Observed ransomware activity — Retail & E-Commerce (sector)

These are provider-observed claim records, not incident confirmations, attacker origin, confirmed targeting intent, or a prediction of future risk.

Top observed groups

Methodology & data freshness

Observation interval: Complete calendar months over the trailing 24 months, ending at the start of the current UTC month.. Dataset anchor 2026-08-01T00:00:00.000Z; 9,567 canonical records represented. Only discovery-basis rows are counted as newly observed by providers.

How to cite: Dragons Eye Ransomware Tracker, “Observed ransomware activity — Retail & E-Commerce (sector)”, provider-observed ransomware claim data as of 2026-08-01, this page's URL. Keep the observed-claim caveat with any reused figures; the methodology documents the evidence model and the data-quality dashboard quantifies screening and exclusions.

Ordered by measured change and, where available, AI-prioritized; every fact is calculated deterministically from provider observations. Records are provider-reported claims, not confirmed incidents. Source: reconciled leak-site victim claims across independent providers.

Source: reconciled leak-site victim claims aggregated from documented public monitoring providers. Independent providers are distinguished from mirrors, and no provider count verifies an underlying allegation. Definitions for every term used here are in the glossary.

All activity profiles · Weekly signals · Victim-claim directory · Intelligence overview

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.