Registry insights
See where documented incidents concentrate, who they affect and how their characteristics change over time.
Incident activity
294 incidents dated in this period
Attribution and disclosure
Threat actors
Explore-
Qilin 17 6%
-
Interlock 15 5%
-
INC Ransom 12 4%
-
Rhysida 6 2%
-
ShinyHunters 6 2%
-
NightSpire 4 1%
6 threat actors tied at 3 incidents; this tied group is not shown.
Geographic impact
State impact
Bubble area represents incident count; one incident may appear in multiple states.
Ranked by incident count; one incident may appear in multiple states.
All 53 affected states and territories are shown.
-
Texas 27 9%
-
California 24 8%
-
Georgia 17 6%
-
Michigan 16 5%
-
Florida 15 5%
-
Massachusetts 15 5%
-
Pennsylvania 15 5%
-
Ohio 14 5%
Counties
Showing 6 of 75 counties with repeated impact. 4 counties tied at 4 incidents; this tied group is not shown. 273 additional counties each appeared in one incident.
Cities
Showing 2 of 54 cities with repeated impact. 8 cities tied at 3 incidents; this tied group is not shown. 513 additional cities each appeared in one incident.
State-by-sector matrix
Each incident is counted once per state-sector pair.
| State or territory | Government Services and Facilities | Healthcare and Public Health | Information Technology | Emergency Services | Water and Wastewater Systems | Commercial Facilities |
|---|---|---|---|---|---|---|
| Texas | 16 | 4 | 3 | 1 | — | — |
| California | 10 | 4 | 4 | — | — | 1 |
| Georgia | 7 | 2 | 2 | — | 3 | — |
| Michigan | 4 | 3 | 2 | — | 3 | 1 |
| Florida | 6 | 2 | 2 | 2 | — | 1 |
| Massachusetts | 7 | 4 | 2 | 2 | — | — |
| Pennsylvania | 11 | 2 | — | — | — | — |
| Ohio | 9 | 1 | 1 | 1 | 1 | — |
Organizations and infrastructure
Organizations with repeated impact
Explore-
Winona County 2 1%
312 additional organizations each appeared in one incident.
Organization types
-
Public Education 58 20%
-
K-12 school district / LEA 45 15%
-
Public Safety & Justice 18 6%
3 organization types tied at 16 incidents; this tied group is not shown.
Critical infrastructure sectors
-
Healthcare and Public Health 31 11%
-
Information Technology 22 7%
-
Emergency Services 17 6%
-
Commercial Facilities 11 4%
-
Financial Services 10 3%
Incident status
-
Presumed Resolved 148 50%
-
Resolved 109 37%
-
Active 24 8%
-
Presumed Active 13 4%
Mechanisms and impacts
Attack mechanisms
-
Unknown cyber mechanism 129 44%
-
Unauthorized access 85 29%
-
Ransomware 65 22%
-
Malware 14 5%
-
Data extortion 12 4%
2 mechanisms tied at 5 incidents; this tied group is not shown.
Operational impacts
-
Internal systems unavailable 160 54%
-
Network outage 92 31%
-
Partial service outage 85 29%
-
Manual workaround required 70 24%
-
Phone service disruption 62 21%
Data impacts
-
Unknown data impact 122 41%
-
Data unavailable 80 27%
-
Data theft or exfiltration 45 15%
-
Unauthorized data access 43 15%
-
No known data impact 19 6%
-
Data encryption 18 6%
-
Data publication or leak 12 4%
-
Data exposure 8 3%
Extortion indicators
-
No known extortion indicator 83 28%
-
Leak-site listing 80 27%
-
Unknown extortion indicators 73 25%
-
Ransom demand 32 11%
-
Public leak threat 31 11%
-
Data-theft extortion 29 10%
2 indicators tied at 16 incidents; this tied group is not shown.
Assessment and transparency
Cyber assessment
-
Confirmed 283 96%
-
Suspected 9 3%
-
Unresolved 2 1%
Ransomware confidence
-
Unresolved 122 41%
-
Confirmed 48 16%
-
Low 45 15%
-
Not Ransomware 34 12%
-
Medium 22 7%
-
High 18 6%
-
Suspected 1 0%
Cyber transparency
-
Official cyber 231 79%
The organization publicly identifies the event as cyber-related.
-
External sources identified the event as cyber-related before the organization publicly confirmed it.
-
External cyber only 26 9%
Only external sources publicly identify the event as cyber-related.
-
The disruption is documented, but available public information does not yet establish cyber involvement.
Disruption transparency
-
Official disruption 263 89%
The organization publicly documents the resulting service disruption.
-
External disruption only 23 8%
Credible external sources document the disruption, but the organization does not clearly do so.
-
No disruption cues 8 3%
No credible public source clearly documents service disruption.
How these figures are calculated
Figures describe published registry coverage, not the prevalence of cyber incidents overall. Incidents are grouped by their canonical incident date rather than publication date.
An incident is counted once within each category. Geographic totals use explicitly impacted incident locations and do not treat an organization headquarters as an impacted place. Municipal impacts roll up to their recorded county and state, with each incident counted once per place. Affected organization counts use primary, victim, operator and owner relationships. Critical infrastructure and organization taxonomies remain separate.
Threat actor figures include only actors attached through eligible public claims. Same-date disclosure compares the calendar date of the first public signal with the calendar date of the official cyber disclosure; it does not measure elapsed hours or response speed. Mean days to later disclosure is the arithmetic mean only among valid intervals greater than zero, so longer intervals have more influence. Missing, invalid or reverse-ordered date pairs are excluded. Empty or unknown values are not inferred.