Skip to content
DysruptionHub registry intelligence

Registry insights

See where documented incidents concentrate, who they affect and how their characteristics change over time.

Reporting period Last 30 days
39 Incidents Documented in this reporting window
Tempo

Incident activity

39 incidents dated in this period

Incident activity over time Jul 25: 0; Jul 26: 2; Jul 27: 11; Jul 28: 0; Jul 29: 0; Jul 30: 1; Jul 31: 1; Aug 1: 0; Aug 2: 0; Aug 3: 2; Aug 4: 2; Aug 5: 2; Aug 6: 3; Aug 7: 4; Aug 8: 0; Aug 9: 0; Aug 10: 2; Aug 11: 1; Aug 12: 1; Aug 13: 4; Aug 14: 0; Aug 15: 1; Aug 16: 1; Aug 17: 1; Aug 18: 0; Aug 19: 0; Aug 20: 0; Aug 21: 0; Aug 22: 0; Aug 23: 0; Aug 24: 0 0 6 11 Jul 25: 0 incidents Jul 25 Jul 26: 2 incidents Jul 27: 11 incidents Jul 28: 0 incidents Jul 29: 0 incidents Jul 29 Jul 30: 1 incident Jul 31: 1 incident Aug 1: 0 incidents Aug 2: 0 incidents Aug 2 Aug 3: 2 incidents Aug 4: 2 incidents Aug 5: 2 incidents Aug 6: 3 incidents Aug 6 Aug 7: 4 incidents Aug 8: 0 incidents Aug 9: 0 incidents Aug 10: 2 incidents Aug 10 Aug 11: 1 incident Aug 12: 1 incident Aug 13: 4 incidents Aug 14: 0 incidents Aug 14 Aug 15: 1 incident Aug 16: 1 incident Aug 17: 1 incident Aug 18: 0 incidents Aug 18 Aug 19: 0 incidents Aug 20: 0 incidents Aug 21: 0 incidents Aug 22: 0 incidents Aug 22 Aug 23: 0 incidents Aug 24: 0 incidents Aug 24

Attribution and disclosure

13% with a named threat actor in the registry 5 of 39 incidents
97% with a recorded official cyber disclosure 38 of 39 incidents
66% officially disclosed on the first-signal date 25 of 38 incidents with comparable dates
3.5 mean days to later official disclosure Across 13 incidents disclosed after the first-signal date

Threat actors

Explore
  1. Storm 1 3%
Footprint

Geographic impact

Explore the incident map

State impact

Bubble area represents incident count; one incident may appear in multiple states.

Ranked by incident count; one incident may appear in multiple states.

State and territory impact bubbles Bubble area represents incident count. Georgia: 5 incidents; Minnesota: 4 incidents; Texas: 4 incidents; New Jersey: 3 incidents; Illinois: 2 incidents; Massachusetts: 2 incidents; New York: 2 incidents; North Carolina: 2 incidents; Oklahoma: 2 incidents; South Carolina: 2 incidents; South Dakota: 2 incidents; Alabama: 1 incident; Alaska: 1 incident; Arizona: 1 incident; Arkansas: 1 incident; California: 1 incident; Florida: 1 incident; Kansas: 1 incident; Maine: 1 incident; Michigan: 1 incident; Pennsylvania: 1 incident; Wisconsin: 1 incident 5 Georgia 4 Minnesota 4 Texas 3 New Jersey 2 Illinois 2 Massachusetts 2 New York 2 North Carolina 2 Oklahoma 2 South Carolina 2 South Dakota 1 Alabama 1 Alaska 1 Arizona 1 Arkansas 1 California 1 Florida 1 Kansas 1 Maine 1 Michigan 1 Pennsylvania 1 Wisconsin

All 22 affected states and territories are shown.

  1. Georgia 5 13%
  2. Minnesota 4 10%
  3. Texas 4 10%

7 states or territories tied at 2 incidents; this tied group is not shown.

Counties

42 additional counties each appeared in one incident.

Cities

62 affected cities

No city appears in more than one incident in this period.

Concentration

State-by-sector matrix

Each incident is counted once per state-sector pair.

Incident counts by state or territory and critical infrastructure sector
State or territoryGovernment Services and FacilitiesWater and Wastewater SystemsHealthcare and Public HealthEmergency ServicesInformation TechnologyTransportation Systems
Georgia131
Minnesota4
Texas31
New Jersey3
Illinois1
Massachusetts11
New York1
North Carolina11
Affected ecosystem

Organizations and infrastructure

Organizations with repeated impact

Explore
40 affected organizations

No organization appears in more than one incident in this period.

Organization types

4 organization types tied at 2 incidents; this tied group is not shown.

Critical infrastructure sectors

Incident status

  1. Active 19 49%
  2. Resolved 13 33%
Characteristics

Mechanisms and impacts

Explore relationships

Attack mechanisms

  1. Malware 2 5%

Operational impacts

4 impacts tied at 8 incidents; this tied group is not shown.

Data impacts

Extortion indicators

6 indicators tied at 2 incidents; this tied group is not shown.

Public record

Assessment and transparency

Cyber assessment

  1. Confirmed 38 97%

Ransomware confidence

  1. Unresolved 24 62%
  2. Low 4 10%
  3. Medium 2 5%
  4. High 1 3%

Cyber transparency

  1. The organization publicly identifies the event as cyber-related.

  2. External sources identified the event as cyber-related before the organization publicly confirmed it.

  3. The disruption is documented, but available public information does not yet establish cyber involvement.

Disruption transparency

  1. The organization publicly documents the resulting service disruption.

  2. No credible public source clearly documents service disruption.

  3. Credible external sources document the disruption, but the organization does not clearly do so.

How these figures are calculated

Figures describe published registry coverage, not the prevalence of cyber incidents overall. Incidents are grouped by their canonical incident date rather than publication date.

An incident is counted once within each category. Geographic totals use explicitly impacted incident locations and do not treat an organization headquarters as an impacted place. Municipal impacts roll up to their recorded county and state, with each incident counted once per place. Affected organization counts use primary, victim, operator and owner relationships. Critical infrastructure and organization taxonomies remain separate.

Threat actor figures include only actors attached through eligible public claims. Same-date disclosure compares the calendar date of the first public signal with the calendar date of the official cyber disclosure; it does not measure elapsed hours or response speed. Mean days to later disclosure is the arithmetic mean only among valid intervals greater than zero, so longer intervals have more influence. Missing, invalid or reverse-ordered date pairs are excluded. Empty or unknown values are not inferred.

Registry data last updated Aug 24, 2026.