Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

Ransomtracker

THE TRACKER

Ransomtracker

A continuously updated index of active ransomware operations and their published victims. Built to make the leak-site economy visible, searchable, and citable.

Browse the index ↓
Read methodology
Editorial coverage →
— Groups tracked
— Victims this month
— Victims year-to-date
— New in last 24h
— Last sync

Loading live counts…


CONFIRMED ATTACKS

The verified layer

Everything below the counters is what the operators claim. This section is what has been independently confirmed: a human-verified dataset of 9,711 ransomware attacks since 2018, geocoded and classified by industry across 149 countries. Curated continuously; updated weekly.

—Confirmed attacks
—Countries
—Confirmed this year
—Last updated
Loading map…
—
Source: ransomnews.com/ransomtracker
DateOrganisationLocationSectorStrainRecordsSrc
Loading confirmed attacks…
—
About this data

The confirmed layer is a proprietary Ransomnews dataset of ransomware attacks that have been independently verified through breach disclosures, regulatory filings, official statements or credible press reporting, rather than taken from leak-site claims alone. Coverage runs from 2018 to the present, is refreshed weekly, and spans 149 countries.

Each record carries the attack month, victim organisation, city and country (geocoded), industry and sub-industry classification, the ransomware strain where attributed, and, where known, records affected, whether a ransom was paid, and the amount demanded or paid. Financial details are published only where they are on the record: most confirmed incidents never disclose them.

A confirmed incident here is not the same as a leak-site listing above. Many confirmed attacks never appear on a leak site; many leak-site claims are never independently confirmed. The two layers together are the point: claims show operator behaviour, confirmations show real-world impact.

Researchers and journalists are welcome to cite this dataset as Ransomnews Confirmed Ransomware Attacks Dataset, with a link to this page. For bulk access, corrections, or questions about individual records: [email protected].


SEARCH

Find a gang or victim

/ search

Searches active threat groups, victims listed across the trailing two years and, for a domain, infostealer-log exposure and affected services.


LATEST ACTIVITY

Recent victim listings

The ten most recently published victims across all tracked operations. Pulled live from the tracker; refreshes every page load.

Loading latest activity…

OPERATORS

Active operations

The most active operators by recent victim listings, with status. Green = leak site live, amber = dormant, red = seized or known dark.

Loading operator list…

TRENDS

Track trends

Monthly and yearly aggregate views show how the leak-site economy is shifting, which groups are rising, which are dying, and how takedowns reshape the field.

Activity over time

Computing…
Year-to-date

Top operators by claimed victims

Computing…
Year-to-date

Victims by domain TLD

Computing…
Year-to-date

Posting rhythm by day of week

Computing…

BROWSE

Browse the index

Filter by year, by operator, or both. Default view shows the latest victims across every tracked operator. Click any operator name to open the per-actor profile.

— Any year — — Loading operators — —
Loading latest activity…

CONFIRMED

Confirmed ransomware attacks, by the numbers

Leak-site listings are what operators claim. Below is the verified layer: incidents Ransomnews has independently confirmed against a named public source. Figures recalculate from the live database.

Ransomnews has independently confirmed 9,711 ransomware attacks worldwide between January 2018 and October 2026. So far in 2026, 872 attacks have been confirmed, including 5 in October 2026. The dataset covers 153 countries, is verified by humans rather than scraped from leak sites, and every figure on this page is recalculated from the live database, refreshed weekly.

