Ransomware groups lie constantly — in their victim lists, their geography, and their prose. Every claim here is an allegation, and every exclusion is deliberate.
This live dashboard reports canonical claim counts, tracked groups and providers, quarantined and malformed rows, contested-country claims, quarantine reasons, and the country-trust breakdown (reported and uncontested, contested and excluded, unknown), alongside source health, coverage, and documented limitations. The rules behind these figures are described in the methodology.
The dashboard reports the live screening state of the dataset: canonical claim counts, tracked groups and providers, quarantined and malformed rows, contested-country exclusions with reasons, and the country-trust breakdown (reported and uncontested, contested and excluded, unknown). Every exclusion is deliberate and counted rather than silently dropped.
Source health shows per-provider ingestion status, and independent providers are distinguished from mirrors and alternate transports: republished observations never increase the independent-provider count. These figures come from the same pipeline that produces every other page, so the dashboard is the dataset auditing itself, not a separate estimate.
Example reading: a nonzero quarantined-rows count means the screening rules caught rows that failed safety checks — for example prose published as a victim name. Quarantine is evidence the filters are working, not evidence of dataset corruption.
Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.
Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.