Group comparison

A head-to-head view of any two tracked ransomware groups. All counts are provider-observed claim cadence on public leak sites — never attack confirmations, targeting evidence, or attribution.

The comparison covers 7-, 30-, and 365-day claim counts, total claims, active and known leak sites, top sectors and reported countries, last activity, first-observed date, aliases, status, and emergence, with shareable URL state and suggested pairings such as most active and recently emerged groups.

How group comparison works

The comparison reads the same canonical claim dataset as the rest of the tracker and computes, per group, claim counts over 7-, 30-, and 365-day windows anchored to the latest canonical observation, plus totals, leak-site availability, top sectors and reported countries, aliases, status, and first-observed date.

Both columns are computed identically, so differences reflect the claim streams rather than measurement artifacts. Counts are provider-observed publishing cadence on public leak sites — never attack confirmations, targeting evidence, or attribution beyond the provider-observed allegation.

Example: reading this page correctly

Example reading: if group A shows 40 claims in 30 days against group B's 5, the supported statement is that providers observed eight times more published claims from A in that window — not that A is eight times more dangerous, since claim volume mixes activity, publishing strategy, and provider coverage.

Frequently asked questions

Can this tell me which group attacked a specific organization?
No. Attribution beyond the provider-observed allegation is out of scope. When multiple groups claim the same organization, the crossfire view shows the collision without deciding who, if anyone, is telling the truth.
What does a group's status mean?
Status reflects observed leak-site and claim activity (for example active or inactive as observed by providers). It is not proof a group has ceased operating — groups rebrand, pause, and resume.
Why do the suggested pairings change?
Suggestions such as most-active or recently-emerged pairs are recomputed from the live dataset, so they track the current observation window rather than a fixed editorial list.

Data freshness

Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.

Related pages

Explore the tracker

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.