Registry insights
See where documented incidents concentrate, who they affect and how their characteristics change over time.
Incident activity
22 incidents dated in this period
Attribution and disclosure
Threat actors
Explore-
Booba Project 1 5%
-
INC Ransom 1 5%
-
LAPSUS$ Chapter II 1 5%
-
NightSpire 1 5%
-
ShinyHunters 1 5%
-
Wallstreet 1 5%
Geographic impact
State impact
Bubble area represents incident count; one incident may appear in multiple states.
Ranked by incident count; one incident may appear in multiple states.
All 20 affected states and territories are shown.
-
California 3 14%
-
Louisiana 2 9%
-
Massachusetts 2 9%
-
Missouri 2 9%
-
Utah 2 9%
-
Wisconsin 2 9%
14 states or territories tied at 1 incident; this tied group is not shown.
Counties
25 additional counties each appeared in one incident.
Cities
No city appears in more than one incident in this period.
State-by-sector matrix
Each incident is counted once per state-sector pair.
| State or territory | Government Services and Facilities | Information Technology | Healthcare and Public Health | Communications | Emergency Services | Financial Services |
|---|---|---|---|---|---|---|
| California | — | 2 | — | — | — | 1 |
| Louisiana | 1 | — | 1 | — | — | — |
| Massachusetts | 1 | — | 1 | — | — | — |
| Missouri | 1 | 1 | — | — | — | — |
| Utah | — | 1 | — | 1 | — | — |
| Wisconsin | 2 | — | — | — | — | — |
| Arizona | — | 1 | — | — | — | — |
| Colorado | 1 | — | — | — | — | — |
Organizations and infrastructure
Organizations with repeated impact
ExploreNo organization appears in more than one incident in this period.
Organization types
-
Public Education 6 27%
Critical infrastructure sectors
-
Information Technology 3 14%
-
Communications 1 5%
-
Emergency Services 1 5%
-
Financial Services 1 5%
-
Food and Agriculture 1 5%
Incident status
-
Active 16 73%
-
Resolved 3 14%
-
Presumed Active 2 9%
-
Presumed Resolved 1 5%
Mechanisms and impacts
Attack mechanisms
-
Unknown cyber mechanism 11 50%
-
Unauthorized access 6 27%
-
Ransomware 3 14%
-
Malware 1 5%
-
Website defacement 1 5%
Operational impacts
-
Network outage 5 23%
-
Phone service disruption 5 23%
4 impacts tied at 4 incidents; this tied group is not shown.
Data impacts
-
Unknown data impact 13 59%
-
Data unavailable 4 18%
-
Data exposure 1 5%
Extortion indicators
-
Unknown extortion indicators 11 50%
-
Leak-site listing 2 9%
-
Public leak threat 1 5%
Assessment and transparency
Cyber assessment
-
Confirmed 20 91%
-
Suspected 1 5%
-
Unresolved 1 5%
Ransomware confidence
-
Unresolved 16 73%
-
Confirmed 2 9%
-
Not Ransomware 2 9%
-
High 1 5%
-
Low 1 5%
Cyber transparency
-
Official cyber 15 68%
The organization publicly identifies the event as cyber-related.
-
External sources identified the event as cyber-related before the organization publicly confirmed it.
-
The disruption is documented, but available public information does not yet establish cyber involvement.
-
External cyber only 1 5%
Only external sources publicly identify the event as cyber-related.
Disruption transparency
-
Official disruption 20 91%
The organization publicly documents the resulting service disruption.
-
Credible external sources document the disruption, but the organization does not clearly do so.
-
No disruption cues 1 5%
No credible public source clearly documents service disruption.
How these figures are calculated
Figures describe published registry coverage, not the prevalence of cyber incidents overall. Incidents are grouped by their canonical incident date rather than publication date.
An incident is counted once within each category. Geographic totals use explicitly impacted incident locations and do not treat an organization headquarters as an impacted place. Municipal impacts roll up to their recorded county and state, with each incident counted once per place. Affected organization counts use primary, victim, operator and owner relationships. Critical infrastructure and organization taxonomies remain separate.
Threat actor figures include only actors attached through eligible public claims. Same-date disclosure compares the calendar date of the first public signal with the calendar date of the official cyber disclosure; it does not measure elapsed hours or response speed. Mean days to later disclosure is the arithmetic mean only among valid intervals greater than zero, so longer intervals have more influence. Missing, invalid or reverse-ordered date pairs are excluded. Empty or unknown values are not inferred.