Two public records of the same crime
When a ransomware crew breaches an American company, the event can enter the public record twice. The first record is criminal: the gang posts its victim on a leak site, usually to pressure payment, sometimes to advertise. The second is regulatory: the victim notifies a state attorney general, HHS, or — for a material incident at a public company — the SEC. In the channels that publish such notices (roughly twenty-one states, HHS for breaches affecting 500 or more individuals, and the SEC), that notice becomes a public filing.
The two records are kept by adversaries, for opposite reasons, and almost nobody has measured how often they meet. The closest prior work is a Dutch study that matched leak-site victims against police reports and incident-response records to estimate the true number of ransomware attacks in the Netherlands. Related survey work found that while 92% of entrepreneurs say they would report a ransomware attack to police, about 18% of actual victims did. Both are Dutch; we found no equivalent measurement for the United States' regulatory record — the channel American breach-notification law actually mandates.
This report is that measurement. We took every leak-site claim posted during calendar 2024 whose victim geography resolved to the United States: 3,106 claims. We resolved each claimed victim to an organization, then searched a corpus of 41,878 formal breach filings for any filing by that organization from 180 days before the claim to 540 days after it. Every claim's window had fully elapsed before measurement, so each claimed victim had the same ~18 months to appear in the regulatory record.
The dark share
Of the 2,747 organizations the criminals claimed as victims, 309 — about 11% — were posted without a usable organization name: the gang published a bare domain, a text fragment, or literally “[Redacted]”. These victims almost never match a filing (2.5% of their claims, and 5 of the 309 organizations, matched anyway), for the obvious reason that there is usually no name to match.
That leaves 2,438 identifiable US organizations publicly claimed by ransomware gangs in 2024. 465 of them — 19.1% — can be matched to any formal breach filing. Counting every US-tagged claimed victim, identifiable or not, the share is 17.1% (470 of 2,747). Counting claims rather than organizations — some victims were posted more than once — it is 19.0% (591 of 3,106). However the ratio is cut, the shape is the same: more than four out of five organizations that ransomware criminals publicly claimed as victims never visibly accounted for it in the regulatory record we can observe.
US-geo-tagged leak-site claims posted in 2024, resolved to organizations and matched against 41,878 formal breach filings. The final bar is 19.1% of the 2,438 identifiable organizations. Matching and coverage misses push the true matched share above the one we measure; a smaller false-positive class pushes the other way.
Data table — Figure 1
| Stage | Count |
|---|---|
| Claims posted | 3,106 |
| Organizations named | 2,747 |
| Identifiable organizations | 2,438 |
| Matched to a filing | 465 |
Two things this number is not. It is not a lawbreaking rate. Many states' notification duties turn on facts we cannot observe from outside: how many residents were affected, whether personal information was actually acquired, whether an exemption applied. An organization may also have notified individuals directly, or a regulator we do not cover, without ever appearing in our matching — the limitations section reports a spot-check that found exactly such a case. And it is not a claim that the gangs' postings are all true: a leak-site post is a criminal allegation, and some fraction of postings are exaggerated or fabricated. What the number does measure is public accountability: how often a publicly alleged breach is followed by any publicly visible formal disclosure.
The 107-day exposure window
For the victims who appear in both records, the ordering is stark. Among incident-linked matched pairs — the strictest match tier, where a claim and a filing are linked to the same incident — the criminals published first in 90.6% of cases. Within those, the filing came a median of 107 days later: a quarter took more than 200 days (the 75th percentile is 229) and one in ten more than 346 days — roughly eleven months. Counting the 9.4% of pairs that ran the other way, the median across all incident-linked pairs is 93 days.
308 incident-linked claim-to-filing pairs from the 2024 US cohort. The amber column holds the 29 pairs where the filing came first — a different ordering, not a shorter lag. The median marker describes the 279 pairs where the criminal post came first. Lags are computed on timestamps; calendar-date differencing shifts the median by one day.
Data table — Figure 2
| Days after the post | Pairs |
|---|---|
| Filing came first | 29 |
| 0–29 days | 36 |
| 30–59 | 45 |
| 60–89 | 39 |
| 90–119 | 29 |
| 120–149 | 27 |
| 150–179 | 11 |
| 180–209 | 13 |
| 210–239 | 15 |
| 240–269 | 13 |
| 270–299 | 4 |
| 300–329 | 13 |
| 330–359 | 7 |
| 360 or more | 27 |
Those are not abstract intervals. The leak post is the moment the victim's data is publicly advertised as stolen — and, where the gang follows through, circulating and searchable. The regulatory filing is the point at which the breach enters the public record on the victim's side. Between the two lies an exposure window in which the data is advertised to criminal buyers while no public record exists on the victim's side. These lag statistics describe the matched population in aggregate; they imply nothing about the timeliness of any individual filing, because notification clocks start from facts — the organization's own discovery date, law-enforcement delay requests, statutory exemptions — that are not observable from outside.
