Network: Wedgetail Astrostrategy Cyberstrategy Geofinance Geopolitics Geostrategy Global Energy
Ransomware leak-site postings by sector

Victims claimed on extortion leak sites, by sector and month. These are claims made by the groups, not confirmed incidents.

  • Manufacturing
  • Not Found
  • Healthcare
  • Other sectors
  • Professional Services
  • Technology
  • Transportation
  • Agriculture and Food Production
  • Financial Services
  • Retail & E-Commerce
  • qilin
  • krybit
  • safepay
  • thegentlemen
  • akira
  • BrainCipher
  • Storm
  • incransom
  • lockbit5
  • metaencryptor
  • play
  • shinyhunters
  • Falcon
  • direwolf
  • SilentRansomGroup
  • AuditTeam
  • chaos
  • insomnia
  • Orova
  • spacebears
  • Wallstreet
  • emperador
  • everest
  • medusalocker
  • DYSPHOR1A
  • Eclipse
  • gunra
  • majinahanashi
  • anubis
  • aurora
  • Dark Project
  • iah6477
  • Panzer
  • Vexy Ransomware
  • Booba Project
  • dragonforce
  • Global Secret Group
  • rhysida
  • ShadowByt3$
  • unsafe
050100150200250postings1 Aug 261 Sep 263 Sep 265 Sep 267 Sep 2610 Sep 2612 Sep 2614 Sep 2616 Sep 26
View as table
PeriodManufacturing (postings)Not Found (postings)Healthcare (postings)Other sectors (postings)Professional Services (postings)Technology (postings)Transportation (postings)Agriculture and Food Production (postings)Financial Services (postings)Retail & E-Commerce (postings)qilin (postings)krybit (postings)safepay (postings)thegentlemen (postings)akira (postings)BrainCipher (postings)Storm (postings)incransom (postings)lockbit5 (postings)metaencryptor (postings)play (postings)shinyhunters (postings)Falcon (postings)direwolf (postings)SilentRansomGroup (postings)AuditTeam (postings)chaos (postings)insomnia (postings)Orova (postings)spacebears (postings)Wallstreet (postings)emperador (postings)everest (postings)medusalocker (postings)DYSPHOR1A (postings)Eclipse (postings)gunra (postings)majinahanashi (postings)anubis (postings)aurora (postings)Dark Project (postings)iah6477 (postings)Panzer (postings)Vexy Ransomware (postings)Booba Project (postings)dragonforce (postings)Global Secret Group (postings)rhysida (postings)ShadowByt3$ (postings)unsafe (postings)
2026-08-0163123325
2026-08-3119.018.07754433322222
2026-09-0121.09635.011.012.0664915.014.04787642643332
2026-09-02614.0510.0812.0647432222
2026-09-03415.0578811.034544322
2026-09-04715.08888673332225
2026-09-0512.015.05684368432226
2026-09-0612.065683984332472
2026-09-0713.045323410.07433249
2026-09-0810.010.021.043410.032333342
2026-09-10510.018.0543448733423
2026-09-11410.013.0845459334434
2026-09-12511.07846469334444
2026-09-13412.011.0754483354434
2026-09-14513.011.0534473364533
2026-09-1510.013.04664364243322
2026-09-1615.06830.043324222222

Source: ransomware.live · retrieved 16 Sep 2026 · Commercial use prohibited without publisher permission
Leak-site postings are claims made by ransomware groups, not confirmed or verified incidents.

Download CSV · Embed this chart

Leak-site postings are the most timely public signal about ransomware activity and the most easily misread. Every posting is an assertion by a criminal group that it has breached an organisation. Groups inflate, re-post old victims, and occasionally invent.

What the series does measure reliably is the public behaviour of extortion operations: how many claims they are making, in which sectors, and how that changes after a takedown or a rebrand.

Sectors past the top seven are folded into "Other" rather than given their own colour, because a chart with fifteen indistinguishable series is not a chart.

The data behind this chart

Ransomware leak-site postings — Victim postings claimed on ransomware leak sites, by group and sector.

Source: ransomware.live · retrieved 16 Sep 2026 · Commercial use prohibited without publisher permission

Dataset CSV · Dataset JSON · This chart's data

Embed this chart

Free to embed with attribution. Every embed stays live as the data updates.


Related from the Network

How the KEV catalog works
On Cyberstrategy