Data Observatory

Ransomware & Cyber Incident Tracker

61 major ransomware incidents tracked. 313 vulnerabilities exploited by ransomware groups (CISA KEV).

Incidents Tracked

61

CISA KEV Ransomware CVEs

313

Total Ransom Demanded

$384.0M

Total Ransom Paid

$161.2M

BBC

2024-08-15 MediaUnited Kingdom

British Broadcasting Corporation systems compromised affecting internal operations.

LockBitLockBit

Synnovis

2024-06-27 HealthcareUnited Kingdom

$2.7M

UK pathology lab network down for weeks, disrupting blood testing across multiple NHS trusts.

LockBitLockBit

Carahsoft Technology

2024-05-15 Government ContractorUnited States

Federal IT contractor breach potentially affecting government systems and data.

RhysidaRhysida

Los Angeles County

2024-03-18 GovernmentUnited States

$2.0M

Major U.S. county government systems compromised with stolen data from medical examiner's office.

LockBitLockBit

Maricopa County

2024-03-11 GovernmentUnited States

$1.0M

Arizona county government systems disrupted, affecting public services.

LockBit

Qwest Communications

2024-03-10 TelecommunicationsUnited States

Telecom provider experienced disruptions affecting business customer services.

BlackCat/ALPHVBlackCat

Lukas Hospital

2024-02-29 HealthcareGermany

$3.0M

German hospital IT infrastructure compromised, affecting patient care operations.

LockBitLockBit

Change Healthcare

2024-02-21 HealthcareUnited States

$22.0M

Paid: $22.0M

Massive healthcare IT outage affecting pharmacies, hospitals, and claims processing nationwide.

Blackcat/ALPHVBlackCat

NatWest Group

2024-02-20 Financial ServicesUnited Kingdom

Major UK bank disrupted with online banking unavailable affecting millions of customers.

LockBitLockBit

UnitedHealth Group

2024-02-15 HealthcareUnited States

Parent company of Change Healthcare experienced cascading impact on US healthcare system operations.

BlackCat/ALPHVBlackCat

Alphacrest Capital

2024-01-15 FinanceUnited States

$3.0M

Investment firm compromised with operational disruptions and data theft.

RhysidaRhysida

Norwegian Hospital Authority

2024-01-09 HealthcareNorway

$8.5M

Norwegian healthcare system partially paralyzed, forcing diversion of emergency patients.

LockBitLockBit

Kroger

2024-01-09 RetailUnited States

Major US grocery chain payment systems compromised affecting multiple store locations.

AlphV/BlackCatBlackCat

Herbalife

2024-01-02 RetailUnited States

$1.1M

Major nutrition company's systems compromised with employee and sales data exposed.

LockBitLockBit

Capita

2023-12-27 IT ServicesUnited Kingdom

UK outsourcing firm attack disrupted services for multiple government agencies and councils.

LockBitLockBit

Caesars Entertainment

2023-12-08 HospitalityUnited States

Casino and hotel chain experienced significant data breach affecting customer systems.

Rhysida Supply Chain

2023-10-31 MultipleUnited States

Emerging ransomware gang conducted large-scale attack affecting multiple sectors.

RhysidaRhysida

Royal Mail (UK)

2023-10-10 LogisticsUnited Kingdom

$66.0M

Critical UK postal service disrupted affecting international shipping for weeks.

LockBitLockBit

MGM Resorts

2023-09-12 HospitalityUnited States

$3.9M

Major casino resort systems disrupted for days, affecting reservations and gaming operations.

Alphv/BlackCatBlackCat

Akron Public Schools

2023-08-20 EducationUnited States

Ohio school district attack affected student and staff records with delayed school operations.

RhysidaRhysida

LockBit 3.0 Targets

2023-06-01 Manufacturing/Supply ChainUnited States

LockBit ransomware gang conducted major supply chain attack campaign targeting US manufacturers.

LockBitLockBit 3.0

MOVEit Transfer

2023-05-31 SoftwareUnited States

$6.0M

Widespread supply chain compromise affecting thousands of organizations through vulnerable file transfer tool.

Cl0pCl0p

MOVEit Transfer (Progress Software)

2023-05-31 SoftwareUnited States

Critical vulnerability exploitation affecting thousands of organizations worldwide including US federal agencies.

ClopClop

Scripps Health

2023-05-30 HealthcareUnited States

$112.0M

Paid: $112.0M

Major healthcare network paid largest known healthcare ransomware ransom in history.

RoyalRoyal

Nottingham City Council

2023-05-26 GovernmentUnited Kingdom

$8.0M

Local government services including housing benefits and council tax disrupted for months.

LockBitLockBit

Port of Hamburg

2023-04-14 Critical InfrastructureGermany

Ransomware attack temporarily disrupted operations at major European port facility.

Medline Industries

2023-04-02 Healthcare SupplyUnited States

Major medical supply distributor shutdown lasted weeks affecting hospital inventory.

BlackCat/ALPHVBlackCat

3CX Supply Chain

2023-03-29 SoftwareCyprus

Compromised software update affected thousands of businesses globally through supply chain.

3CX Supply Chain Attack

2023-03-29 Software/Supply ChainCyprus

Software supply chain compromise through trojanized desktop application updates.

