Skip to content
DysruptionHub registry intelligence

Registry insights

See where documented incidents concentrate, who they affect and how their characteristics change over time.

294 Incidents Documented in this reporting window
Tempo

Incident activity

294 incidents dated in this period

Incident activity over time 2021: 1; 2022: 0; 2023: 2; 2024: 1; 2025: 65; 2026: 225 0 113 225 2021: 1 incident 2021 2022: 0 incidents 2022 2023: 2 incidents 2023 2024: 1 incident 2024 2025: 65 incidents 2025 2026: 225 incidents 2026

Attribution and disclosure

35% with a named threat actor in the registry 102 of 294 incidents
83% with a recorded official cyber disclosure 245 of 294 incidents
54% officially disclosed on the first-signal date 132 of 245 incidents with comparable dates
14.3 mean days to later official disclosure Across 113 incidents disclosed after the first-signal date

Threat actors

Explore
  1. Qilin 17 6%
  2. Interlock 15 5%
  3. Rhysida 6 2%

6 threat actors tied at 3 incidents; this tied group is not shown.

Footprint

Geographic impact

Explore the incident map

State impact

Bubble area represents incident count; one incident may appear in multiple states.

Ranked by incident count; one incident may appear in multiple states.

State and territory impact bubbles Bubble area represents incident count. Texas: 27 incidents; California: 24 incidents; Georgia: 17 incidents; Michigan: 16 incidents; Florida: 15 incidents; Massachusetts: 15 incidents; Pennsylvania: 15 incidents; Ohio: 14 incidents; Minnesota: 13 incidents; North Carolina: 11 incidents; Utah: 10 incidents; Virginia: 10 incidents; Wisconsin: 10 incidents; Illinois: 9 incidents; New Jersey: 9 incidents; Tennessee: 9 incidents; Mississippi: 8 incidents; New York: 8 incidents; Oklahoma: 8 incidents; Indiana: 7 incidents; Kansas: 7 incidents; Washington: 7 incidents; Alabama: 6 incidents; Arizona: 6 incidents; Iowa: 6 incidents; Missouri: 6 incidents; South Carolina: 6 incidents; Idaho: 5 incidents; New Hampshire: 5 incidents; Puerto Rico: 5 incidents; Colorado: 4 incidents; District of Columbia: 4 incidents; Maryland: 4 incidents; New Mexico: 4 incidents; North Dakota: 4 incidents; Oregon: 4 incidents; Arkansas: 3 incidents; Connecticut: 3 incidents; Louisiana: 3 incidents; Maine: 3 incidents; Nebraska: 3 incidents; Rhode Island: 3 incidents; South Dakota: 3 incidents; West Virginia: 3 incidents; Alaska: 2 incidents; Montana: 2 incidents; Vermont: 2 incidents; Wyoming: 2 incidents; Delaware: 1 incident; Guam: 1 incident; Kentucky: 1 incident; Northern Mariana Islands: 1 incident; U.S. Virgin Islands: 1 incident 27 Texas 24 California 17 Georgia 16 Michigan 15 Florida 15 Massachusetts 15 Pennsylvania 14 Ohio 13 Minnesota 11 North Carolina 10 Utah 10 Virginia 10 Wisconsin 9 Illinois 9 New Jersey 9 Tennessee 8 Mississippi 8 New York 8 Oklahoma 7 Indiana 7 Kansas 7 Washington 6 Alabama 6 Arizona 6 Iowa 6 Missouri 6 South Carolina 5 Idaho 5 New Hampshire 5 Puerto Rico 4 Colorado 4 District of Columbia 4 Maryland 4 New Mexico 4 North Dakota 4 Oregon 3 Arkansas 3 Connecticut 3 Louisiana 3 Maine 3 Nebraska 3 Rhode Island 3 South Dakota 3 West Virginia 2 Alaska 2 Montana 2 Vermont 2 Wyoming 1 Delaware 1 Guam 1 Kentucky 1 Northern Mariana Islands 1 U.S. Virgin Islands

All 53 affected states and territories are shown.

  1. Texas 27 9%
  2. Georgia 17 6%
  3. Michigan 16 5%
  4. Florida 15 5%
  5. Ohio 14 5%

Counties

Showing 6 of 75 counties with repeated impact. 4 counties tied at 4 incidents; this tied group is not shown. 273 additional counties each appeared in one incident.

Cities

Showing 2 of 54 cities with repeated impact. 8 cities tied at 3 incidents; this tied group is not shown. 513 additional cities each appeared in one incident.

Concentration

State-by-sector matrix

Each incident is counted once per state-sector pair.

Incident counts by state or territory and critical infrastructure sector
State or territoryGovernment Services and FacilitiesHealthcare and Public HealthInformation TechnologyEmergency ServicesWater and Wastewater SystemsCommercial Facilities
Texas16431——
California1044——1
Georgia722—3—
Michigan432—31
Florida6222—1
Massachusetts7422——
Pennsylvania112————
Ohio91111—
Affected ecosystem

Organizations and infrastructure

Organizations with repeated impact

Explore

312 additional organizations each appeared in one incident.

Organization types

3 organization types tied at 16 incidents; this tied group is not shown.

Critical infrastructure sectors

Incident status

  1. Resolved 109 37%
  2. Active 24 8%
Characteristics

Mechanisms and impacts

Explore relationships

Attack mechanisms

  1. Ransomware 65 22%
  2. Malware 14 5%

2 mechanisms tied at 5 incidents; this tied group is not shown.

Operational impacts

Data impacts

Extortion indicators

2 indicators tied at 16 incidents; this tied group is not shown.

Public record

Assessment and transparency

Cyber assessment

  1. Confirmed 283 96%

Ransomware confidence

  1. Unresolved 122 41%
  2. Confirmed 48 16%
  3. Low 45 15%
  4. Medium 22 7%
  5. High 18 6%

Cyber transparency

  1. The organization publicly identifies the event as cyber-related.

  2. External sources identified the event as cyber-related before the organization publicly confirmed it.

  3. Only external sources publicly identify the event as cyber-related.

  4. The disruption is documented, but available public information does not yet establish cyber involvement.

Disruption transparency

  1. The organization publicly documents the resulting service disruption.

  2. Credible external sources document the disruption, but the organization does not clearly do so.

  3. No credible public source clearly documents service disruption.

How these figures are calculated

Figures describe published registry coverage, not the prevalence of cyber incidents overall. Incidents are grouped by their canonical incident date rather than publication date.

An incident is counted once within each category. Geographic totals use explicitly impacted incident locations and do not treat an organization headquarters as an impacted place. Municipal impacts roll up to their recorded county and state, with each incident counted once per place. Affected organization counts use primary, victim, operator and owner relationships. Critical infrastructure and organization taxonomies remain separate.

Threat actor figures include only actors attached through eligible public claims. Same-date disclosure compares the calendar date of the first public signal with the calendar date of the official cyber disclosure; it does not measure elapsed hours or response speed. Mean days to later disclosure is the arithmetic mean only among valid intervals greater than zero, so longer intervals have more influence. Missing, invalid or reverse-ordered date pairs are excluded. Empty or unknown values are not inferred.

Registry data last updated Oct 8, 2026.