Method

# What the correction log reveals about cybercrime press releases

Every change made during re-verification is published with a reason. Read together they are a measurement of how reliable official announcements are.

Computed from the published tables at the August 23, 2026 research cutoff. Last reviewed August 23, 2026.

Every record in this index was re-verified against its cited sources, and every value that changed was written down with the reason it changed. That log now holds 1361 corrections across 106 records. It was built as an audit trail, but read sideways it is something more useful: a measurement of how reliable official announcements are about their own operations.

## What needed correcting most

| Field | Corrections |
| --- | --- |
| Geographic scope | 63 |
| Announced on | 59 |
| Started on | 53 |
| Technical outcome | 43 |
| Ended on | 40 |
| Reported apprehended count | 33 |
| Later status | 31 |
| Summary | 20 |

Dates and geography dominate, and that is the finding. Between them, 152 corrections landed on the three date fields, and 63 on which countries an action touched. These are not contested interpretive questions. They are the most basic facts about an event, and they were wrong or unsupported often enough to need fixing at that scale.

## Why announcements get dates wrong

Not through carelessness, mostly. A press release is written to announce, not to record. It says "this week" or "following a two-year investigation" because that reads well, and the reader is not expected to need a date field. When a release does give a date it is often the announcement date standing in for the operation date, and the two can be weeks apart.

Geography drifts for a related reason. Coordination releases list every participating country, which is not the same as the countries where infrastructure sat or where people were arrested. Recording the participant list as the geographic scope inflates the map, and a large share of those 63 corrections were exactly that: a scope trimmed back to what the source actually placed there.

## Counts move too

61 corrections landed on the reported people counts. Aggregate figures in announcements are frequently revised, restated across releases, or quoted from a partner agency using a different definition of the same word. Where re-verification could not establish which figure the source supported, the value became null rather than being left at a best guess.

## Every correction carries a reason

All 1361 entries record why the change was made, not just what changed. That is deliberate. A dataset that silently improves itself is indistinguishable from one that silently drifts, and the only way a reader can tell the difference is if the reasoning is on the record alongside the result.

It also means a disagreement is checkable. If you think a correction went the wrong way, the old value, the new value and the argument are all published, and you can go to the cited source and decide for yourself.

## What this does not say

It does not say official sources are unreliable in general, and it does not say anyone was misleading. Announcements are doing a different job from a database, and they are usually accurate about the thing they are announcing. The gap opens on the details a release has no reason to be precise about, which happen to be the details a structured record depends on.

Nor is the log finished. It reflects one re-verification pass against sources that were reachable, and the 10 documented [coverage gaps](https://takedownindex.org/about/coverage-gaps) describe what that pass could not reach. The full list of changes is published at [corrections and updates](https://takedownindex.org/about/corrections-and-updates).

Every figure above is derived from the published tables and can be recomputed from them. [Download the data](https://takedownindex.org/data), then read the [counting rules](https://takedownindex.org/about/counting-incidents) and the [known limitations](https://takedownindex.org/about/known-limitations) before citing any of it.
