Where each group's claimed victims sit — the top tracked groups against the countries they name most, in one readable grid.
The matrix covers a 365-day window of provider-observed claims and uses only uncontested reported countries. Geography here is victim geography — it never implies attacker origin or infrastructure location.
The matrix crosses the most active tracked groups (by 365-day observed claims) with the victim countries they named most, using only uncontested reported countries — the same country-trust rules as the map. Each cell is a count of provider-observed claims naming victims reported in that country.
Rows therefore describe where each group's published claims concentrate geographically. As everywhere in the tracker, geography is victim geography: the matrix never implies attacker origin, infrastructure location, or deliberate national targeting.
Example reading: a heavy cell at group X row and country Y column means X's observed claims disproportionately named organizations reported in Y over the year — which may reflect the group's affiliate footprint, language reach, or simply the distribution of organizations with public exposure, none of which the matrix distinguishes.
Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.
Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.