Skip to content

Editorial policy

How we use other people’s research

This site is built almost entirely on work published by other people. That arrangement only stays fair if the rules are written down, enforced in code rather than in good intentions, and easy for the original author to hold us to.

By Antonio RaduLast reviewed 2026-08-06

Standing offer to researchers

If anything on this site misrepresents your work, email corrections@clickfixreport.com and it is corrected within five working days. No questions asked. You do not have to prove you wrote it, explain why it matters, or argue the point.

That includes removal. If you would rather we did not summarise your research at all, say so and the page comes down.

The principle

Facts are not copyrightable. The prose describing them is. A domain name, a date, a file hash, a technique label and the name of the publisher who reported them are facts, and reusing them with credit is legitimate. The paragraphs an analyst wrote to explain those facts are their creative work, and reproducing them here would be taking something that is not ours to take — regardless of how much traffic it earned.

Everything below is the operational version of that single distinction.

What we take

  • Indicator strings, exactly as printed, with the sentence they appeared in kept privately for provenance.
  • Dates: when the activity was observed, when the report was published.
  • The publisher, the author where they are named, and the canonical URL.
  • Structured labels: target operating systems, lure themes, malware family names, execution mechanisms, technique identifiers.
  • Whether the source assessed a host as attacker-registered or compromised, and what evidence it gave.

What we never take

  • Paragraphs. Not lightly reworded, not machine-paraphrased. A summary that shares an eight-word sequence with the source is rejected before publication.
  • Images, screenshots and diagrams. Not the analyst’s infection-chain graphic, and not their screenshot of the lure — the second of which we would refuse to publish even if it were ours.
  • A report’s narrative framing. Their argument about what the campaign means belongs to them. Read it at the source; we link to it.
  • Anything from a source whose licence forbids it. Several well-known feeds prohibit derivative works or redistribution by contract. We do not ingest those, and no amount of “facts are not copyrightable” changes a term of service you agreed to when you fetched the file.

The limits, in numbers

Editorial limits and how each is enforced
RuleLimitEnforced by
Summary length150 wordsComposed from fields by us; checked in CI
Overlap with the source textno 8-gram matchAutomated check against the archived source
Direct quotation25 wordsIn quotation marks, attributed inline, at most one per section
Model-written prosenoneThe extraction schema accepts structured fields only
Correction turnaround5 working daysLogged publicly on /corrections

Attribution, and why the links are followed

Every campaign page opens with an attribution block: who reported it, when they published, and a link to the original. It sits above the summary, not underneath the indicator table, because the original research is the more valuable document and a reader should be able to leave for it immediately.

Where we hold an archived snapshot of a source, it is linked beside the original, so a citation survives the page being moved or taken down. We have not captured those for the reports published so far, and no page carries one yet. That is outstanding work, not a policy.

Those links are followed. We do not mark source links with nofollow. A citation that deliberately withholds credit from the person who did the work is not a citation, it is extraction with a hyperlink attached. This costs us something and it is meant to.

Where several publishers reported the same campaign, all of them appear, ordered by publication date, so the record shows who was first rather than who we found first.

Disclosure: what the machine does

A language model reads source reports and returns structured fields. It writes none of the prose on this site, including the campaign summaries, which are composed from those fields by template plus human sentences. A person reviews every campaign before it is published, and a random sample of published entries is re-audited weekly. The mechanics, and the resulting measured error rate, are on /methodology.

Our own material

The structured dataset and the prose we write are licensed CC BY 4.0. Take it, build on it, sell something with it — just credit ClickFixReport and link back so the next person can check our working. The terms are on /terms. The licence covers what is ours; it does not and cannot cover the source reports we link to.

If you are not the researcher

If a page concerns a website you own — most often because it was compromised and used to serve a lure — the route is /dispute, and the disclaimer explains what an entry does and does not assert about you. We do not charge for removal, we do not require a lawyer, and being listed as a compromised victim is not an accusation.