Live ransomware intelligence map

A country-level view of provider-observed ransomware claims: recent-claim spotlight, activity timeline, and volume, recency, and change lenses across the tracked dataset.

Filters cover the observation window (24 hours to all time), ransomware group, victim sector, data provider, and country, with shareable URLs and pinnable countries. Country aggregates reflect reported victim geography only — never precise locations and never attacker origins. Contested-country claims are excluded from every named-country surface.

How the activity map works

Each claim record carries at most one reported victim country, and only when the reporting provider tagged it and no contested-country rule excludes it. The map aggregates those uncontested reported countries into country-level totals for the selected observation window; records with unknown or contested geography are excluded from every named-country surface rather than guessed.

The three lenses read the same aggregates differently: volume ranks countries by total claims in the window, recency weights the most recent observations, and change compares the current window against the preceding one. Geography is always victim geography as reported by providers — it never indicates attacker origin, infrastructure location, or precise victim coordinates.

Example: reading this page correctly

Example reading: if a country's change lens shows a sharp rise over 30 days, the correct statement is "providers observed more claims naming victims reported in this country than in the previous 30 days" — not that the country is being targeted more, since claim publication timing is controlled by the groups themselves.

Frequently asked questions

Does the map show where attackers are located?
No. Countries reflect the reported location of claimed victim organizations only. The tracker never asserts attacker origin, and contested or unknown geography is excluded rather than inferred.
Why does a country I expect to see show no activity?
Either no provider observation in the selected window carried an uncontested reported country for it, or the claims that exist have unknown geography. Absence on the map is absence of observed, geolocatable claims — never evidence that no attacks occurred.
Can I link to a specific map view?
Yes. The observation window, group, sector, source, and country filters, the active lens, pinned countries, and the timeline selection are all encoded in the URL, so any configured view can be shared or cited as a stable link.

Data freshness

Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.

Related pages

Explore the tracker

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.