Victims claimed on extortion leak sites, by sector and month. These are claims made by the groups, not confirmed incidents.
Manufacturing
Not Found
Healthcare
Other sectors
Professional Services
Technology
Transportation
Agriculture and Food Production
Financial Services
Retail & E-Commerce
qilin
krybit
safepay
thegentlemen
akira
BrainCipher
Storm
incransom
lockbit5
metaencryptor
play
shinyhunters
Falcon
direwolf
SilentRansomGroup
AuditTeam
chaos
insomnia
Orova
spacebears
Wallstreet
emperador
everest
medusalocker
DYSPHOR1A
Eclipse
gunra
majinahanashi
anubis
aurora
Dark Project
iah6477
Panzer
Vexy Ransomware
Booba Project
dragonforce
Global Secret Group
rhysida
ShadowByt3$
unsafe
View as table
Period
Manufacturing (postings)
Not Found (postings)
Healthcare (postings)
Other sectors (postings)
Professional Services (postings)
Technology (postings)
Transportation (postings)
Agriculture and Food Production (postings)
Financial Services (postings)
Retail & E-Commerce (postings)
qilin (postings)
krybit (postings)
safepay (postings)
thegentlemen (postings)
akira (postings)
BrainCipher (postings)
Storm (postings)
incransom (postings)
lockbit5 (postings)
metaencryptor (postings)
play (postings)
shinyhunters (postings)
Falcon (postings)
direwolf (postings)
SilentRansomGroup (postings)
AuditTeam (postings)
chaos (postings)
insomnia (postings)
Orova (postings)
spacebears (postings)
Wallstreet (postings)
emperador (postings)
everest (postings)
medusalocker (postings)
DYSPHOR1A (postings)
Eclipse (postings)
gunra (postings)
majinahanashi (postings)
anubis (postings)
aurora (postings)
Dark Project (postings)
iah6477 (postings)
Panzer (postings)
Vexy Ransomware (postings)
Booba Project (postings)
dragonforce (postings)
Global Secret Group (postings)
rhysida (postings)
ShadowByt3$ (postings)
unsafe (postings)
2026-08-01
6
3
1
2
3
3
—
—
2
5
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
—
2026-08-31
—
—
—
—
—
—
—
—
—
—
19.0
—
—
18.0
7
—
—
7
5
—
4
4
3
3
—
—
3
—
—
—
2
2
—
—
—
—
—
2
—
—
—
2
—
—
—
—
—
—
2
—
2026-09-01
21.0
9
6
35.0
11.0
12.0
6
6
4
9
15.0
14.0
—
4
7
8
—
7
6
—
4
2
—
6
—
—
—
—
4
—
3
—
3
—
—
—
—
3
—
—
—
2
—
—
—
—
—
—
—
—
2026-09-02
—
—
—
—
—
—
—
—
—
—
6
14.0
—
5
10.0
8
—
12.0
6
—
4
—
—
7
—
—
—
—
—
—
4
—
3
2
—
2
—
—
—
2
—
—
—
—
—
—
2
—
—
—
2026-09-03
—
—
—
—
—
—
—
—
—
—
4
15.0
—
5
7
8
8
11.0
3
—
4
—
—
5
4
—
—
—
—
—
4
—
3
2
—
—
—
—
—
—
—
—
—
2
—
—
—
—
—
—
2026-09-04
—
—
—
—
—
—
—
—
—
—
7
15.0
—
—
8
8
8
8
—
—
—
—
—
6
7
—
—
—
—
3
3
—
3
2
—
—
2
—
—
—
—
—
2
5
—
—
—
—
—
—
2026-09-05
—
—
—
—
—
—
—
—
—
—
12.0
15.0
—
5
6
—
8
4
3
—
—
—
—
6
8
—
—
—
—
4
3
—
—
—
2
—
2
—
—
2
—
—
—
6
—
—
—
—
—
—
2026-09-06
—
—
—
—
—
—
—
—
—
—
12.0
6
—
5
6
—
8
—
3
—
—
—
—
9
8
—
—
—
—
4
3
—
—
—
3
—
—
—
—
2
—
—
4
7
—
2
—
—
—
—
2026-09-07
—
—
—
—
—
—
—
—
—
—
13.0
—
—
4
5
—
3
2
3
4
—
—
—
10.0
7
—
—
—
—
4
—
—
3
—
3
—
—
—
—
—
2
—
4
9
—
—
—
—
—
—
2026-09-08
—
—
—
—
—
—
—
—
—
—
10.0
—
10.0
21.0
4
—
—
—
3
4
—
—
—
10.0
—
3
2
—
—
—
—
—
3
—
3
—
—
—
—
—
3
—
3
4
—
—
—
2
—
—
2026-09-10
—
—
—
—
—
—
—
—
—
—
5
—
10.0
18.0
5
—
4
3
4
4
—
—
—
8
—
7
—
—
—
—
—
3
3
—
—
—
—
—
—
—
4
—
2
3
—
—
—
—
—
—
2026-09-11
—
—
—
—
—
—
—
—
—
—
4
—
10.0
13.0
8
—
4
—
5
—
4
—
—
5
—
9
3
—
—
—
3
4
—
—
—
—
—
—
—
—
4
—
—
3
—
—
—
4
—
—
2026-09-12
—
—
—
—
—
—
—
—
—
—
5
—
11.0
7
8
—
4
—
6
—
4
—
—
6
—
9
3
—
—
—
3
4
—
—
—
—
—
—
—
—
4
—
4
—
—
—
—
4
—
—
2026-09-13
—
—
—
—
—
—
—
—
—
—
4
12.0
11.0
—
7
—
—
—
5
—
4
—
—
4
—
8
3
—
—
—
3
5
—
4
—
—
—
—
—
—
—
—
4
3
—
—
—
4
—
—
2026-09-14
—
—
—
—
—
—
—
—
—
—
5
13.0
11.0
—
5
—
—
—
3
—
4
—
—
4
—
7
3
—
—
—
3
6
—
4
—
—
—
—
—
—
—
—
5
3
—
—
—
3
—
—
2026-09-15
—
—
—
—
—
—
—
—
—
—
10.0
13.0
—
—
4
—
—
—
6
—
—
—
—
—
—
6
4
—
—
—
3
6
—
4
—
—
—
—
2
—
—
—
4
3
—
—
—
3
2
2
2026-09-16
—
—
—
—
—
—
—
—
—
—
15.0
6
8
30.0
4
—
3
—
3
2
—
—
—
—
—
4
2
2
—
—
—
—
—
—
—
—
—
—
—
—
—
—
2
2
2
—
—
—
—
2
Source: ransomware.live · retrieved 16 Sep 2026 · Commercial use prohibited without publisher permission Leak-site postings are claims made by ransomware groups, not confirmed or verified incidents.
Leak-site postings are the most timely public signal about ransomware activity and the most easily misread. Every posting is an assertion by a criminal group that it has breached an organisation. Groups inflate, re-post old victims, and occasionally invent.
What the series does measure reliably is the public behaviour of extortion operations: how many claims they are making, in which sectors, and how that changes after a takedown or a rebrand.
Sectors past the top seven are folded into "Other" rather than given their own colour, because a chart with fifteen indistinguishable series is not a chart.