Data-rich country, sector, and country-by-sector profiles built from reconciled ransomware claim observations. The primary metric is newly observed claim records in the last 12 complete months, split by timestamp basis. There is no risk score: the dataset does not measure an organization's probability of being attacked, attacker origin, confirmed targeting intent, or future risk.
Related: weekly ransomware signals, the country-level activity map, and the hunting-grounds matrix of groups versus victim countries.
Ordered by measured change and, where available, AI-prioritized; every fact is calculated deterministically from provider observations. Records are provider-reported claims, not confirmed incidents. Source: reconciled leak-site victim claims across independent providers.
Source: reconciled leak-site victim claims aggregated from documented public monitoring providers. Independent providers are distinguished from mirrors, and no provider count verifies an underlying allegation. Definitions for every term used here are in the glossary.
Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.