Public incident case studies
Case Study Methodology and Corrections
How Lykos Defence selects, sources, qualifies, reviews, maintains, and corrects public incident case studies.
Purpose and scope
The Lykos Defence public incident case studies examine significant cybersecurity incidents using publicly available information.
They are intended to identify transferable lessons about incident readiness, decision-making, dependencies, evidence, continuity, recovery, governance, and resilience. They are not intended to assign blame, rank affected organisations, or suggest that a particular product, control, or service would certainly have prevented an incident.
The organisations profiled are not and have not been Lykos Defence clients in relation to the incidents described. Inclusion does not imply endorsement by, or any relationship with, the affected organisation.
Public reporting rarely describes every internal control, capability, decision, or circumstance surrounding an incident. The case studies therefore distinguish what the public record establishes from what remains uncertain and from Lykos Defence analysis.
Case selection
Cases are selected where the available public record supports a useful examination of cybersecurity consequences and organisational readiness.
We prioritise incidents with well-supported:
- operational or service disruption;
- material financial consequences;
- regulatory or legal outcomes;
- customer or community impact;
- supply-chain or third-party consequences;
- environmental or safety effects;
- physical or cyber-physical consequences; or
- significant recovery, continuity, or governance lessons.
An incident is not selected simply because it involved a large data breach, ransom demand, prominent organisation, or sophisticated attacker.
The public evidence must be sufficient to support a defensible chronology and meaningful lessons without relying on speculation about facts that have not been established.
Source preference
We prefer primary and authoritative sources wherever they are available.
Sources are generally prioritised in the following order:
- company annual reports, securities filings, and formal financial disclosures;
- regulator findings, court judgments, court orders, and official inquiries;
- government and law-enforcement reports;
- official company incident updates and investor communications;
- national cybersecurity authority, national CSIRT, and other government cybersecurity publications;
- insurer, auditor, or other formally attributable disclosures;
- high-quality investigative journalism; and
- reputable threat intelligence or security research.
Secondary reporting may be used where it provides necessary context or where no suitable primary source is publicly available. It does not replace an authoritative primary source for a material claim when one exists.
The appearance of the same claim in multiple secondary sources is not automatically treated as independent corroboration.
Each case identifies its public sources and the date on which the record was most recently reviewed.
Evidence language and confidence
Material claims are qualified according to what the underlying evidence actually establishes.
A case may distinguish between:
Confirmed facts
Facts directly supported by authoritative evidence and suitable for direct statement.
Reported or alleged facts
Statements made by an affected organisation, regulator, litigant, law-enforcement body, researcher, or other identifiable source where the underlying proposition has not necessarily been independently established.
Qualified or disputed facts
Claims supported by credible evidence but subject to uncertainty, competing accounts, incomplete evidence, unresolved proceedings, or other material limitations.
Estimates and assessments
Figures, attribution assessments, technical conclusions, or other judgments that the source itself describes as estimated, assessed, approximate, or otherwise uncertain.
Lykos Defence analysis
Our interpretation of the documented evidence and the transferable readiness lessons it may support. Analysis is presented separately from the factual chronology and is not represented as a finding about the affected organisation.
Allegations remain allegations unless and until a competent authority makes a relevant finding. Company statements, regulator allegations, threat intelligence assessments, media reporting, and court findings are not treated as interchangeable forms of evidence.
Attribution is similarly qualified. Where responsibility for an incident remains unresolved or is based on an intelligence assessment rather than a judicial or government finding, the case says so.
Incident classification
The editorial record separately classifies:
- the scope of the incident;
- any reported physical or operational effect;
- the geographical location or area affected;
- the status of the incident or related proceedings; and
- confidence in the documented impact.
These classifications are intended to prevent materially different types of consequence from being conflated.
For example, an IT ransomware incident that causes an organisation to shut down industrial operations is not described as direct manipulation of operational technology unless the evidence supports that conclusion.
Likewise, operational disruption does not necessarily imply physical damage, and confidence in an impact describes the strength of the evidence for that consequence rather than any unresolved question of legal liability.
Sectors and technical readiness themes
Cases use broad sector classifications so that filters remain useful across organisations with similar operating models and dependencies.
Each case also uses a small number of readiness themes derived from the documented incident. These may include areas such as:
- identity and access;
- remote access;
- third-party risk;
- network segmentation;
- monitoring and detection;
- evidence availability;
- business continuity;
- manual operations;
- backup and recovery;
- incident response;
- operational resilience; and
- industrial control security.
Overlapping terms are consolidated where they describe substantially the same practical capability. For example, vendor risk and supply-chain risk may be grouped as third-party risk, while OT monitoring and protocol monitoring may be grouped within monitoring and detection.
These themes describe capabilities relevant to preventing, detecting, containing, investigating, responding to, or recovering from comparable incidents. They do not imply that the absence of a particular capability caused the incident or that implementing one control would certainly have prevented it.
