Mass-Victim Weeks

Every year or two a single crew converts one access route into a wave of leak-site listings that lands across every sector and region at once. Cl0p published 236 victims in the week beginning 2025-02-24: 32.6% of its entire recorded output, 644 days after its first listing (measured 2026-08-29).

That shape is invisible to every other view we publish. A sector page aggregates one industry, a country page one geography, and a wave is defined by neither — it is defined by time and by a shared access route, and it hits everything at once precisely because the victims have nothing in common except a piece of software.

The method is the product, and it is on the page. Peak-week share of lifetime output finds the bursts; days-from-debut separates them from the thing that looks identical and is not. Eight of the groups whose peak week reaches twenty claims peak in their FIRST week — a new leak site publishing its backlog on day one, not a mass exploitation event. A burst leaderboard without that column puts its loudest false positive at the top.

All collections

What these have in common

Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.

ATT&CK techniques

Shared tooling

Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.

Peak weeks

The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.

Groups

Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.

Vulnerabilities

KEV marks a vulnerability CISA records as exploited in the wild.

Defining tradecraft

Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.

Recent activity

The most recent incidents in our log attributed to the groups above, from the last twelve months.

Our coverage

The 12 most recent of 35 briefings that mention a member of this collection.

How this list was chosen. Membership here is illustrative and small on purpose: the burst table computes live over an incidents table the importer grows every three hours, but only for the actors on this list — a new wave appears here when a curator adds the crew, not on its own. Medusa and Akira are included as negative controls — both heavy exploiters with very large lifetime output and no burst. EVERY DATE ON THIS PAGE IS A LEAK-SITE PUBLICATION DATE, not a date of compromise; victims in these windows were typically breached weeks or months before our rows exist. Debut is a tracker date too: days-from-debut counts from a crew's first listing in our corpus, so a leak site onboarded by the tracker mid-life clears the debut-week filter and its backlog can score as a wave — a false-positive class the two columns cannot see. The two CVEs are carried for a computable date relationship to a wave, not as an established cause: we hold no link between any individual victim and any vulnerability. MOVEit is included as the counterexample — the event this page is usually named after contributes no victims to our corpus at all.

Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.

Read the full analysis on IntelFusions