# Data Limitations — California Cybersecurity Risk Report 2027

**IC3 data is self-reported and undercounts true incidence.** Complaints reflect only victims who report to the FBI. The FBI's own analysis of one ransomware group's infrastructure indicated roughly 20 percent of that group's victims had reported [C-025]. All IC3-derived figures in this report are floors.

**IC3 "complaints" are not deduplicated victims.** One person or business may file multiple complaints; the FBI de-duplicates losses "as much as possible" but complaint counts represent filings.

**IC3 state attribution follows the complainant's stated location.** A business operating in California but filing from another state (or vice versa) is attributed by the filer's information. Business versus consumer complainants are not separable in state tables.

**IC3 loss figures are reported, not verified,** and ransomware losses in particular exclude downtime, lost business, wages, files, equipment, and third-party remediation, by the FBI's stated definition [C-020].

**Year-over-year IC3 comparisons carry definitional drift.** Crime-type definitions and descriptors change across editions (e.g., "Charity" and "AI Related" were not captured in earlier years). This report's trend claims use only totals and fields published consistently.

**The AG register records notices, not incidents.** One incident can generate many notices (including supplemental notices from the same filer), and one notice can list multiple breach dates. Counts are labeled as notices throughout.

**The register covers only breaches affecting more than 500 California residents.** Smaller breaches are invisible to it, so it cannot measure total breach incidence.

**Register breach dates are as reported by filers** and contain occasional errors (including future-dated entries). Handling rules and exclusion counts are documented in the methodology; four rows were excluded from lag statistics on this basis and none were deleted.

**Occurrence-to-notice lag is not a compliance measurement.** California's statutory deadlines run from discovery of a breach, which the register does not record. The lag measures the victim exposure window only, and the report says so wherever the figure appears.

**The SB 446-era cohort is right-censored.** Notices for 2026 breaches that take longer to file had not yet arrived at the August 24, 2026 capture; the cohort's median (70 days) is therefore a lower bound and will rise. The complete 2026 cohort will be re-measured in the 2028 edition.

**The register capture was collected via recorded web fetch,** not direct file download, due to analysis-environment network restrictions. Verification of the capture against a fresh download of the live export (row counts for the window, plus spot checks) is a required pre-publication step and is specified in the package index.

**The 2022 California loss figure is known at reported precision only** ("more than $2 billion") and is excluded from all percentage calculations.

**DBIR findings describe a global dataset,** not California; the report uses them for breach mechanics only and never localizes them.

**No Orange County-level cybercrime statistics exist in these sources.** IC3 does not publish county data. The Orange County media version therefore uses statewide findings plus individually documented Orange County entries from the public register, and manufactures no local statistics.

**Vendor-cascade identification is indicative, not forensic.** Shared breach-date signatures corroborated by filer composition strongly indicate common incidents but are not incident-response attribution; the method also undercounts cascades whose members report differing date strings.
