Methodology

Why the numbers hold: the evidence model, provenance rules, and the lines this tracker does not cross.

What we track

Provider-observed ransomware claims aggregated from leak-site monitoring providers. Every record is a group-published allegation that a provider observed — not a confirmed attack.

Provenance

Observations from multiple providers reconcile into canonical records by shared public identity. Records retain traceability back to the provider observations that produced them, and corrections or removals resolve through immutable canonical identity.

Redaction and safety

Leak-site URLs and sensitive URL-like content are redacted. Provider-derived names pass through a single display chokepoint, payloads are allowlisted and byte-limited, and malware is never downloaded.

Time discipline

Analysis windows anchor to the latest canonical observation. Charts show complete buckets only, with the in-progress period reported separately, and day counts use UTC.

Enrichment, labeled

CISA KEV, FIRST EPSS, MITRE ATT&CK, Abuse.ch, and AlienVault OTX provide labeled defensive context only. Enrichment never verifies a claim.

Authority-confirmed tier

Authority-confirmed badges require exact, date-plausible matches against primary official sources: California OAG breach notifications, SEC EDGAR Item 1.05 ransomware-scoped filings, or HHS OCR breach records. This confirms an official breach report exists — not the group's claim — and is excluded from provider corroboration counts.

What we never claim

No attack confirmation, no attribution beyond the provider allegation, no proof of tempo or cessation, and no predictions. Claim cadence is a visibility floor, not a harm census.

Explore the tracker

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.