Registry insights
See where documented incidents concentrate, who they affect and how their characteristics change over time.
Incident activity
188 incidents dated in this period
Attribution and disclosure
Threat actors
Explore-
Qilin 9 5%
-
INC Ransom 8 4%
-
Interlock 8 4%
-
ShinyHunters 4 2%
-
LockBit 3 2%
-
NightSpire 3 2%
-
The Gentlemen 3 2%
6 threat actors tied at 2 incidents; this tied group is not shown.
Geographic impact
State impact
Bubble area represents incident count; one incident may appear in multiple states.
Ranked by incident count; one incident may appear in multiple states.
All 49 affected states and territories are shown.
-
Texas 18 10%
-
California 14 7%
-
Georgia 13 7%
-
Michigan 13 7%
-
Minnesota 13 7%
-
Florida 12 6%
-
Massachusetts 11 6%
-
Pennsylvania 9 5%
Counties
Showing 6 of 45 counties with repeated impact. 6 counties tied at 3 incidents; this tied group is not shown. 213 additional counties each appeared in one incident.
Cities
-
Kentwood, Michigan 3 2%
-
Walker, Michigan 3 2%
-
Wyoming, Michigan 3 2%
Showing 6 of 31 cities with repeated impact. 25 cities tied at 2 incidents; this tied group is not shown. 366 additional cities each appeared in one incident.
State-by-sector matrix
Each incident is counted once per state-sector pair.
| State or territory | Government Services and Facilities | Healthcare and Public Health | Water and Wastewater Systems | Information Technology | Emergency Services | Commercial Facilities |
|---|---|---|---|---|---|---|
| Texas | 10 | 3 | — | 2 | 1 | — |
| California | 6 | 2 | — | 2 | — | 1 |
| Georgia | 6 | 2 | 3 | 1 | — | — |
| Michigan | 3 | 3 | 3 | 1 | — | 1 |
| Minnesota | 5 | 2 | 4 | 1 | — | 1 |
| Florida | 6 | 2 | — | 1 | 1 | 1 |
| Massachusetts | 5 | 2 | — | 2 | 2 | — |
| Pennsylvania | 6 | 2 | — | — | — | — |
Organizations and infrastructure
Organizations with repeated impact
Explore-
Winona County 2 1%
205 additional organizations each appeared in one incident.
Organization types
-
Public Education 31 16%
-
K-12 school district / LEA 22 12%
2 organization types tied at 11 incidents; this tied group is not shown.
Critical infrastructure sectors
-
Healthcare and Public Health 20 11%
-
Information Technology 14 7%
-
Emergency Services 10 5%
-
Financial Services 7 4%
Incident status
-
Presumed Resolved 89 47%
-
Resolved 77 41%
-
Active 20 11%
-
Presumed Active 2 1%
Mechanisms and impacts
Attack mechanisms
-
Unknown cyber mechanism 90 48%
-
Unauthorized access 53 28%
-
Ransomware 46 24%
-
Malware 11 6%
-
Data extortion 8 4%
2 mechanisms tied at 3 incidents; this tied group is not shown.
Operational impacts
-
Internal systems unavailable 106 56%
-
Partial service outage 71 38%
-
Network outage 64 34%
-
Manual workaround required 51 27%
-
Service delay 39 21%
Data impacts
-
Unknown data impact 84 45%
-
Data unavailable 58 31%
-
Data theft or exfiltration 28 15%
-
Unauthorized data access 19 10%
-
No known data impact 17 9%
-
Data encryption 16 9%
4 impacts tied at 3 incidents; this tied group is not shown.
Extortion indicators
-
No known extortion indicator 63 34%
-
Leak-site listing 55 29%
-
Unknown extortion indicators 26 14%
-
Data-theft extortion 25 13%
-
Public leak threat 24 13%
-
Ransom demand 23 12%
2 indicators tied at 12 incidents; this tied group is not shown.
Assessment and transparency
Cyber assessment
-
Confirmed 186 99%
-
Suspected 1 1%
-
Unresolved 1 1%
Ransomware confidence
-
Unresolved 78 41%
-
Confirmed 38 20%
-
Not Ransomware 26 14%
-
Low 20 11%
-
Medium 19 10%
-
High 7 4%
Cyber transparency
-
Official cyber 165 88%
The organization publicly identifies the event as cyber-related.
-
External sources identified the event as cyber-related before the organization publicly confirmed it.
-
External cyber only 7 4%
Only external sources publicly identify the event as cyber-related.
-
The disruption is documented, but available public information does not yet establish cyber involvement.
Disruption transparency
-
Official disruption 175 93%
The organization publicly documents the resulting service disruption.
-
Credible external sources document the disruption, but the organization does not clearly do so.
-
No disruption cues 6 3%
No credible public source clearly documents service disruption.
How these figures are calculated
Figures describe published registry coverage, not the prevalence of cyber incidents overall. Incidents are grouped by their canonical incident date rather than publication date.
An incident is counted once within each category. Geographic totals use explicitly impacted incident locations and do not treat an organization headquarters as an impacted place. Municipal impacts roll up to their recorded county and state, with each incident counted once per place. Affected organization counts use primary, victim, operator and owner relationships. Critical infrastructure and organization taxonomies remain separate.
Threat actor figures include only actors attached through eligible public claims. Same-date disclosure compares the calendar date of the first public signal with the calendar date of the official cyber disclosure; it does not measure elapsed hours or response speed. Mean days to later disclosure is the arithmetic mean only among valid intervals greater than zero, so longer intervals have more influence. Missing, invalid or reverse-ordered date pairs are excluded. Empty or unknown values are not inferred.