Skip to content
DysruptionHub registry intelligence

Registry insights

See where documented incidents concentrate, who they affect and how their characteristics change over time.

Reporting period Last 30 days
22 Incidents Documented in this reporting window
Tempo

Incident activity

22 incidents dated in this period

Incident activity over time Sep 8: 0; Sep 9: 0; Sep 10: 1; Sep 11: 2; Sep 12: 0; Sep 13: 1; Sep 14: 0; Sep 15: 0; Sep 16: 1; Sep 17: 2; Sep 18: 1; Sep 19: 0; Sep 20: 1; Sep 21: 1; Sep 22: 1; Sep 23: 1; Sep 24: 0; Sep 25: 1; Sep 26: 0; Sep 27: 0; Sep 28: 0; Sep 29: 1; Sep 30: 1; Oct 1: 1; Oct 2: 4; Oct 3: 0; Oct 4: 1; Oct 5: 1; Oct 6: 0; Oct 7: 0; Oct 8: 0 0 2 4 Sep 8: 0 incidents Sep 8 Sep 9: 0 incidents Sep 10: 1 incident Sep 11: 2 incidents Sep 12: 0 incidents Sep 12 Sep 13: 1 incident Sep 14: 0 incidents Sep 15: 0 incidents Sep 16: 1 incident Sep 16 Sep 17: 2 incidents Sep 18: 1 incident Sep 19: 0 incidents Sep 20: 1 incident Sep 20 Sep 21: 1 incident Sep 22: 1 incident Sep 23: 1 incident Sep 24: 0 incidents Sep 24 Sep 25: 1 incident Sep 26: 0 incidents Sep 27: 0 incidents Sep 28: 0 incidents Sep 28 Sep 29: 1 incident Sep 30: 1 incident Oct 1: 1 incident Oct 2: 4 incidents Oct 2 Oct 3: 0 incidents Oct 4: 1 incident Oct 5: 1 incident Oct 6: 0 incidents Oct 6 Oct 7: 0 incidents Oct 8: 0 incidents Oct 8

Attribution and disclosure

27% with a named threat actor in the registry 6 of 22 incidents
77% with a recorded official cyber disclosure 17 of 22 incidents
59% officially disclosed on the first-signal date 10 of 17 incidents with comparable dates
2.1 mean days to later official disclosure Across 7 incidents disclosed after the first-signal date

Threat actors

Explore
Footprint

Geographic impact

Explore the incident map

State impact

Bubble area represents incident count; one incident may appear in multiple states.

Ranked by incident count; one incident may appear in multiple states.

State and territory impact bubbles Bubble area represents incident count. California: 3 incidents; Louisiana: 2 incidents; Massachusetts: 2 incidents; Missouri: 2 incidents; Utah: 2 incidents; Wisconsin: 2 incidents; Arizona: 1 incident; Colorado: 1 incident; District of Columbia: 1 incident; Florida: 1 incident; Idaho: 1 incident; Illinois: 1 incident; Kansas: 1 incident; Mississippi: 1 incident; North Carolina: 1 incident; Pennsylvania: 1 incident; Tennessee: 1 incident; Texas: 1 incident; Virginia: 1 incident; Washington: 1 incident 3 California 2 Louisiana 2 Massachusetts 2 Missouri 2 Utah 2 Wisconsin 1 Arizona 1 Colorado 1 District of Columbia 1 Florida 1 Idaho 1 Illinois 1 Kansas 1 Mississippi 1 North Carolina 1 Pennsylvania 1 Tennessee 1 Texas 1 Virginia 1 Washington

All 20 affected states and territories are shown.

  1. Utah 2 9%

14 states or territories tied at 1 incident; this tied group is not shown.

Counties

25 additional counties each appeared in one incident.

Cities

29 affected cities

No city appears in more than one incident in this period.

Concentration

State-by-sector matrix

Each incident is counted once per state-sector pair.

Incident counts by state or territory and critical infrastructure sector
State or territoryGovernment Services and FacilitiesInformation TechnologyHealthcare and Public HealthCommunicationsEmergency ServicesFinancial Services
California—2———1
Louisiana1—1———
Massachusetts1—1———
Missouri11————
Utah—1—1——
Wisconsin2—————
Arizona—1————
Colorado1—————
Affected ecosystem

Organizations and infrastructure

Organizations with repeated impact

Explore
22 affected organizations

No organization appears in more than one incident in this period.

Organization types

Critical infrastructure sectors

Incident status

  1. Active 16 73%
  2. Resolved 3 14%
Characteristics

Mechanisms and impacts

Explore relationships
Public record

Assessment and transparency

Cyber assessment

  1. Confirmed 20 91%

Ransomware confidence

  1. Unresolved 16 73%
  2. High 1 5%
  3. Low 1 5%

Cyber transparency

  1. The organization publicly identifies the event as cyber-related.

  2. External sources identified the event as cyber-related before the organization publicly confirmed it.

  3. The disruption is documented, but available public information does not yet establish cyber involvement.

  4. Only external sources publicly identify the event as cyber-related.

Disruption transparency

  1. The organization publicly documents the resulting service disruption.

  2. Credible external sources document the disruption, but the organization does not clearly do so.

  3. No credible public source clearly documents service disruption.

How these figures are calculated

Figures describe published registry coverage, not the prevalence of cyber incidents overall. Incidents are grouped by their canonical incident date rather than publication date.

An incident is counted once within each category. Geographic totals use explicitly impacted incident locations and do not treat an organization headquarters as an impacted place. Municipal impacts roll up to their recorded county and state, with each incident counted once per place. Affected organization counts use primary, victim, operator and owner relationships. Critical infrastructure and organization taxonomies remain separate.

Threat actor figures include only actors attached through eligible public claims. Same-date disclosure compares the calendar date of the first public signal with the calendar date of the official cyber disclosure; it does not measure elapsed hours or response speed. Mean days to later disclosure is the arithmetic mean only among valid intervals greater than zero, so longer intervals have more influence. Missing, invalid or reverse-ordered date pairs are excluded. Empty or unknown values are not inferred.

Registry data last updated Oct 8, 2026.