Data last updated: 7 October 2026

Most active ransomware groups by confirmed victims

Source: ransomnews.com
#Ransomware groupConfirmed victims, 2026
1Qilin92
2The Gentlemen87
3INC50
4Akira42
5LockBit35
6SafePay28
7DragonForce23
8Chaos20
9Interlock17
10Kairos14
Source: ransomnews.com
#Ransomware groupConfirmed victims, all time
1LockBit545
2Qilin346
3Akira311
4Conti269
5Play223
6INC217
7ALPHV/BlackCat217
8Black Basta174
9Maze170
10RansomHub166

Latest confirmed incidents

Source: ransomnews.com
DateOrganisationCountrySectorStrain
October 2026Andersen Group Inc.United StatesBusiness / FinanceLeakedData/Silent Ransom Group
October 2026University of Illinois ChicagoUnited StatesEducationBooba Project
October 2026Colegio Oficial de Arquitectos de LeónSpainBusiness / OtherAkira
October 2026Osaka Metropolitan UniversityJapanEducationUnknown
October 2026City of VicksburgUnited StatesGovernmentUnknown
September 2026Lakewood Medical CentreCanadaHealthcareBooba Project
September 2026The Japan TimesJapanBusiness / OtherEclipse
September 2026Ada Mert Sağlık Hizmetleri Ticaret AŞTurkeyHealthcareUnknown
September 2026CR Healthcare ServicesIndiaBusiness / HealthcareUnknown
September 2026Ikegami Tsushinki Co., Ltd.JapanBusiness / ManufacturingQilin

Full breakdowns: ransomware statistics, the confirmed-attacks index by sector, country and year, and the ransom payment rate.


METHODOLOGY

What the tracker tracks, and what it doesn’t

Ransomtracker is a continuously updated index of active ransomware operations. The collector watches the public leak sites of every active operator it can reach, most are Tor hidden services, parses every new victim listing the operators publish, normalises the data, and keeps a structured record. The page you are reading reflects the current state of that index, refreshed on each page load.

The index is built specifically for journalism, threat intelligence, and breach-response work. It is not a credential-leak service and it does not host the stolen data, only the metadata of who appeared on whose leak site, when.

What we track

  • Operators with publicly visible leak sites, typically 50 to 90 active at any given time.
  • Each victim listing the operator publishes: organisation name, listing date, ransom deadline (where stated), and a short description if the operator provides one.
  • Operator status, leak site live, dormant (no new posts for 30+ days), or dark (seized, exit-scammed, voluntarily retired).
  • Aggregate counts: per-group, per-month, per-year, per-sector where it can be inferred.

What we do not track

  • The leaked data itself. The tracker indexes that a victim was listed and by whom, never the stolen data. Hosting that data is illegal in most jurisdictions and unethical in all of them.
  • Private negotiations, ransom amounts, or confidential incident details. The tracker only sees what operators choose to publish.
  • Groups operating without a public leak site. Pure-encryption operators, double-extortion holdouts who never publish, and small bespoke campaigns are invisible to leak-site monitoring by design.

Data caveats

  • Victim listings are operator claims. Some are inflated, some are duplicated across rebrands, a few are fabricated. The tracker presents them as the operator presents them; verifying any specific listing is the analyst’s responsibility.
  • Leak sites change layout frequently and disappear without warning. Brief gaps in coverage for individual operators are expected.
  • Attribution between rebranded operations (Conti → Black Basta, Royal → BlackSuit, etc.) is annotated where the lineage is well-established and left ambiguous where it isn’t.

Source data: RansomLook (CC BY 4.0), aggregated and adapted by Ransomnews.


USING IT

How to use the tracker

Search by victim

Enter an organisation name to see whether it has been listed, by whom, and when. Useful for due-diligence checks, breach-notification work, and tracking how long stolen data sits on leak sites before publication.

Drill into a group

Each operator has a profile page with their full victim history, leak-site URLs (current and historic), and timeline of activity. Useful for threat-intelligence work and historical research.

Track trends

Monthly and yearly aggregate views show how the leak-site economy is shifting, which groups are rising, which are dying, and how takedowns reshape the field.


COVERAGE

Editorial coverage

The data above is the operational signal. The analysis that contextualises it lives in our editorial coverage. Start with Ransomware for how operations actually run, Threat Groups for profiles of the major operators, Explainers for long-form primers on the underlying mechanics, or News for the chronological feed of everything we publish.

Corrections to operator metadata, story leads, or sensitive tips: email [email protected]. We act on every submission.


FAQ

Frequently asked questions

What is a ransomware leak site?

