Skip to content
DysruptionHub registry intelligence

Registry insights

See where documented incidents concentrate, who they affect and how their characteristics change over time.

Reporting period Last 12 months
152 Incidents Documented in this reporting window
Tempo

Incident activity

152 incidents dated in this period

Incident activity over time Aug 2025: 0; Sep 2025: 0; Oct 2025: 0; Nov 2025: 1; Dec 2025: 1; Jan 2026: 3; Feb 2026: 8; Mar 2026: 30; Apr 2026: 21; May 2026: 17; Jun 2026: 16; Jul 2026: 31; Aug 2026: 24 0 16 31 Aug 2025: 0 incidents Aug 2025 Sep 2025: 0 incidents Oct 2025: 0 incidents Oct 2025 Nov 2025: 1 incident Dec 2025: 1 incident Dec 2025 Jan 2026: 3 incidents Feb 2026: 8 incidents Feb 2026 Mar 2026: 30 incidents Apr 2026: 21 incidents Apr 2026 May 2026: 17 incidents Jun 2026: 16 incidents Jun 2026 Jul 2026: 31 incidents Aug 2026: 24 incidents Aug 2026

Attribution and disclosure

32% with a named threat actor in the registry 48 of 152 incidents
96% with a recorded official cyber disclosure 146 of 152 incidents
52% officially disclosed on the first-signal date 76 of 146 incidents with comparable dates
13.7 mean days to later official disclosure Across 70 incidents disclosed after the first-signal date

Threat actors

Explore
  1. Qilin 6 4%
  2. LockBit 3 2%

5 threat actors tied at 2 incidents; this tied group is not shown.

Footprint

Geographic impact

Explore the incident map

State impact

Bubble area represents incident count; one incident may appear in multiple states.

Ranked by incident count; one incident may appear in multiple states.

State and territory impact bubbles Bubble area represents incident count. Texas: 16 incidents; Minnesota: 12 incidents; Georgia: 10 incidents; Michigan: 10 incidents; California: 9 incidents; Florida: 9 incidents; Massachusetts: 8 incidents; Utah: 7 incidents; Virginia: 7 incidents; Wisconsin: 7 incidents; Pennsylvania: 6 incidents; Illinois: 5 incidents; Iowa: 5 incidents; New Jersey: 5 incidents; North Carolina: 5 incidents; Tennessee: 5 incidents; Arizona: 4 incidents; Indiana: 4 incidents; Mississippi: 4 incidents; New York: 4 incidents; Oklahoma: 4 incidents; Alabama: 3 incidents; Maine: 3 incidents; Missouri: 3 incidents; New Hampshire: 3 incidents; Ohio: 3 incidents; Puerto Rico: 3 incidents; South Carolina: 3 incidents; South Dakota: 3 incidents; Washington: 3 incidents; West Virginia: 3 incidents; Idaho: 2 incidents; Maryland: 2 incidents; North Dakota: 2 incidents; Alaska: 1 incident; Arkansas: 1 incident; Colorado: 1 incident; District of Columbia: 1 incident; Guam: 1 incident; Kansas: 1 incident; Montana: 1 incident; Nebraska: 1 incident; New Mexico: 1 incident; Northern Mariana Islands: 1 incident; Rhode Island: 1 incident 16 Texas 12 Minnesota 10 Georgia 10 Michigan 9 California 9 Florida 8 Massachusetts 7 Utah 7 Virginia 7 Wisconsin 6 Pennsylvania 5 Illinois 5 Iowa 5 New Jersey 5 North Carolina 5 Tennessee 4 Arizona 4 Indiana 4 Mississippi 4 New York 4 Oklahoma 3 Alabama 3 Maine 3 Missouri 3 New Hampshire 3 Ohio 3 Puerto Rico 3 South Carolina 3 South Dakota 3 Washington 3 West Virginia 2 Idaho 2 Maryland 2 North Dakota 1 Alaska 1 Arkansas 1 Colorado 1 District of Columbia 1 Guam 1 Kansas 1 Montana 1 Nebraska 1 New Mexico 1 Northern Mariana Islands 1 Rhode Island

All 45 affected states and territories are shown.

  1. Texas 16 11%
  2. Minnesota 12 8%
  3. Georgia 10 7%
  4. Michigan 10 7%
  5. Florida 9 6%

3 states or territories tied at 7 incidents; this tied group is not shown.

Counties

Showing 6 of 35 counties with repeated impact. 29 counties tied at 2 incidents; this tied group is not shown. 177 additional counties each appeared in one incident.

Cities

Showing 3 of 24 cities with repeated impact. 21 cities tied at 2 incidents; this tied group is not shown. 302 additional cities each appeared in one incident.

Concentration

State-by-sector matrix

Each incident is counted once per state-sector pair.

Incident counts by state or territory and critical infrastructure sector
State or territoryGovernment Services and FacilitiesHealthcare and Public HealthWater and Wastewater SystemsInformation TechnologyCommercial FacilitiesEmergency Services
Texas9221
Minnesota51411
Georgia4131
Michigan3311
California411
Florida5111
Massachusetts3122
Utah141
Affected ecosystem

Organizations and infrastructure

Characteristics

Mechanisms and impacts

Explore relationships

Attack mechanisms

  1. Ransomware 35 23%
  2. Malware 10 7%

Operational impacts

Data impacts

2 impacts tied at 3 incidents; this tied group is not shown.

Extortion indicators

2 indicators tied at 8 incidents; this tied group is not shown.

Public record

Assessment and transparency

Cyber assessment

  1. Confirmed 151 99%

Ransomware confidence

  1. Unresolved 65 43%
  2. Confirmed 27 18%
  3. Low 16 11%
  4. Medium 13 9%
  5. High 7 5%

Cyber transparency

  1. The organization publicly identifies the event as cyber-related.

  2. External sources identified the event as cyber-related before the organization publicly confirmed it.

  3. Only external sources publicly identify the event as cyber-related.

  4. The disruption is documented, but available public information does not yet establish cyber involvement.

Disruption transparency

  1. The organization publicly documents the resulting service disruption.

  2. Credible external sources document the disruption, but the organization does not clearly do so.

  3. No credible public source clearly documents service disruption.

How these figures are calculated

Figures describe published registry coverage, not the prevalence of cyber incidents overall. Incidents are grouped by their canonical incident date rather than publication date.

An incident is counted once within each category. Geographic totals use explicitly impacted incident locations and do not treat an organization headquarters as an impacted place. Municipal impacts roll up to their recorded county and state, with each incident counted once per place. Affected organization counts use primary, victim, operator and owner relationships. Critical infrastructure and organization taxonomies remain separate.

Threat actor figures include only actors attached through eligible public claims. Same-date disclosure compares the calendar date of the first public signal with the calendar date of the official cyber disclosure; it does not measure elapsed hours or response speed. Mean days to later disclosure is the arithmetic mean only among valid intervals greater than zero, so longer intervals have more influence. Missing, invalid or reverse-ordered date pairs are excluded. Empty or unknown values are not inferred.

Registry data last updated Aug 24, 2026.