Mass-Victim Weeks

Every year or two a single crew converts one access route into a wave of leak-site listings that lands across every sector and region at once. Cl0p published 236 victims in the week beginning 2025-02-24: 34.9% of its entire recorded output, 644 days after its first listing (measured 2026-08-06).

That shape is invisible to every other view we publish. A sector page aggregates one industry, a country page one geography, and a wave is defined by neither — it is defined by time and by a shared access route, and it hits everything at once precisely because the victims have nothing in common except a piece of software.

The method is the product, and it is on the page. Peak-week share of lifetime output finds the bursts; days-from-debut separates them from the thing that looks identical and is not. Seven of the groups whose peak week reaches twenty claims peak in their FIRST week — a new leak site publishing its backlog on day one, not a mass exploitation event. A burst leaderboard without that column puts its loudest false positive at the top.

All collections

Peak weeks

The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.

Groups

Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.

Vulnerabilities

KEV marks a vulnerability CISA records as exploited in the wild.

Defining tradecraft

Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.

Recent activity

The most recent incidents in our log attributed to the groups above, from the last twelve months.

Our coverage

The 12 most recent of 16 briefings that mention a member of this collection.

How this list was chosen. Membership here is illustrative and small on purpose: the computation runs corpus-wide over an incidents table the importer grows every three hours, so the next wave surfaces without anyone editing this list. Medusa and Akira are included as negative controls — both heavy exploiters with very large lifetime output and no burst. EVERY DATE ON THIS PAGE IS A LEAK-SITE PUBLICATION DATE, not a date of compromise; victims in these windows were typically breached weeks or months before our rows exist. The two CVEs are carried for a computable date relationship to a wave, not as an established cause: we hold no link between any individual victim and any vulnerability. MOVEit is included as the counterexample — the event this page is usually named after contributes no victims to our corpus at all.

Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.

Read the full analysis on IntelFusions