Publication

Editorial standards

The rules the newsroom works under — published so readers can hold us to them.

Verification

  • Every factual claim traces to a retrievable source. An article with no recorded sources does not ship.
  • Primary sources first: vendor advisories, official company statements, regulatory filings, court records, and named on-the-record sources.
  • We distinguish confirmed events from allegations and ongoing investigations, and we say which one we are reporting in the story itself.

Two-source rule

Significant factual claims — especially breach attributions, victim counts, and incident scope — require confirmation from at least two independent sources before publication. A single anonymous claim is never enough.

Breach-reporting ethics

  • Every breach report states what happened, when it happened, who confirmed it, what data may be affected, what remains unknown, and what defensive action readers can take.
  • We never publish stolen credentials, personal records, access tokens, live secrets, or links intended to distribute stolen data.
  • We never perform unauthorized access, exploitation, scanning, intrusion, or collection of leaked personal information in the course of reporting.
  • Vulnerability reporting uses responsible disclosure and qualified technical review. We never invent CVSS scores, affected products, victim counts, exploit activity, or incident attribution.

Corrections

When we get something wrong, we fix it fast and say so publicly. See our corrections policy.

AI use & authorship

HackedWire articles are produced with AI assistance under human editorial direction. Our bylines are house editorial personas — named roles representing the newsroom’s desks, not real employees. This is disclosed plainly because readers deserve to know how the byline works.

  • AI assistance does not change the verification standard: every factual claim is still sourced, and the two-source rule still applies.
  • We do not fabricate quotes, people, events, statistics, or sources. Quotes are verbatim from published or on-the-record sources, attributed, with the source recorded.
  • We make no first-hand claims (“we tested”, “we visited”) unless a verified record of that first-hand work exists.

Source protection

We protect confidential sources. Do not send sensitive material by plain email — see our secure-contact guidance.