Skip to content
ThreatBharat

How we verify

Nothing is published on an analyst's word alone. This is how ThreatBharat assesses, labels, and publishes intelligence — and how we handle mistakes.

Source assessment

Every item begins with a source. We record where a signal came from and weigh its reliability. A post on a criminal forum, an official disclosure, a regulatory notice, and an independent report are not treated as equal.

Claimed vs. confirmed

We never present a source’s claim as an established fact. A threat-actor listing is reported as a claim until it is corroborated. “Claimed data breach” and “confirmed data breach” are different states, and we say which one applies.

Verification labels

Each report carries a verification label: unverified claim, corroborated, partially verified, verified, disputed, false claim, or unable to verify. The label reflects the evidence we hold at publication and can change.

Confidence

Confidence is independent of severity. A high-severity claim can carry low confidence, and vice-versa. We state both so you can weigh a report on its merits rather than its headline.

Attribution caveats

Attribution — who is behind an activity, and any reported origin or sponsorship — is shown with the stated confidence and is never presented as certain when it is not. Aliases and origins are reported claims and may be revised as evidence is corroborated.

Screenshot redaction

We do not republish original stolen material. Where an evidence derivative is shown, it is redaction-reviewed and approved first. Original screenshots, datasets, and samples are never exposed publicly.

Visibility levels

Intelligence is classified by who may see it: public, customer, analyst, and restricted. This public site shows only public, published records. Draft, customer, and restricted records are never served here.

Corrections

When a published report needs a material change, we issue a correction with a dated notice rather than silently editing the record. The report’s history is preserved.

Retractions

When a report should not have been published, we retract it transparently. The page remains as a retraction notice with its body withdrawn — we do not simply delete the record, and a retracted page never re-exposes unsafe original content.

Responsible handling

ThreatBharat surfaces exposure from public criminal claims to help defenders. It does not distribute stolen data and does not publish credentials, hidden-service links, negotiation material, or malware samples.

Affected organisations & correction requests

If your organisation is named in a report, you can contact us as an affected organisation. If you believe a published report is inaccurate, you can request a correction. We review every request.