Macro Incident Trends & Analytics
Download Raw Datasets (CSV/JSON/SQLite) →Empirical findings synthesized from sworn federal court dockets, SEC disclosures, CISA alerts, and asset forfeiture records across all 59 cataloged incidents.
Key Facts
- 59 primary-sourced prosecution matters and cyber incident records analyzed.
- Over $42.8 billion in cumulative direct documented financial loss.
- Stolen single-factor credentials remain the #1 initial intrusion vector across modern enterprise breaches.
- $243.9M in verified ransom extortion payments tracked with law enforcement forfeiture metrics.
Cumulative extortion demands across tracked landmark ransomware incidents.
Direct cryptocurrency payments transferred to threat actor wallets before decryption.
Cryptocurrency forfeited or clawed back via FBI and international seizure operations.
Initial Access Vectors Across Landmark Breaches
Distribution of root intrusion mechanisms identified in primary forensic evidence.
| Category | Count |
|---|---|
| Stolen Credentials / Single-Factor Portal | 10 cases |
| Public Vulnerability / CVE Exploitation | 3 cases |
| Spearphishing & Malicious Links | 1 cases |
| Software Supply Chain Infiltration | 3 cases |
| Helpdesk Social Engineering / Vishing | 1 cases |
| Cloud Workspace Misconfiguration / Token Leak | 41 cases |
Victim Sector Concentration
Top industry verticals targeted by nation-state actors and cybercrime cartels.
| Category | Count |
|---|---|
| Financial Services | 17 cases |
| Retail | 9 cases |
| Banking | 8 cases |
| Healthcare | 7 cases |
| Energy | 6 cases |
| E-Commerce | 6 cases |
| Telecommunications | 5 cases |
| Education | 4 cases |
Attributed Sovereign Jurisdiction & Syndicate Origin
Case volume attributed to nation-state intelligence agencies or sovereign hosts.
Historical Evolution: Attacker Velocity & Dwell Time Trends
Extended Espionage Dwell Time
Median dwell time exceeded 200+ days. Actors like PLA Unit 61398 and APT29 operated silently for years extracting intellectual property before network discovery.
Automated Lateral Traversal
Wormable exploits and automated scripts dropped dwell time to 10 to 30 days. Ransomware groups demanded millions after staging exfiltration over weekends.
Rapid Identity & Cloud Heists
Median dwell time dropped to under 48 hours. Infostealer credentials and SaaS API tokens permit immediate exfiltration without deploying host binaries.