A head-to-head view of any two tracked ransomware groups. All counts are provider-observed claim cadence on public leak sites — never attack confirmations, targeting evidence, or attribution.
The comparison covers 7-, 30-, and 365-day claim counts, total claims, active and known leak sites, top sectors and reported countries, last activity, first-observed date, aliases, status, and emergence, with shareable URL state and suggested pairings such as most active and recently emerged groups.
The comparison reads the same canonical claim dataset as the rest of the tracker and computes, per group, claim counts over 7-, 30-, and 365-day windows anchored to the latest canonical observation, plus totals, leak-site availability, top sectors and reported countries, aliases, status, and first-observed date.
Both columns are computed identically, so differences reflect the claim streams rather than measurement artifacts. Counts are provider-observed publishing cadence on public leak sites — never attack confirmations, targeting evidence, or attribution beyond the provider-observed allegation.
Example reading: if group A shows 40 claims in 30 days against group B's 5, the supported statement is that providers observed eight times more published claims from A in that window — not that A is eight times more dangerous, since claim volume mixes activity, publishing strategy, and provider coverage.
Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.
Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.