Connecting to feeds

Global Threat Board

Live ransomware activity around the world, and the software flaws attackers are exploiting right now. Then the tools to clean an infected machine — all checked, all from the vendor direct.

Attack Claims
Countries Hit
Active Groups
Exploited Flaws
Used In Ransomware

Where it is happening

Attack claims by country

Equirectangular · marker area ∝ claim count

Loading…

Who has been named

Every organisation recorded on a ransomware leak site since 2020

Unverified. Every name below was posted by the attackers themselves on their own leak site. None of it is confirmed by the organisation named, and a listing is not proof that a breach occurred — groups have been known to relist old data, exaggerate, and name companies they never breached. Each row links to ransomware.live, which is where the claim is recorded, so you can judge it yourself.

Loading…

Unverified claim

Day by day

This board's own daily record — the only view here that shows climate rather than weather

Loading…

Which groups work which sectors

Busiest groups against busiest sectors — shade and number both show the claim count

Loading…

Statistics

Derived from the same claims as everything above — moves with the range tabs

Loading…

Sectors targeted

Victim sector, where disclosed

Loading…

Claims per hour

Rolling window, UTC

Loading…

The UK picture

Where the UK sits in the current window

Pulled out of the same claims as the board above — follows the range tabs

Loading…

Latest from the NCSC

Headlines from the National Cyber Security Centre — the UK authority

Loading…

If it happens: your UK obligations

  • The ICO, within 72 hours. If personal data was accessed or stolen — and modern ransomware almost always exfiltrates before it encrypts — UK GDPR Article 33 requires you to notify the Information Commissioner's Office within 72 hours of becoming aware. The clock starts at awareness, not at resolution. Report at ico.org.uk or 0303 123 1113.
  • Action Fraud. Ransomware is a crime and reporting it is how it gets counted and investigated. 0300 123 2040, 24/7 for live business attacks.
  • The NCSC wants to hear about significant incidents, and can help. Reporting is separate from Action Fraud — do both.
  • Paying may itself be an offence. Several ransomware groups are sanctioned. Paying a sanctioned entity breaches UK financial sanctions regardless of intent, and "we did not know who they were" is not a defence. Check before anyone even discusses payment, and involve your insurer and a solicitor.
  • Preserve the evidence. Do not wipe and rebuild before someone has imaged the affected machines. It is the difference between knowing what left your network and guessing — and the ICO will ask.

Cyber Essentials self-check

The five controls in the UK government's baseline scheme, scored against the ways the groups above are actually getting in

Loading…

How they are getting in

Initial access across the groups currently active

MITRE ATT&CK initial-access techniques, counted by how many active groups use each — with the control that actually stops it

Loading…

Who these groups are

Profiles for the groups currently claiming victims

Aliases, first seen, tooling and MITRE ATT&CK tactics — for the groups on the board above

Loading…

Exploited in the wild right now

Two years of the catalogue

Vulnerabilities confirmed as exploited each month, with the ransomware-linked share

Loading…

Remediation status across the whole catalogue

CISA sets a fix-by date on every entry. Past it, these are overdue — not merely known

Loading…

Patch these first

Added in the last 90 days and already used in ransomware — with CISA's own required action

Loading…

What kind of flaw

Weakness classes across the catalogue — this is the part that generalises beyond one product

Loading…

Whose software appears most

Scan for anything you actually run — that is your patch queue

Loading…

Latest additions

Newest entries first — confirmed under active attack

Loading…

Malware removal tools

Every link checked · vendor pages only, never a direct download

Read this first

  • Only ever download from the vendor's own site. Search results for "free virus removal" are a well-known malware delivery route. Every link below goes to the official page — not to a direct installer, because those move and get mirrored by others.
  • On-demand scanners are safe to stack; real-time antivirus is not. The scanners in the first group run once and exit, so you can use several for a second opinion. Never install two always-on antivirus products together.
  • If the machine is badly infected, scan it from outside. Malware with kernel access can hide from any tool running inside the infected Windows. That is what the rescue media group is for.
  • Back up your files before running an aggressive remover — on a drive you then unplug. Removal can break a system that was limping along, and ransomware can encrypt an attached backup.
  • Never pay a ransom before checking No More Ransom. A free decryptor already exists for many strains. Paying funds the next attack and often gets you nothing.
  • Tools deliberately not listed here: ComboFix (long obsolete and can break modern Windows), anything marketed as a "registry cleaner" (does not remove malware), and Kaspersky's TDSSKiller — discontinued, and its signed driver has been abused by ransomware crews to switch off security software.

1 · Free on-demand scanners

Start here. Each runs once, checks the machine and exits, so several can be used together for a second opinion without conflicting with the antivirus you already have.

Think you have picked something up?

If a machine is behaving oddly, showing pop-ups, running hot, or you have opened something you wish you hadn't — I clean infections properly and recover data where it is recoverable. Based in Taunton, Somerset, remote or in person.

Get it looked at

 

Attack data from ransomware.live, which aggregates public ransomware leak-site postings. Vulnerability data from the CISA Known Exploited Vulnerabilities catalogue (public domain).

Attack claims are made by the attackers themselves on their own leak sites and are not independently verified. Most of this page reports totals only — by country, group and sector. The “Who has been named” table is the one exception: it lists the organisations those posts name, each linked to ransomware.live where the claim is recorded. A listing there is a criminal’s assertion, not a confirmed breach, and should not be read as one. Attackers relist old data, overstate what they hold, and name organisations they never breached. Figures describe what has been published in the feed window, not every attack that occurred. If your organisation appears here in error, get in touch and I will remove the row.