Ransomware Tracker
A live view of ransomware activity, built from the attacks that criminal groups claim on their dark-web leak sites. Below: who is most active, which sectors and countries are being hit, and how the pace is changing month to month.
Updated continuously · Data as of 28 Aug 2026, 04:43 UTC · Coverage since July 2025
These are claims, not confirmed breaches. Every figure here comes from listings that ransomware groups post on their own dark-web leak sites to pressure victims. Such listings are unverified, sometimes exaggerated, and occasionally false. A company appearing in this data has not necessarily confirmed any incident.
Claimed attacks per month
Last 12 months · current month partialMonthly ransomware reports
A citable deep-dive on every completed month — totals, trends, group movements, sectors and countries.
Most active groups
- 1Qilin1,666
- 2The Gentlemen791
- 3Akira737
- 4INC Ransom574
- 5DragonForce449
- 6Play371
- 7LockBit344
- 8Cl0p332
- 9SafePay316
- 10Sinobi274
Ranked by claimed claims
Most-targeted sectors
- 1Manufacturing1,587
- 2Business Services1,339
- 3Technology1,250
- 4Healthcare908
- 5Consumer Services622
- 6Financial Services618
- 7Construction603
- 8Agriculture and Food Production411
- 9Education374
- 10Transportation/Logistics347
Ranked by claimed claims
Most-affected countries
- 1United States4,608
- 2Germany507
- 3United Kingdom417
- 4Canada397
- 5Italy294
- 6France287
- 7Brazil218
- 8Spain216
- 9India198
- 10Australia179
Ranked by claimed claims
How this tracker works
ThreatVectr monitors the leak sites of 200+ ransomware groups through ransomware.live, an open monitoring service that watches the dark-web portals so we do not have to run our own crawler. Each new listing is counted once, by the group claiming it, the victim's sector and country where the listing states them, and the date the claim was posted.
The numbers above are aggregate counts only. ThreatVectr does not publish the names of the companies named in these listings, because a leak-site post is an accusation by criminals, not a verified fact. Read more in our editorial policy.
Most ransomware starts with one email
The groups above overwhelmingly get in through phishing. Train2Secure runs realistic phishing simulations and short training that teach your team to spot the lure before it becomes an incident.