Leak-site claims
Ransomware groups run extortion sites where they post the names of organisations they say they have compromised. This page counts those posts. It shows no names and there is no way to look one up here — for anybody, at any price. What the counts mean.
“Not attributed to a country” is not a place. Every per-country figure on this page is a floor rather than a total. How the country filter counts
1,034 claims counted for worldwide between 2026-08-25 and 2026-09-23, with 2 of 2 feeds recent enough for their own cadence. Each is a post a criminal group published about somebody else, and we have verified none of them. Before you read these numbers
Claims over time
worldwide · 30 days to 2026-09-23
The later half of this window holds 480 claims against 554 in the earlier half — 13.4% down. That compares the later half of the window against the earlier half, not this quarter against last: a figure drawn from claims outside the window would be one a reader cannot check against anything on this page.
By sector
worldwide · claims in this window
- Not stated by the source35234%
- Manufacturing14814.3%
- Technology1009.7%
- Professional services999.6%
- Healthcare807.7%
- Consumer goods555.3%
- Financial services393.8%
- Transport and logistics343.3%
- Education333.2%
- Agriculture and food production262.5%
- Government and public sector252.4%
- Hospitality and tourism222.1%
- Energy and utilities212%
The ring shows shares of this window; the bars beside each row compare counts against the largest sector, which is a different question and is why both are drawn. A percentage is published only where the sector carries at least 5 claims in this window; anything thinner shows a dash, because a share computed from three claims is a number with no information in it. 8 further sectors in the taxonomy hold no claims in this window. 352 of 1034 carry no sector, because the source did not state one — they are counted here rather than dropped, so the totals stay honest. That is 34% of the window.
Groups publishing the most claims
Worldwide · last 30 days
| Group | Claims | Most recent |
|---|---|---|
| the gentlemen | 101 | |
| qilin | 100 | |
| storm | 52 | |
| krybit | 44 | |
| akira | 43 | |
| inc ransom | 35 | |
| AuditTeam | 32 | |
| audit team | 29 | |
| settra | 29 | |
| zawoo | 28 |
It is materialized separately from the totals above, so these counts are not a subset of them and dividing one by the other produces a share of nothing. Names are the groups’ own branding, resolved through known aliases so a rebrand does not read as a newcomer. A group marked thin published fewer than 5 claims in this window, which is too few to rank it against the others. Claim counts measure how much a group posted, not how successful it was.
Every feed was recent enough for its own cadence when these figures were computed. A green state means we reached the source, not that what it holds is current. The feeds behind these counts
Reference
Before you read these numbers
- What we read. 2 of 2 leak-site feeds answered recently enough for their own refresh cadence. The newest claim we hold from any source is dated 2026-09-23 (0 days ago), which is the figure that tells you whether the pipeline is current — a feed can answer every request and still be a historical archive. The set of extortion sites those feeds monitor is not every extortion site, and a group that publishes nowhere we read is counted nowhere on this page.
- What the window says. 1,034 claims counted for worldwide between 2026-08-25 and 2026-09-23, the most recent dated 2026-09-23. Each one is a post a criminal group published about somebody else. We have not verified any of them, the organisations named have generally not commented, and some posts are duplicates, exaggerations or fabrications.
- What sits behind this window. We hold 31,900 claims in total, dated 2020-01-01 to 2026-09-23. The window above is a slice of that and not the total, and the corpus is kept as counts by day, country, sector and group — never as a list of names.
- How much of this carries a country. 268 of the 1,034 claims counted here arrived with no country from the source (25.9%). They sit in the “not attributed” bucket rather than being guessed into a country, which is why every per-country figure on this page is a floor and not a total.
- What this is not. It is not a count of organisations harmed, and a rise or fall says as much about how many leak sites we could read this month as about what groups did. Nothing here is evidence about any particular company, and we publish no names precisely so it cannot be used as if it were.
How the country filter counts
We did not determine your country, so this page opened on the worldwide figure rather than guessing one. “Not attributed” is the bucket for claims whose source named no country, and it is where most historical rows sit. Filtering to a country therefore counts less than the true figure for that country, because a claim we could not place is never guessed into one.
The feeds behind these counts
How current each source is.
| Source | State | Last successful read | Refreshed every | Recent enough to rely on |
|---|---|---|---|---|
| ransomlook | answering | every 1 hour | yes | |
| ransomware.live | answering | every 1 hour | yes |
Every feed was recent enough for its own cadence when these figures were computed. A green state means we reached the source, not that what it holds is current.
- ransomlook — Answered within its own refresh cadence. That means we reached it — see the note below the table for what it does not mean.
- ransomware.live — Answered within its own refresh cadence. That means we reached it — see the note below the table for what it does not mean.
A source can answer every request and still be a historical archive that stopped publishing a year ago, so read a green state as “we reached it” rather than as “what it holds is current”. This table cannot yet show the newest claim each individual source carries; the figure for the corpus as a whole is above. What a feed reports about itself is also the only thing measured here: none of it says anything about extortion sites nobody reads.