Those 9.4% that ran the other way are worth a sentence: the organization filed before the gang posted. Prompt disclosure, in other words, does not prevent criminal publication — but it does close the exposure window, which is the part a victim organization controls.
Visibility tracks who has to file publicly
The sharpest split in the data is sectoral.
Claim-level: n is US-geo-tagged 2024 claims; the rate is the share whose claimed victim matched a filing. Healthcare is the one sector we observe through a national portal: 18 of its 136 matches came only through HHS, and without that channel it reads 28.3% rather than 32.6% — no other sector loses more than one match. The amber row is a coverage reference, not a sector: claims whose victim carried no sector tag match at 15.4%, inside the tagged sectors' range. Whiskers are approximate 95% bands — the healthcare-to-information gap is well outside sampling error, but several adjacent rows are not separable and should not be read as ranked. Sector codes are two-digit family tags. A further 111 claims fall in sectors with fewer than 100 claims each.
Data table — Figure 3
| Sector | Claims | Matched |
|---|---|---|
| Health care (62) | 417 | 32.6% ±4.5 |
| Education (61) | 183 | 28.4% ±6.5 |
| Finance & insurance (52) | 157 | 24.2% ±6.7 |
| Public administration (92) | 131 | 18.3% ±6.6 |
| Transportation (48) | 156 | 17.3% ±5.9 |
| Manufacturing (31) | 416 | 15.6% ±3.5 |
| Professional services (54) | 951 | 15.4% ±2.3 |
| No sector tag | 279 | 15.4% ±4.2 |
| Information (51) | 305 | 11.5% ±3.6 |
The gradient is consistent with who is obliged to file publicly. Healthcare sits under HIPAA's breach-notification rule and a public federal breach portal. Finance carries genuine overlapping duties of its own — the GLBA Safeguards Rule, the banking agencies' incident rules, NYDFS Part 500. Education is a weaker case for a sectoral story: FERPA mandates no breach notification at all. Manufacturing — ranked ransomware's most-attacked sector by several major trackers — has no sector-specific federal breach-notification duty, and its claims match a filing less than half as often as healthcare's.
Duty is not the whole story, and the table says so. Professional services — the largest bucket here, and covered by the same general state statutes as everyone else — matches at 15.4%, statistically indistinguishable from manufacturing; public administration sits below both education and finance. So the defensible reading is narrower than “regulation creates visibility”: a sector-specific duty that produces a public filing, as HIPAA's portal does, puts a sector at the top of this table. What orders the rest is not something a cross-section like this one can identify.
Part of the gradient is also ours, not the sectors'. HHS gives us national reach on healthcare breaches — every reported breach affecting 500 or more people, in all fifty states. Every other sector is visible mainly where it filed in one of the 17 state registries we ingest. A manufacturer that lawfully notified in a state we do not observe is counted dark; a hospital in that same state is not.
Half of that asymmetry is measurable. Eighteen of healthcare's 136 matches came only through the HHS portal; drop that channel and healthcare falls from 32.6% to 28.3%. No other sector loses more than one match — manufacturing is unchanged at 15.6% — so the healthcare-to-manufacturing gap narrows from 17.0 points to 12.7, and about three quarters of it survives. The other half cannot be measured at all: a filing made in one of the roughly thirty states we do not ingest is invisible by construction, and that loss falls on every sector except healthcare. Both halves point the same way, so even 28.3% against 15.6% is an upper bound on the true gap rather than a correction of it.
Federal incident-reporting policy is already moving into this space — but with a caveat this data makes concrete: CIRCIA's critical-infrastructure reporting rules, once in force, deliver incident reports to CISA confidentially, exempt by statute from FOIA and state public-records laws alike. They would close the government-visibility gap, not the public-accountability gap measured here. Closing the public gap requires rules that produce a public record, as HIPAA's portal does.
