Software is not an industry
For a while our feed gave a research lab and a hosting provider the same industry codes. Why a uniform label is worse than a coarse one. Last updated: 2026-08-22
For a while, our news feed gave almost every software company the same three industry codes. A research lab that trains models, a company that resells managed IT, and a firm that rents server space all came back tagged identically. That is not a small labeling quirk. It is the difference between saying "attackers hit a cloud hosting provider this week" and "attackers hit an AI research group," and for a few days it put an AI story into a list of IT vendors that had been breached.
Observed across the victim-industry tags in the live news feed, 2026-07-24. Codes are NAICS (the North American Industry Classification System).
What went wrong
Industry codes are supposed to say what a business does. The problem was not the codes themselves. It was that a whole category of victim, call it "software and technology," was being stamped with one fixed set of codes for the entire category, rather than the specific code that fits the specific company. So the field said "software publisher, and computer systems design, and data hosting" for everyone in the bucket, which is another way of saying it told you nothing about the individual victim.
A reader who filters on "managed IT and hosting" then sweeps up the AI lab too, because on paper the lab carries the hosting code. The label looked precise. It was uniform, which is the opposite of precise.
Why a coarse victim label is a real problem
Every claim about who is being targeted rests on how well you can tell victims apart. If your sector view cannot separate a hosting provider from a model developer, then "this sector is under attack" is a statement about your labeling, not about the threat. The failure is quiet, because the output still looks like clean structured data. It is confident and wrong in a way you cannot see unless you go and read the underlying stories, which is exactly what nobody has time to do.
The fix is the boring, correct one
The answer is not a cleverer rule for turning the category label into a finer code. It is to classify each victim directly, from what that company actually does, and to accept a coarser code when the specific one is not known rather than borrow a precise-looking code that does not fit. The feed is now doing this: an AI platform gets the software publisher code, a hosting firm gets the hosting code, and the two stop being interchangeable. Where the business is genuinely unclear, the honest move is a broad code, not a confident guess.
What to take from it
When a tool shows you a sector breakdown of who got hit, ask how the victims were classified. If every company in a category carries the same codes, the breakdown is decoration. For a resource constrained team deciding whether a wave of attacks is coming for an industry like yours, that distinction is the whole value of the readout.