Ransomware Frontline Report

Supplement F: Fact-Checking Method

V2 | English | Full Report

F.1 Three Layers of Incident Description

Layer Example Treatment in this report
Official disclosure by the victim organization or government Shutdown, isolation, notification, officially confirmed data impact Can be stated as fact.
Joint advisories from investigative/government agencies Confirmed TTPs and scope of damage for a specific group Stated together with the source and its scope.
Media reports, attacker claims, secondary analysis Intrusion route, payment amount, attribution, leak claims Supplementary information. Not stated definitively without official corroboration.

F.2 Three Layers for Describing an Incident

When recording or explaining an incident, separate confirmed facts, judgments or analysis derived from those facts, and matters that remain unconfirmed or prospective. Mixing these layers can cause assumptions to be treated as established facts and can make it difficult to review the basis for later decisions.

Layer What to record Writing guidance
Confirmed facts Matters confirmed through logs, configurations, observations, official disclosures, or similar evidence Keep assumptions and evaluations separate, and record when the fact was confirmed and what supports it
Judgment and analysis Assessments, interpretations, and response decisions based on confirmed facts Make clear which facts support the judgment and the level of confidence at the time
Unconfirmed matters and outlook Matters not yet confirmed, hypotheses under investigation, and points that still need verification Do not present them as facts; state what remains unconfirmed and how it will be checked

Keeping “what is known,” “what is currently judged to be likely,” and “what is still unknown” separate is important not only for technical investigation, but also for maintaining consistency in management decisions, legal response, and external communications.

F.3 Handling of Figures

IC3’s complaint counts and loss amounts, the DBIR’s percentages, and IPA’s rankings are all useful, but each has a different population, definition, and period. For example, IC3’s loss amount is the adjusted loss included in the complaints filed, and does not represent the total worldwide damage, total ransom paid, or total recovery cost. [S02][S12][S13] The DBIR’s percentages are a metric concerning breaches in the analyzed sample, not the probability of occurrence for every company. [S03][S04]

Figures are strong material for rejecting the conclusion that “this is not important,” but they should not be used for a precise prediction such as “our company will lose X yen” or “there will be X incidents next year.”

F.4 Procedure for Updates

  1. Update the research reference date.
  2. Re-confirm, from the original text, the definition, population, and publication date of new annual materials such as the 2026 DBIR.
  3. When comparing against existing statistics, confirm whether the definition is the same.
  4. For new information about an incident, prioritize primary sources from the victim organization, government, or investigative authorities.
  5. Before adding a new threat name to the body text, confirm it does not duplicate an existing defensive principle.
  6. Add the material, confirmed facts, limitations, and reference location to the source ledger.

This procedure keeps the report from simply bloating with every piece of trending news added on, while maintaining factual accuracy, clear definitions, and practical value.