Search and filter provider-observed ransomware claims across all tracked groups. Every row is a group-published allegation observed by a monitoring provider — explicitly unverified.
The directory supports free-text and plain-English intent search, filters for group, country, sector, data source, and time window, sorting by recency, organization, or group, an authority-confirmed-only toggle, and MISP export for defensive tooling.
Every row is a canonical claim record: observations of the same group-published allegation from multiple providers are reconciled by shared public identity into one record that retains traceability back to each provider observation. Rows that fail safety screening are quarantined rather than displayed, and missing metadata such as country or sector stays explicitly unknown.
Search covers organization names and plain-English intent; filters combine group, country, sector, data source, time window, and an authority-confirmed-only toggle. Authority confirmation means an exact, date-plausible match against a primary official source (California OAG, SEC EDGAR Item 1.05, or HHS OCR) exists — it confirms an official breach report, not the group's claim itself.
Example reading: filtering to one sector over 90 days and sorting by recency yields the provider-observed claim stream for that sector — a visibility floor of what groups chose to publish and providers captured, not a census of attacks in that sector.
Data refreshes continuously: the tracker ingests documented public provider feeds on a recurring cycle and reconciles new observations into canonical records. The feed-status indicator in the app header shows the time of the last successful sync. A quiet interval means no new provider observations — not an absence of attacks.
Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.