A ransomware leak site is a dark-web page, usually a Tor hidden service, where a ransomware operator publishes the names of victims who have not paid, together with samples or full dumps of the stolen data. Ransomtracker indexes these listings, the fact that a victim was named and by which operator, never the stolen data itself.

How many ransomware groups are active right now?

Typically 50 to 90 operators run a publicly visible leak site at any one time. Ransomtracker follows every one it can reach and marks each as live, dormant (no new post for 30 or more days), or dark (seized, retired or exit-scammed).

Are the victim listings verified?

The listings are operator claims, shown as the operators publish them; some are inflated, duplicated across rebrands or fabricated. Ransomnews separately maintains a human-verified dataset of confirmed ransomware attacks, corroborated against breach notifications, regulatory filings and press reports, and shows those confirmed figures alongside the claimed ones.

How often is the tracker updated?

Continuously. The collector parses new victim listings as operators publish them, and the page reflects the current state of the index on each load.

Can I search Ransomtracker for a specific company?

Yes. Use the search box to check whether an organisation has been listed on a leak site, by which operator, and when. It is useful for due-diligence, breach-notification and threat-intelligence work.


LEGAL & ETHICAL

A note on what this is for

Ransomtracker exists to make the operations of an entrenched criminal economy visible. The information it surfaces, that a particular organisation appeared on a particular operator’s leak site at a particular time, is already public, published by the operators themselves on indexed Tor sites, and widely scraped by other research, threat-intelligence, and journalism projects.

The tracker indexes that public information. It does not host stolen data, does not assist in pressuring victims, and does not operate as a back-channel for any operator. If you are an organisation listed on the tracker and would like to share a public response or correction, write to [email protected].

Stay on top of the feed

Subscribe for editorial coverage of new operations, takedowns, and shifts in the leak-site economy.

Browse the news →
Threat group profiles
{“@context”:”https://schema.org”,”@graph”:[{“@type”:”FAQPage”,”@id”:”https://ransomnews.com/ransomtracker/#faq”,”mainEntity”:[{“@type”:”Question”,”name”:”What is a ransomware leak site?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”A ransomware leak site is a dark-web page, usually a Tor hidden service, where a ransomware operator publishes the names of victims who have not paid, together with samples or full dumps of the stolen data. Ransomtracker indexes these listings, the fact that a victim was named and by which operator, never the stolen data itself.”}},{“@type”:”Question”,”name”:”How many ransomware groups are active right now?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Typically 50 to 90 operators run a publicly visible leak site at any one time. Ransomtracker follows every one it can reach and marks each as live, dormant (no new post for 30 or more days), or dark (seized, retired or exit-scammed).”}},{“@type”:”Question”,”name”:”Are the victim listings verified?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”The listings are operator claims, shown as the operators publish them; some are inflated, duplicated across rebrands or fabricated. Ransomnews separately maintains a human-verified dataset of confirmed ransomware attacks, corroborated against breach notifications, regulatory filings and press reports, and shows those confirmed figures alongside the claimed ones.”}},{“@type”:”Question”,”name”:”How often is the tracker updated?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Continuously. The collector parses new victim listings as operators publish them, and the page reflects the current state of the index on each load.”}},{“@type”:”Question”,”name”:”Can I search Ransomtracker for a specific company?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Yes. Use the search box to check whether an organisation has been listed on a leak site, by which operator, and when. It is useful for due-diligence, breach-notification and threat-intelligence work.”}}]},{“@type”:”BreadcrumbList”,”@id”:”https://ransomnews.com/ransomtracker/#breadcrumb”,”itemListElement”:[{“@type”:”ListItem”,”position”:1,”name”:”Home”,”item”:”https://ransomnews.com/”},{“@type”:”ListItem”,”position”:2,”name”:”Tools”,”item”:”https://ransomnews.com/tools/”},{“@type”:”ListItem”,”position”:3,”name”:”Ransomtracker”,”item”:”https://ransomnews.com/ransomtracker/”}]}]}

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,711 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.