ThreatVectr Intelligence

Ransomware Tracker

A live view of ransomware activity, built from the attacks that criminal groups claim on their dark-web leak sites. Below: who is most active, which sectors and countries are being hit, and how the pace is changing month to month.

Updated continuously · Data as of 28 Aug 2026, 04:43 UTC · Coverage since July 2025

These are claims, not confirmed breaches. Every figure here comes from listings that ransomware groups post on their own dark-web leak sites to pressure victims. Such listings are unverified, sometimes exaggerated, and occasionally false. A company appearing in this data has not necessarily confirmed any incident.

10,847
Claimed attacks tracked
2,620 in the last 90 days
167
Active ransomware groups
160
Countries affected
1,022
Claimed in last 30 days
234 in the last 7 days

Claimed attacks per month

Last 12 months · current month partial

Monthly ransomware reports

A citable deep-dive on every completed month — totals, trends, group movements, sectors and countries.

Most active groups

  1. 1Qilin1,666
  2. 2The Gentlemen791
  3. 3Akira737
  4. 4INC Ransom574
  5. 5DragonForce449
  6. 6Play371
  7. 7LockBit344
  8. 8Cl0p332
  9. 9SafePay316
  10. 10Sinobi274

Ranked by claimed claims

Most-targeted sectors

  1. 1Manufacturing1,587
  2. 2Business Services1,339
  3. 3Technology1,250
  4. 4Healthcare908
  5. 5Consumer Services622
  6. 6Financial Services618
  7. 7Construction603
  8. 8Agriculture and Food Production411
  9. 9Education374
  10. 10Transportation/Logistics347

Ranked by claimed claims

Most-affected countries

  1. 1United States4,608
  2. 2Germany507
  3. 3United Kingdom417
  4. 4Canada397
  5. 5Italy294
  6. 6France287
  7. 7Brazil218
  8. 8Spain216
  9. 9India198
  10. 10Australia179

Ranked by claimed claims

How this tracker works

ThreatVectr monitors the leak sites of 200+ ransomware groups through ransomware.live, an open monitoring service that watches the dark-web portals so we do not have to run our own crawler. Each new listing is counted once, by the group claiming it, the victim's sector and country where the listing states them, and the date the claim was posted.

The numbers above are aggregate counts only. ThreatVectr does not publish the names of the companies named in these listings, because a leak-site post is an accusation by criminals, not a verified fact. Read more in our editorial policy.

Most ransomware starts with one email

The groups above overwhelmingly get in through phishing. Train2Secure runs realistic phishing simulations and short training that teach your team to spot the lure before it becomes an incident.

Start free — no card required
© 2026 Threat Vectr