North Korean APTN/A

University of Vermont Medical Center

2023-02-16 HealthcareUnited States

$5.5M

Major teaching hospital disrupted for weeks, affecting patient care and forcing manual operations.

BlackCat/ALPHVBlackCat

Clemson University

2023-02-01 EducationUnited States

$1.1M

University experienced significant operational disruption with sensitive research and personnel data exposed.

BlackCatBlackCat

LoanDepot

2023-01-15 FinanceUnited States

Mortgage lender confirmed data breach affecting millions of applicants and customers.

Kent Schools (UK)

2023-01-04 EducationUnited Kingdom

Multiple UK schools experienced system outages affecting student records and operations.

LockBitLockBit

Medibank (Australia)

2022-10-17 Insurance/HealthcareAustralia

Australian health insurer exposed data of nearly 10 million customers including health records.

Optus (Australia)

2022-09-22 TelecommunicationsAustralia

$1.0M

Major Australian telecom exposed personal data of nearly 10 million customers.

Los Angeles Unified School District

2022-09-20 EducationUnited States

US largest school district experienced cyber attack disrupting online platforms and communications.

Canadian Parliament

2022-07-20 GovernmentCanada

Canadian government experienced cyberattack affecting parliamentary IT systems.

Los Angeles County

2022-07-15 GovernmentUnited States

US government agency experienced significant operational disruption from ransomware infection.

London Fire Brigade

2022-07-04 GovernmentUnited Kingdom

Emergency services IT systems disrupted, affecting incident response coordination.

Qwest Communications

2022-02-15 Critical InfrastructureUnited States

Telecommunications company experienced ransomware attack affecting service delivery.

Mediatek Supply Chain

2021-11-15 Electronics/Supply ChainTaiwan

Chipmaker data breach affected semiconductor supply chain globally.

Kaseya VSA

2021-07-02 Software/ITUnited States

$70.0M

Paid: $11.0M

Supply chain attack affecting ~1,500 businesses through compromised software management tool.

REvilREvil

JBS Foods

2021-05-30 Food ProductionUnited States

$22.5M

Paid: $11.0M

Disrupted global meat processing operations, threatening food supply chain security.

REvilREvil

Scripps Health

2021-05-27 HealthcareUnited States

San Diego hospital network forced to divert patients and operate on emergency protocols.

REvil

Ireland Health Service Executive

2021-05-14 Government/HealthcareIreland

$20.0M

Attack on national health service disrupted medical systems and forced cancellation of procedures.

ContiConti

Colonial Pipeline

2021-05-07 EnergyUnited States

$5.0M

Paid: $4.4M

Forced shutdown of major U.S. fuel pipeline, causing gas shortage and national security crisis.

DarkSideDarkSide

Brenntag

2021-03-31 Supply ChainGermany

Chemical distributor experienced operational disruption affecting global supply chain.

DarkSide

University of San Francisco

2020-12-15 EducationUnited States

Educational institution paid ransom after threat actor leaked sensitive academic and personal data.

MazeMaze

SolarWinds

2020-12-13 Software/Supply ChainUnited States

Supply chain attack compromised software updates affecting US government agencies and Fortune 500 companies.

APT29N/A

OSForensics/Passware

2020-11-09 SoftwareUnited States

Forensics software companies compromised affecting cybersecurity professionals.

Universal Health Services

2020-09-27 HealthcareUnited States

400+ hospital locations across US disrupted for weeks, emergency services compromised.

Ryuk

Franchise Tax Board (California)

2020-08-25 GovernmentUnited States

California state tax agency suffered data breach exposing personal information through ransomware attack.

Taiwanese Ministry of Justice

2020-08-03 GovernmentTaiwan

Government agency suffered ransomware attack compromising sensitive internal systems.

Garmin

2020-07-23 ElectronicsUnited States

$10.0M

GPS and wearable device manufacturer services disrupted for several days.

WastedLocker

Travelex

2020-01-02 Financial ServicesUnited Kingdom

$3.0M

Global currency exchange service disrupted affecting international customers and operations.

Sodinokibi

Travelex

2019-12-29 Financial ServicesUnited Kingdom

$6.0M

Currency exchange service halted operations after ransomware forced offline during critical period.

Sodinokibi/REvilREvil

Baltimore City Government

2019-05-07 GovernmentUnited States

$76K

City services disrupted including water billing, permit systems, and property records.

RobinHood

Broward County School District

2018-06-07 EducationUnited States

$40K

Paid: $40K

Florida school district forced to pay ransom affecting student records and operations.

Riviera Beach City Government

2018-05-09 GovernmentUnited States

$600K

Paid: $600K

Florida city paid ransom to restore IT systems after significant operational disruption.

NotPetya Global Outbreak

2017-06-27 MultipleUkraine

$300

Wiper malware disguised as ransomware targeting Ukraine, causing estimated $10 billion in global damages.

Sandworm/GRUNotPetya

WannaCry Global Outbreak

2017-05-12 Healthcare/MultipleUnited Kingdom

$300

Paid: $140K

Affected over 200,000 computers across 150 countries, disrupting hospitals, banks, and critical infrastructure.

Lazarus GroupWannaCry

Protect your organization from ransomware

IQWorks helps organizations identify and protect sensitive data before it becomes a target.

Talk to an Expert