression of the affected organization, its systems, the attackers or the incident itself. An AI-generated illustration may be used when it serves a clear editorial purpose, cannot reasonably be mistaken for documentary evidence and is prominently labeled.
File photos, illustrations and composites are also labeled when their nature may not otherwise be clear. We avoid generic cybersecurity imagery that could misleadingly associate a person, system or organization with criminal activity.
Screenshots and source-provided material
Screenshots, video and other visual material supplied by organizations, officials, researchers, witnesses or other sources are treated as source material rather than automatically accepted as independent evidence. We seek to verify their authenticity and context, identify who provided them and disclose material limitations. Screenshots are labeled as such and, when relevant, identify the originating page, account, document or system.
Material published by ransomware groups, hackers or other threat actors is treated as a claim. Its publication does not establish that the material is authentic or that the threat actor’s broader claims are true. We use only what is necessary to report the news and avoid unnecessarily amplifying extortion demands, propaganda, stolen information or links to malicious infrastructure.
We may crop, mask, blur or redact visual material to protect personal information, access credentials, security-sensitive details, victims and other people who could face unnecessary harm. We may also obscure graphic, obscene or gratuitously disturbing content when the underlying material remains newsworthy. When practical, we prefer cropping or withholding an image to altering it.
Material redactions or alterations are disclosed in the caption or accompanying text. They must not change the meaning of an image, conceal information necessary to understand the reporting or create a misleading impression of the original material.
We balance newsworthiness against privacy, dignity, safety and the risk of enabling further harm. Possessing or having access to an image does not by itself justify publishing it.
Independence, funding and conflicts
DysruptionHub is published by ColTex Media LLC and is supported by readers, subscriptions and other disclosed revenue.
Advertisers, sponsors, partners and financial supporters do not control editorial conclusions. Paid or sponsored material is clearly labeled and visually distinguishable from independent reporting.
Writers and editors must disclose financial, professional or personal interests that could reasonably raise questions about their coverage. A conflict may be disclosed in the article, reassigned or handled through another appropriate editorial measure.
We do not accept payment in exchange for favorable editorial coverage or the removal of accurate reporting.
Originality and copyright
We do not knowingly plagiarize or present another publisher’s work as our own. Quotations and information from other sources are limited to what is necessary, attributed and used with appropriate context.
DysruptionHub’s original text is protected by copyright. Brief quotations may be used with clear attribution and a link to the source article.
Contact us
Tips, corrections and media inquiries may be sent to [email protected].
Security-sensitive communications may be sent to [email protected].