External exposure monitoring, weighted to the routes ransomware crews take in
Free, and built on public sources. Alongside it we count what extortion groups publish on their leak sites — the panel below is that count, open to anyone.
Window: last 90 days
26 Jun 2026 — 23 Sept 2026
Ransomware claims, worldwide
Full statisticsWhat extortion groups publish on their own leak sites, counted. No organisation names — none are shown here, and none can be looked up.
Worldwide, 26 Jun 2026 to 23 Sept 2026. Published by extortion groups, not verified by us.
Everything we hold, 1 Jan 2020 to 23 Sept 2026. One organisation can appear more than once.
How current the corpus is, which is a different question from whether the feeds answered.
Groups claiming in the last 90 days
- the gentlemen368yesterday
- qilin361today
- inc ransom1122d ago
- krybit942d ago
- deadlock9129d ago
- storm86yesterday
- akira85today
- settra76today
The group’s own branding, resolved through known aliases so a rebrand does not read as a newcomer, with the number of claims it published and when it last posted. Ordered by claims. A group marked thin published fewer than 5 claims, which is below the floor we require before describing anything as a pattern. These counts are materialized separately from the window total above, so they are not expected to sum to it.
Where claims are attributed · last 90 days
Equirectangular projection on a 30° graticule — no coastlines are drawn, because a rough one would be read as an accurate one. Circle area, not radius, is proportional to the number of claims recorded.
Most claims recorded
- United States955
- Not attributed to a country395not on map
- Germany160
- United Kingdom109
- Italy103
- Canada84
- India77
- Brazil75
114 further countries carried at least one claim in this window. The statistics page lists them.
The country is the source’s attribution, which is usually the named organisation’s stated head office rather than where anything took place. Counts only — no percentage is published per country, because most of these cells sit below the floor of 5 claims.
395 claims name no country and are shown in the list, never on the map. Placing them somewhere would invent an attribution the source did not make; dropping them would present the countries above as the whole picture. That is 13.3% of the window.
43 countries in the list (60 claims) has no entry in our coordinate table and is not drawn. The figure is not lost — it is in the ranked list, marked not on map.
What ransomware groups are claiming
The aggregate behind the counts: which sectors are named, how the window is distributed, and how current it is.
Sectors named
- Not stated by the source646 · 21.7%
- Manufacturing456 · 15.3%
- Professional services394 · 13.2%
- Technology357 · 12%
- Healthcare262 · 8.8%
- Consumer goods187 · 6.3%
- Financial services146 · 4.9%
A share is published only where the sector carries at least 5 claims in this window; thinner cells show a count and a dash. Claims whose source stated no sector are counted in their own row rather than dropped, so the totals stay honest. That row is 21.7% of the window.
Claims per day
90 of the 90 days in this window carried a claim we recorded. A day with no bar is a day we counted nothing, which is a statement about our reading rather than about what was published.
Recency
- Latest claim in this window
- 23 Sept 2026
- Corpus starts
- 1 Jan 2020
- Aggregates as of
- 23 Sept, 05:00 UTC
Ingestion and aggregation are separate jobs, so a healthy feed and a frozen number can happen at once. Both timestamps are shown for that reason. Responses are cached for up to 60 minutes, so nothing here updates while you watch it.
What this is not
Stated here rather than in a terms page, because it changes what the rest of this screen means.
- We correlate information that is already public. We do not see inside your network, we do not read your email, and we do not detect compromise.
- We make no claim to have found everything. External exposure only — absence of findings does not mean absence of compromise.
- Nothing is sent at your infrastructure until you prove you control the domain with a DNS record or a file on your webserver. Before that, we read public datasets and nothing else. Verifying your email address does not change this.
- The risk score is a relative indicator for comparing your own exposure over time, not a measure of whether you will be hit.
- The figures on this screen are claims made by criminal groups about other organisations. We do not verify them, and a group naming someone is not evidence that anything happened.
Counts reflect claims published on extortion leak sites. Claims are made by criminal groups, are frequently unverified, and may be duplicated, exaggerated or false.
What an extortion crew can see of you from the outside
Sentinel Surface watches your organisation’s internet-facing footprint — domains, certificates, exposed services, email posture — and weights what it finds towards the routes ransomware crews actually take in. It also matches the leak-site claims above against your own verified domains, so you hear it from us rather than from a journalist.
Every module that fails is reported as a failure rather than passed over, and every source shows when it last answered. A quiet scan that looks like a clean bill of health is the worst thing this product could hand you.
- 01Register with a work address at the domain itself. Free mailbox providers are refused — we need to know who is asking.
- 02We read public sources straight away — certificate transparency, passive DNS, DNS posture. Nothing is sent at your infrastructure at this stage.
- 03Prove you control the domain with a DNS TXT record or a file on your webserver. Only that unlocks connect-level checks, and it is re-checked every 90 days.
- 04Findings, a score and alerts by email, webhook or Slack when something material changes — including a leak-site claim matching your own domain.