Global Threat Board
Live ransomware activity around the world, and the software flaws attackers are exploiting right now. Then the tools to clean an infected machine — all checked, all from the vendor direct.
Where it is happening
Attack claims by country
Equirectangular · marker area ∝ claim count
Who has been named
Every organisation recorded on a ransomware leak site since 2020
Unverified. Every name below was posted by the attackers themselves on their own leak site. None of it is confirmed by the organisation named, and a listing is not proof that a breach occurred — groups have been known to relist old data, exaggerate, and name companies they never breached. Each row links to ransomware.live, which is where the claim is recorded, so you can judge it yourself.
Day by day
This board's own daily record — the only view here that shows climate rather than weather
Which groups work which sectors
Busiest groups against busiest sectors — shade and number both show the claim count
Statistics
Derived from the same claims as everything above — moves with the range tabs
Sectors targeted
Victim sector, where disclosed
Claims per hour
Rolling window, UTC
The UK picture
Where the UK sits in the current window
Pulled out of the same claims as the board above — follows the range tabs
Latest from the NCSC
Headlines from the National Cyber Security Centre — the UK authority
If it happens: your UK obligations
- The ICO, within 72 hours. If personal data was accessed or stolen — and modern ransomware almost always exfiltrates before it encrypts — UK GDPR Article 33 requires you to notify the Information Commissioner's Office within 72 hours of becoming aware. The clock starts at awareness, not at resolution. Report at ico.org.uk or 0303 123 1113.
- Action Fraud. Ransomware is a crime and reporting it is how it gets counted and investigated. 0300 123 2040, 24/7 for live business attacks.
- The NCSC wants to hear about significant incidents, and can help. Reporting is separate from Action Fraud — do both.
- Paying may itself be an offence. Several ransomware groups are sanctioned. Paying a sanctioned entity breaches UK financial sanctions regardless of intent, and "we did not know who they were" is not a defence. Check before anyone even discusses payment, and involve your insurer and a solicitor.
- Preserve the evidence. Do not wipe and rebuild before someone has imaged the affected machines. It is the difference between knowing what left your network and guessing — and the ICO will ask.
Cyber Essentials self-check
The five controls in the UK government's baseline scheme, scored against the ways the groups above are actually getting in
How they are getting in
Initial access across the groups currently active
MITRE ATT&CK initial-access techniques, counted by how many active groups use each — with the control that actually stops it
Who these groups are
Profiles for the groups currently claiming victims
Aliases, first seen, tooling and MITRE ATT&CK tactics — for the groups on the board above
Exploited in the wild right now
Two years of the catalogue
Vulnerabilities confirmed as exploited each month, with the ransomware-linked share
Remediation status across the whole catalogue
CISA sets a fix-by date on every entry. Past it, these are overdue — not merely known
Patch these first
Added in the last 90 days and already used in ransomware — with CISA's own required action
What kind of flaw
Weakness classes across the catalogue — this is the part that generalises beyond one product
Whose software appears most
Scan for anything you actually run — that is your patch queue
Latest additions
Newest entries first — confirmed under active attack
Malware removal tools
Every link checked · vendor pages only, never a direct downloadRead this first
- Only ever download from the vendor's own site. Search results for "free virus removal" are a well-known malware delivery route. Every link below goes to the official page — not to a direct installer, because those move and get mirrored by others.
- On-demand scanners are safe to stack; real-time antivirus is not. The scanners in the first group run once and exit, so you can use several for a second opinion. Never install two always-on antivirus products together.
- If the machine is badly infected, scan it from outside. Malware with kernel access can hide from any tool running inside the infected Windows. That is what the rescue media group is for.
- Back up your files before running an aggressive remover — on a drive you then unplug. Removal can break a system that was limping along, and ransomware can encrypt an attached backup.
- Never pay a ransom before checking No More Ransom. A free decryptor already exists for many strains. Paying funds the next attack and often gets you nothing.
- Tools deliberately not listed here: ComboFix (long obsolete and can break modern Windows), anything marketed as a "registry cleaner" (does not remove malware), and Kaspersky's TDSSKiller — discontinued, and its signed driver has been abused by ransomware crews to switch off security software.
1 · Free on-demand scanners
Start here. Each runs once, checks the machine and exits, so several can be used together for a second opinion without conflicting with the antivirus you already have.
2 · Bootable rescue media
For when Windows will not start, a scanner is being killed as it launches, or a rootkit is suspected. These boot the machine from a USB stick and scan the drive while the infection is not running — the only reliable way to deal with malware that has kernel access. Prepare them on a clean computer.
3 · Hit by ransomware
Identify the strain before doing anything else — free decryptors exist for a great many of them, and law enforcement releases new keys regularly. Keep the encrypted files even if no decryptor exists today; one may appear later. Do not reformat in a hurry.
4 · Technician tools
These diagnose and expose; they do not clean up after themselves, and a wrong move can leave a machine unbootable. Included for completeness — if you are not confident reading their output, stop here and get help rather than guessing.
5 · Leave one of these running
Once the machine is clean, one always-on product — and only one. Windows' own is genuinely competent now and needs no licence, no renewal and no upselling.
Think you have picked something up?
If a machine is behaving oddly, showing pop-ups, running hot, or you have opened something you wish you hadn't — I clean infections properly and recover data where it is recoverable. Based in Taunton, Somerset, remote or in person.
Get it looked at
Attack data from ransomware.live, which aggregates public ransomware leak-site postings. Vulnerability data from the CISA Known Exploited Vulnerabilities catalogue (public domain).
Attack claims are made by the attackers themselves on their own leak sites and are not independently verified. Most of this page reports totals only — by country, group and sector. The “Who has been named” table is the one exception: it lists the organisations those posts name, each linked to ransomware.live where the claim is recorded. A listing there is a criminal’s assertion, not a confirmed breach, and should not be read as one. Attackers relist old data, overstate what they hold, and name organisations they never breached. Figures describe what has been published in the feed window, not every attack that occurred. If your organisation appears here in error, get in touch and I will remove the row.