Dragons Eye Ransomware Tracker

Public ransomware intelligence: live monitoring of leak-site victim claims, a directory of tracked ransomware groups, sector and geography statistics, and activity trends for defenders, researchers, and SOC analysts.

Most active ransomware groups

Most targeted sectors

Most affected countries

Frequently asked questions

What is a ransomware victim claim on Dragons Eye?

A claim is a group-published allegation that an organization was attacked, posted on the group's leak site and observed by a monitoring provider. Dragons Eye reports what providers saw groups publish — not what Dragons Eye independently verified happened.

Are these claims verified attacks?

No. Every record is an unverified attacker assertion observed by a provider. Multiple providers observing the same claim raises confidence that the claim was posted; it does not verify that an attack occurred. Authority-confirmed badges only mean a matching official breach report exists in a primary source — they still do not verify the group's claim.

How are ransomware groups counted?

Groups are tracked as canonical identities after reconciling provider observations and approved aliases. Tracked groups are the directory total; active groups are those with recent provider-observed claim activity in the current window. Mirror or republished observations do not inflate independent-provider counts, and no provider count verifies the underlying allegation.

How should this tracker be used responsibly?

Dragons Eye is for research, defense, and educational use only. Do not use it to interact with, support, or negotiate with threat groups. The tracker never connects to Tor, never exposes leak-site infrastructure or leaked material, and must not be used to harass or extort named organizations.

For collection rules and terminology, read the methodology and glossary.

Explore

Source: reconciled leak-site victim claims aggregated from documented public monitoring providers. Independent providers are distinguished from mirrors, and no provider count verifies an underlying allegation. Definitions for every term used here are in the glossary.

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.