How we screen and label claims

Ransomware groups lie constantly — in their victim lists, their geography, and their prose. Every claim here is an allegation, and every exclusion is deliberate.

This live dashboard reports canonical claim counts, tracked groups and providers, quarantined and malformed rows, contested-country claims, quarantine reasons, and the country-trust breakdown (reported and uncontested, contested and excluded, unknown), alongside source health, coverage, and documented limitations. The rules behind these figures are described in the methodology.

How these quality figures are measured

The dashboard reports the live screening state of the dataset: canonical claim counts, tracked groups and providers, quarantined and malformed rows, contested-country exclusions with reasons, and the country-trust breakdown (reported and uncontested, contested and excluded, unknown). Every exclusion is deliberate and counted rather than silently dropped.

Source health shows per-provider ingestion status, and independent providers are distinguished from mirrors and alternate transports: republished observations never increase the independent-provider count. These figures come from the same pipeline that produces every other page, so the dashboard is the dataset auditing itself, not a separate estimate.

Example: reading this page correctly

Example reading: a nonzero quarantined-rows count means the screening rules caught rows that failed safety checks — for example prose published as a victim name. Quarantine is evidence the filters are working, not evidence of dataset corruption.

Frequently asked questions

Why quarantine rows instead of fixing them?
Provider rows can carry attacker-injected content. Rows failing safety checks are held out of display rather than edited, because editing attacker prose risks laundering it into trusted output.
What makes a provider independent?
Independent providers make their own observations of leak sites. Mirrors and feeds that republish another provider's data are tracked but never counted as separate corroboration for a claim.
Should researchers cite these figures?
Yes — the screening counts quantify the dataset's known limitations, which is exactly what a methods section needs. Cite them as of the dataset state shown on the page, alongside the methodology.

Data freshness

Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.

Related pages

Explore the tracker

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.