The “How Lykos helps” section uses selected readiness themes to identify relevant capabilities that can be validated, exercised, investigated, or improved. Service connections are based on transferable lessons from the public evidence rather than claims about what the affected organisation should have purchased or implemented.
Related case studies
Related cases are selected from the same editorial metadata used to classify the case studies, without behavioural tracking.
The ranking gives weight to factors including:
- the same broad sector;
- shared readiness themes;
- comparable physical or operational effects;
- shared countries or regions; and
- similar incident scope.
Case name provides a stable alphabetical tie-break where cases otherwise rank equally.
Figures and calculations
Financial and quantitative figures retain the meaning, scope, period, and unit used by their source.
Where relevant, we distinguish between:
- incurred costs;
- estimates or forecasts;
- provisions;
- revenue effects;
- delayed revenue;
- business-interruption impacts;
- regulatory penalties;
- insurance proceeds;
- customer-support or remediation funding; and
- other financial measures.
These categories are not treated as interchangeable.
A provision is not necessarily a final cost. A revenue impact is not automatically a permanent loss. Insurance proceeds do not erase the underlying operational impact. A regulatory capital requirement is not a fine.
Figures concerning different organisations, reporting periods, accounting treatments, or gross and net presentations are not combined unless the sources and calculation support doing so without changing their meaning.
Composite or cumulative figures identify their components. Derived figures are used only where the calculation can be reproduced from cited public information and where combining the source figures does not create a misleading measure.
Where a figure remains an allegation, litigation claim, estimate, or forecast, it is labelled accordingly.
Limits of the public record
These case studies necessarily operate within the limits of publicly available evidence.
A source may describe what happened without explaining why. A company may disclose an operational consequence without publishing the forensic detail needed to establish the initial access mechanism. A regulator may allege a control deficiency that remains contested in court.
We do not fill those gaps by assumption.
In particular, the absence of a control or capability from public reporting is not treated as evidence that the organisation did not have it.
Where the evidence does not support a conclusion about root cause, attribution, causation, individual responsibility, or a specific control deficiency, the case either qualifies the issue or leaves it unresolved.
Review and maintenance
The case-study library is maintained as the public record develops.
Each case includes a public record reviewed or equivalent date indicating when its evidence was last assessed.
Cases may be reviewed when:
- a company publishes a new annual or quarterly report;
- a regulator issues a finding, enforcement action, undertaking, penalty, or closure notice;
- a court proceeding materially changes status;
- law enforcement or a government agency publishes new findings;
- an official technical or incident report becomes available;
- attribution materially changes;
- a financial estimate, provision, insurance amount, or loss figure is revised;
- new information clarifies initial access, affected systems, containment, recovery, or consequences;
- a stronger primary source becomes available for an existing claim; or
- information is identified that contradicts or materially qualifies an existing statement.
Older historical cases may also be refreshed where new authoritative material materially improves the public record.
Corrections and updates
New information does not always require the same kind of change.
Source enhancement
A more authoritative source may become available without changing the underlying conclusion. For example, a later regulator or government report may confirm a fact previously supported by investigative reporting.
In these cases, references may be strengthened or replaced and the public-record review date updated.
Material update
A later development may add an important consequence or outcome, such as a regulatory penalty, court judgment, final financial impact, insurance recovery, investigation result, recovery milestone, or authoritative attribution.
The case is updated to incorporate the new information and its review date is changed accordingly.
Correction or qualification
If new evidence shows that a published statement, figure, attribution, date, classification, or conclusion is inaccurate, overstated, outdated, or insufficiently qualified, the affected case is corrected.
Material corrections are recorded transparently. We do not preserve a statement simply because it reflected the best information available when the case was first published.
Where appropriate, the case will identify what was corrected or materially qualified and the evidence that prompted the change.
Editorial boundaries
Every case study follows several standing editorial principles:
- Lykos Defence does not imply that it advised the affected organisation in relation to the incident;
- analysis relies on publicly available information;
- public reporting may not disclose every relevant internal capability, control, or decision;
- confirmed facts are separated from allegations, assessments, and analysis;
- uncertainty and conflicting evidence are identified where material;
- the purpose is to identify transferable lessons rather than assign blame;
- legal proceedings are described according to their current procedural status;
- financial measures retain the meaning given to them by their source; and
- no Lykos Defence service or individual security control is represented as having certainly prevented an incident or eliminated its consequences.
Reporting a correction
We welcome corrections supported by authoritative public evidence.
Corrections or additional sources can be sent to contact@lykosdefence.com.
Please include:
- the case-study title;
- the statement, figure, or reference you believe should be reviewed;
- the supporting public source; and
- any relevant page, section, paragraph, or other pinpoint reference.
We will review material submissions against the same evidence standards used for the original case study.