ThreatPaperBeta

Rating Methodology

Every paper published here assesses the specific claims made about the incident it covers, rather than restating them. Each assessed claim gets its own rating, its own explanation, and its own page, so it can be cited on its own.

The ratings are deliberately not a simple true/false pair. Most disputed claims about a cyber incident are neither: they are assessments published at a stated confidence by a vendor, or assertions repeated so often that their absence of evidence stops being noticed. Collapsing those into “true” or “false” loses the thing that actually matters.

Two distinctions do most of the work. Assessed is not Verified: an intelligence vendor naming a nation state at moderate confidence is reporting its own judgment, and repeating it as established fact misrepresents the source. And Unverified is not False: one means nothing published supports the claim, the other means the authoritative record contradicts it. Only the second is a correction.

Verified5 / 5

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

Assessed, Not Confirmed4 / 5

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

Weak Evidence3 / 5

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

Unverified2 / 5

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

Superseded2 / 5

Reported accurately at the time, then corrected by the original source. Recorded because the original version usually continues circulating long after the correction.

False1 / 5

Contradicted by primary sources. Reserved for claims checked directly against the authoritative record — an advisory that does not exist, a catalogue that does not list the entry, a directive that says something other than what is reported.

Source hierarchy

Primary sources come first: the original disclosure, court filings and indictments, government advisories and vulnerability catalogues, regulatory notifications, and first-party incident reports from the affected organisation or its incident responders.

Vendor research is treated as a source of assessments, reported with the vendor named and its confidence stated. News coverage is used to locate primary sources, not as a source in itself. Where a claim traces back only to other reporting, it is rated Unverified however widely it has been repeated.

When an assessment changes

Ratings are revisited when new primary sources appear, and a changed rating is recorded in the corrections log rather than applied silently. A claim rated Superseded is one where the original source itself issued the correction.

If you believe a rating here is wrong, report it. Corrections are published.