Hunting grounds

Where each group's claimed victims sit — the top tracked groups against the countries they name most, in one readable grid.

The matrix covers a 365-day window of provider-observed claims and uses only uncontested reported countries. Geography here is victim geography — it never implies attacker origin or infrastructure location.

How the hunting-grounds matrix works

The matrix crosses the most active tracked groups (by 365-day observed claims) with the victim countries they named most, using only uncontested reported countries — the same country-trust rules as the map. Each cell is a count of provider-observed claims naming victims reported in that country.

Rows therefore describe where each group's published claims concentrate geographically. As everywhere in the tracker, geography is victim geography: the matrix never implies attacker origin, infrastructure location, or deliberate national targeting.

Example: reading this page correctly

Example reading: a heavy cell at group X row and country Y column means X's observed claims disproportionately named organizations reported in Y over the year — which may reflect the group's affiliate footprint, language reach, or simply the distribution of organizations with public exposure, none of which the matrix distinguishes.

Frequently asked questions

Does a concentrated row mean a group targets that country?
No. The matrix shows where claimed victims were reported to be located. Deliberate targeting intent is not observable from leak-site claims, so the tracker does not assert it.
Why are some claims missing from the matrix?
Claims with unknown geography or contested country tags are excluded from every named-country surface rather than guessed, so matrix totals can be lower than a group's overall claim count.
How are the groups and countries chosen?
Both axes are ranked by observed 365-day claim volume — the top groups against the countries they name most — so the matrix is reproducible from the dataset rather than editorially curated.

Data freshness

Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.

Related pages

Explore the tracker

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.