Claimed victims

Search and filter provider-observed ransomware claims across all tracked groups. Every row is a group-published allegation observed by a monitoring provider — explicitly unverified.

The directory supports free-text and plain-English intent search, filters for group, country, sector, data source, and time window, sorting by recency, organization, or group, an authority-confirmed-only toggle, and MISP export for defensive tooling.

How the victim-claim directory works

Every row is a canonical claim record: observations of the same group-published allegation from multiple providers are reconciled by shared public identity into one record that retains traceability back to each provider observation. Rows that fail safety screening are quarantined rather than displayed, and missing metadata such as country or sector stays explicitly unknown.

Search covers organization names and plain-English intent; filters combine group, country, sector, data source, time window, and an authority-confirmed-only toggle. Authority confirmation means an exact, date-plausible match against a primary official source (California OAG, SEC EDGAR Item 1.05, or HHS OCR) exists — it confirms an official breach report, not the group's claim itself.

Example: reading this page correctly

Example reading: filtering to one sector over 90 days and sorting by recency yields the provider-observed claim stream for that sector — a visibility floor of what groups chose to publish and providers captured, not a census of attacks in that sector.

Frequently asked questions

Are the victims listed here confirmed breach victims?
No. Every record is a group-published allegation observed by a monitoring provider. Some claims are false, exaggerated, or recycled. Records with an authority-confirmed badge additionally match an official breach report, which is the strongest signal the tracker offers.
Can I export this data for research?
Yes — the directory offers MISP-format export for defensive tooling, and reuse is welcome provided the observed-claim caveat and upstream provider attribution travel with the data, as described in the terms of use.
How do I report an incorrect record?
Named organizations can challenge a claim from its detail page. Accepted corrections are annotated in the record history and withdrawals persist across future provider syncs.

Data freshness

Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.

Related pages

Explore the tracker

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.