Registry insights
See where documented incidents concentrate, who they affect and how their characteristics change over time.
Incident activity
225 incidents dated in this period
Attribution and disclosure
Threat actors
Explore-
Interlock 11 5%
-
INC Ransom 10 4%
-
Qilin 9 4%
-
ShinyHunters 5 2%
-
NightSpire 4 2%
5 threat actors tied at 3 incidents; this tied group is not shown.
Geographic impact
State impact
Bubble area represents incident count; one incident may appear in multiple states.
Ranked by incident count; one incident may appear in multiple states.
All 52 affected states and territories are shown.
-
Texas 22 10%
-
California 20 9%
-
Georgia 15 7%
-
Michigan 14 6%
-
Florida 13 6%
-
Massachusetts 13 6%
-
Minnesota 13 6%
-
Pennsylvania 10 4%
Counties
Showing 5 of 57 counties with repeated impact. 4 counties tied at 4 incidents; this tied group is not shown. 238 additional counties each appeared in one incident.
Cities
Showing 2 of 34 cities with repeated impact. 8 cities tied at 3 incidents; this tied group is not shown. 430 additional cities each appeared in one incident.
State-by-sector matrix
Each incident is counted once per state-sector pair.
| State or territory | Government Services and Facilities | Healthcare and Public Health | Information Technology | Water and Wastewater Systems | Emergency Services | Financial Services |
|---|---|---|---|---|---|---|
| Texas | 11 | 4 | 3 | — | 1 | 1 |
| California | 8 | 3 | 4 | — | — | 1 |
| Georgia | 6 | 2 | 1 | 3 | — | 2 |
| Michigan | 3 | 3 | 1 | 3 | — | 1 |
| Florida | 5 | 2 | 2 | — | 1 | 1 |
| Massachusetts | 6 | 3 | 2 | — | 2 | — |
| Minnesota | 5 | 2 | 1 | 4 | — | — |
| Pennsylvania | 7 | 2 | — | — | — | 1 |
Organizations and infrastructure
Organizations with repeated impact
Explore-
Winona County 2 1%
242 additional organizations each appeared in one incident.
Organization types
-
Public Education 41 18%
-
K-12 school district / LEA 30 13%
3 organization types tied at 14 incidents; this tied group is not shown.
Critical infrastructure sectors
-
Healthcare and Public Health 27 12%
-
Information Technology 18 8%
-
Emergency Services 11 5%
-
Financial Services 10 4%
Incident status
-
Presumed Resolved 101 45%
-
Resolved 87 39%
-
Active 24 11%
-
Presumed Active 13 6%
Mechanisms and impacts
Attack mechanisms
-
Unknown cyber mechanism 100 44%
-
Unauthorized access 74 33%
-
Ransomware 51 23%
-
Malware 14 6%
-
Data extortion 10 4%
-
Website defacement 4 2%
Operational impacts
-
Internal systems unavailable 119 53%
-
Partial service outage 77 34%
-
Network outage 73 32%
-
Manual workaround required 59 26%
3 impacts tied at 42 incidents; this tied group is not shown.
Data impacts
-
Unknown data impact 94 42%
-
Data unavailable 74 33%
-
Data theft or exfiltration 36 16%
-
Unauthorized data access 27 12%
-
No known data impact 18 8%
-
Data encryption 16 7%
-
Data publication or leak 10 4%
3 impacts tied at 4 incidents; this tied group is not shown.
Extortion indicators
-
No known extortion indicator 76 34%
-
Leak-site listing 63 28%
-
Unknown extortion indicators 44 20%
-
Public leak threat 28 12%
-
Data-theft extortion 27 12%
-
Ransom demand 26 12%
-
Direct victim contact 15 7%
Assessment and transparency
Cyber assessment
-
Confirmed 221 98%
-
Suspected 2 1%
-
Unresolved 2 1%
Ransomware confidence
-
Unresolved 98 44%
-
Confirmed 41 18%
-
Not Ransomware 29 13%
-
Low 27 12%
-
Medium 18 8%
-
High 11 5%
-
Suspected 1 0%
Cyber transparency
-
Official cyber 188 84%
The organization publicly identifies the event as cyber-related.
-
External sources identified the event as cyber-related before the organization publicly confirmed it.
-
External cyber only 11 5%
Only external sources publicly identify the event as cyber-related.
-
The disruption is documented, but available public information does not yet establish cyber involvement.
Disruption transparency
-
Official disruption 210 93%
The organization publicly documents the resulting service disruption.
-
Credible external sources document the disruption, but the organization does not clearly do so.
-
No disruption cues 7 3%
No credible public source clearly documents service disruption.
How these figures are calculated
Figures describe published registry coverage, not the prevalence of cyber incidents overall. Incidents are grouped by their canonical incident date rather than publication date.
An incident is counted once within each category. Geographic totals use explicitly impacted incident locations and do not treat an organization headquarters as an impacted place. Municipal impacts roll up to their recorded county and state, with each incident counted once per place. Affected organization counts use primary, victim, operator and owner relationships. Critical infrastructure and organization taxonomies remain separate.
Threat actor figures include only actors attached through eligible public claims. Same-date disclosure compares the calendar date of the first public signal with the calendar date of the official cyber disclosure; it does not measure elapsed hours or response speed. Mean days to later disclosure is the arithmetic mean only among valid intervals greater than zero, so longer intervals have more influence. Missing, invalid or reverse-ordered date pairs are excluded. Empty or unknown values are not inferred.