Who posted the claim changes whether the public ever hears
Matched-filing rates also vary two-fold by which gang posted the claim — but the table must be read together with its last column, and with its error bands. It lists every gang with at least 110 US-tagged 2024 claims; approximate 95% bands run ±5 to ±8 points at these n, so the BianLian-to-Akira span is outside sampling error while the mid-table ordering is not. Adjacent rows should not be read as ranked — which is why this one stays a table rather than becoming a ranked chart.
| Gang | US claims | Matched | In healthcare |
|---|---|---|---|
| BianLian | 149 | 31.5% | 24.2% |
| Hunters International | 127 | 26.8% | 12.6% |
| INC Ransom | 127 | 25.2% | 27.6% |
| Black Basta | 110 | 24.5% | 10.0% |
| Medusa | 160 | 24.4% | 13.1% |
| BlackSuit | 114 | 23.7% | 17.5% |
| Play | 355 | 18.9% | 1.7% |
| Qilin | 136 | 17.6% | 19.1% |
| LockBit 3.0 | 230 | 17.0% | 15.7% |
| RansomHub | 253 | 16.2% | 14.6% |
| Akira | 190 | 15.8% | 3.7% |
This is a traceability measure, not a lie detector. Gangs that hunt regulated sectors — BianLian and INC Ransom, with roughly a quarter of their claims against healthcare organizations — leave a paper trail, because their claimed victims are the ones with filing duties. Gangs whose claimed victims skew toward manufacturers and service firms — 1.7% of Play's claims and 3.7% of Akira's are against healthcare — leave far fewer traces. Sector mix does not explain the whole ordering — the two highest-healthcare crews are not the two highest matchers — though the mid-table differences sit inside sampling error and should not be over-read. And a crew that posts more fabricated or recycled victims will land lower on this table for a reason that has nothing to do with its victims' filing behaviour.
What this study cannot show
Every matched-filing rate above is best read as a floor; the report quantifies what it can of the gap above each one and names what it cannot. Claimed victims are matched by resolved organization identity: a name-normalized twin scan bounds the same-name subclass of resolution misses at 0.15% of dark victims, but misses across different name forms — subsidiaries, d/b/a names, filings made by counsel — are undetectable by that scan and remain unquantified.
The main bias runs the other way, and we quantified its one detectable signature. Because a claim counts as matched when the same organization filed anything in the window, a filing about a different incident can produce a spurious match. Of the 591 matched claims, only 30 have their matching filing attached to an incident that already contains a different leak claim — the signature of a genuinely separate event. Treating all 30 as false positives would move the claim-level rate from 19.0% to 18.1%. A spurious match to an incident no gang ever claimed carries no such signature, so this quantifies the detectable class, not every possible false positive; the method appendix adds a distributional test pointing the same way.
Coverage is the larger limit. We observe 17 states' attorney-general filings, HHS, and the SEC. A victim that notified only a non-covered or non-publishing state, or only affected individuals, is invisible to us and counted dark. In a four-victim manual spot-check of dark victims, three showed no notification evidence anywhere on the public web; one had filed with a state regulator whose archive our corpus does not yet reach. A sample of four bounds nothing — it demonstrates the class exists, not its size.
The lag statistics carry different biases from the match rates: they are measured only on matched, incident-linked pairs — a regulated-sector-skewed subsample — so selection could move the median in either direction, and the 540-day matching window right-truncates the tail. Every claim received the identical, fully-elapsed window, so there is no differential censoring within the cohort; the operative truncation is the 540-day cap itself, plus residual source-ingestion lag near the window's edge.
The full method appendix — corpus definition, the junk-name predicate, window sensitivity (the claim-level rate moves only between 18.3% and 19.3% across three matching windows), a capture-recapture estimate of the true US victim population and why we present it only as a research direction — is published with the report. Every figure derives from SQL over the production corpus, and the queries are available on request.
Reproduce this in the product
Every record behind these figures is browsable. The claims feed carries the criminal record and the disclosures feed the regulatory one; an uncorroborated claim shows a corroboration watch — whether a formal filing has yet been linked to it. That feature applies the strict, incident-level test; this study runs the same question backward over a year of history and reports the more generous organization-level answer beside it.
- Claims posted by BianLian — the most traceable crew in the table
- Claims posted by Akira — the least
- Healthcare claims versus manufacturing claims
- Incidents — where the two records are joined
Sources & prior work
- Meurs, Junger, Cruyff & van der Heijden — Estimating the Number of Ransomware AttacksJournal of Quantitative Criminology, 2025 — the Dutch capture-recapture predecessor
- Matthijsse, van 't Hoff-de Goede & Leukfeldt — To report or not to reportJournal of Criminal Justice 97, 2025 — 92% say they would report; ~18% did
- HHS Office for Civil Rights — Breach Portalthe public federal record for breaches affecting 500+ individuals
- Ransomware.live — leak-site aggregationsource for every leak-site claim in this study; used under its PRO commercial terms
- CISA — CIRCIAincident reports to CISA are confidential by statute (6 U.S.C. §681e)
Corrections: corrections@disclosurelens.com — 48-hour SLA. Leak-site claims are sourced from Ransomware.live and used under its commercial terms (source: Ransomware.live). Structured extraction is LLM-assisted with a complete per-field audit trail back to each source document; every figure in this report was human-audited.