Ecosystem calendar

A year of provider-observed claims as a heat calendar — surges, droughts, and weekly publishing patterns at a glance, for the whole ecosystem or one selected group.

The calendar covers up to the most recent 400 UTC days. Ecosystem scope also flags exceptional drought and surge weeks against the trailing median. Quiet periods mean no provider observations, not no attacks.

How the ecosystem calendar works

The calendar buckets provider-observed claims by UTC day across up to the most recent 400 days, for the whole ecosystem or one selected group. Day cells shade by claim count, so publishing surges and droughts are visible as texture rather than requiring chart reading.

In ecosystem scope, exceptional weeks are flagged by comparing each week's total against the trailing median — a deterministic threshold, not a judgment call. Because groups control when they publish, the calendar measures leak-site publishing tempo, never attack timing.

Example: reading this page correctly

Example reading: a two-week blank stretch for a single group means providers observed no new claims from that group in those weeks. It is consistent with a pause in publishing, a leak-site outage, or provider coverage gaps — the calendar cannot distinguish these, so it claims none of them.

Frequently asked questions

Do quiet days mean fewer attacks happened?
No. Quiet periods mean no provider observations were recorded. Groups batch publications, take breaks, and move infrastructure; providers also have coverage windows. Claim cadence is a visibility floor.
What timezone are the day cells in?
All day bucketing uses UTC, matching the rest of the tracker's time discipline, so a cell is the same 24-hour interval for every reader.
Why does the current week look low?
In-progress periods are inherently partial. The tracker's charts show complete buckets and report the current period separately, so a low-looking current week is an artifact of incompleteness, not a measured drop.

Data freshness

Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.

Related pages

Explore the tracker

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.