Co-claim evidence, visualized: which groups named the same victim organizations in provider-observed claims, and how the claim stream is distributed across groups.
Over a 365-day window anchored to the latest observation, the page renders a collision graph of groups with shared victim claims and a Monopoly Index of claim-stream concentration. Results are provider observations — not attribution and not verified attacks.
Over a 365-day window anchored to the latest canonical observation, the collision graph links any two groups whose provider-observed claims named the same victim organization. Matching uses reconciled canonical victim identity — exact identity continuity, never fuzzy name matching — so a collision is a documented co-claim, not a guessed similarity.
The Monopoly Index summarizes how concentrated the claim stream is: whether observed claims cluster in a few dominant groups or spread across many. Both views are analytic readings of public claims; a co-claim shows two groups published the same name, which can reflect re-victimization, affiliate overlap, data resale, or simple false claims — the graph asserts none of these.
Example reading: an edge between two groups with three shared victims means providers observed both groups publishing claims naming the same three organizations within the window. The correct citation is the co-claim count, not any inferred relationship between the groups.
Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.
Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.