THREAT INTELLIGENCE ANALYTICS

Macro Incident Trends & Analytics

Download Raw Datasets (CSV/JSON/SQLite) →

Empirical findings synthesized from sworn federal court dockets, SEC disclosures, CISA alerts, and asset forfeiture records across all 59 cataloged incidents.

Key Facts

Cataloged Cases
59
Primary legal records
Documented Losses
$42.8B+
Quantified impact
Tracked Actors
20
APTs and cartels
OFAC Sanctions
12
Treasury designations
  • 59 primary-sourced prosecution matters and cyber incident records analyzed.
  • Over $42.8 billion in cumulative direct documented financial loss.
  • Stolen single-factor credentials remain the #1 initial intrusion vector across modern enterprise breaches.
  • $243.9M in verified ransom extortion payments tracked with law enforcement forfeiture metrics.
Ransom Extortion Demanded
$700.1M

Cumulative extortion demands across tracked landmark ransomware incidents.

Extortion Paid by Victims
$243.9M

Direct cryptocurrency payments transferred to threat actor wallets before decryption.

Law Enforcement Seizures
$50.5M

Cryptocurrency forfeited or clawed back via FBI and international seizure operations.

Initial Access Vectors Across Landmark Breaches

Distribution of root intrusion mechanisms identified in primary forensic evidence.

Initial Access Vectors Dominant access methods across 59 cases. Stolen Credentials / Single-Factor Portal 10 cases Public Vulnerability / CVE Exploitation 3 cases Spearphishing & Malicious Links 1 cases Software Supply Chain Infiltration 3 cases Helpdesk Social Engineering / Vishing 1 cases Cloud Workspace Misconfiguration / Token Leak 41 cases
Dominant access methods across 59 cases.
Initial Access Vectors
Category Count
Stolen Credentials / Single-Factor Portal 10 cases
Public Vulnerability / CVE Exploitation 3 cases
Spearphishing & Malicious Links 1 cases
Software Supply Chain Infiltration 3 cases
Helpdesk Social Engineering / Vishing 1 cases
Cloud Workspace Misconfiguration / Token Leak 41 cases

Victim Sector Concentration

Top industry verticals targeted by nation-state actors and cybercrime cartels.

Victim Sectors Industry distribution of cases. Financial Services 17 cases Retail 9 cases Banking 8 cases Healthcare 7 cases Energy 6 cases E-Commerce 6 cases Telecommunications 5 cases Education 4 cases
Industry distribution of cases.
Victim Sectors
Category Count
Financial Services 17 cases
Retail 9 cases
Banking 8 cases
Healthcare 7 cases
Energy 6 cases
E-Commerce 6 cases
Telecommunications 5 cases
Education 4 cases

Attributed Sovereign Jurisdiction & Syndicate Origin

Case volume attributed to nation-state intelligence agencies or sovereign hosts.

View All Threat Actor Dossiers →
Russian Federation
14
linked cases
Transnational (US / UK / Canada)
2
linked cases
People's Republic of China
2
linked cases
Democratic People's Republic of Korea
1
linked cases
Transnational / Eastern Europe
1
linked cases
Islamic Republic of Iran
1
linked cases
Transnational (UK / Brazil)
0
linked cases

Historical Evolution: Attacker Velocity & Dwell Time Trends

ERA 1: 2005 to 2015

Extended Espionage Dwell Time

Median dwell time exceeded 200+ days. Actors like PLA Unit 61398 and APT29 operated silently for years extracting intellectual property before network discovery.

Examples: Target Stores (40 days), Equifax (76 days), OPM (365+ days).
ERA 2: 2016 to 2021

Automated Lateral Traversal

Wormable exploits and automated scripts dropped dwell time to 10 to 30 days. Ransomware groups demanded millions after staging exfiltration over weekends.

Examples: NotPetya (hours), Colonial Pipeline (8 days), Kaseya (hours).
ERA 3: 2022 to Present

Rapid Identity & Cloud Heists

Median dwell time dropped to under 48 hours. Infostealer credentials and SaaS API tokens permit immediate exfiltration without deploying host binaries.

Examples: Snowflake / Ticketmaster (hours), MGM Resorts (10-minute vishing), Midnight Blizzard.