Why the numbers hold: the evidence model, provenance rules, and the lines this tracker does not cross.
Provider-observed ransomware claims aggregated from leak-site monitoring providers. Every record is a group-published allegation that a provider observed — not a confirmed attack.
Observations from multiple providers reconcile into canonical records by shared public identity. Records retain traceability back to the provider observations that produced them, and corrections or removals resolve through immutable canonical identity.
Leak-site URLs and sensitive URL-like content are redacted. Provider-derived names pass through a single display chokepoint, payloads are allowlisted and byte-limited, and malware is never downloaded.
Analysis windows anchor to the latest canonical observation. Charts show complete buckets only, with the in-progress period reported separately, and day counts use UTC.
CISA KEV, FIRST EPSS, MITRE ATT&CK, Abuse.ch, and AlienVault OTX provide labeled defensive context only. Enrichment never verifies a claim.
Authority-confirmed badges require exact, date-plausible matches against primary official sources: California OAG breach notifications, SEC EDGAR Item 1.05 ransomware-scoped filings, or HHS OCR breach records. This confirms an official breach report exists — not the group's claim — and is excluded from provider corroboration counts.
No attack confirmation, no attribution beyond the provider allegation, no proof of tempo or cessation, and no predictions. Claim cadence is a visibility floor, not a harm census.
Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.