DisclosureLens
Feed News/Research · 2024 cohort

The Silent Majority: What Happens After Ransomware Gangs Name a Company

We followed every US organization posted on a ransomware leak site in 2024 — 3,106 criminal claims naming 2,747 organizations — into the regulatory record. More than four out of five never appeared in the channels we observe, and where a claim and a filing are linked to the same incident, the filing followed the criminal post by a median of 107 days.

By DisclosureLens · August 1, 2026 · Data snapshot 2026-07-31
Matched
19.1%
465 of 2,438 identifiable
Never appeared
80.9%
in the channels we observe
Median lag
107 d
post first, then the filing
Cohort
3,106
US claims · 2,747 organizations

Leak-site postings are criminal allegations, not confirmed breaches. This measures public visibility, not legal compliance — notification duties turn on facts not observable from outside. Matched-filing rates are best read as floors. Method & limitations below.

Key findings

  1. Nearly 1 in 5 identifiable US organizations claimed as victims — 19.1% — can be matched to a regulatory breach filing; roughly 81% remain publicly unaccounted for in the channels we observe. Across all US-tagged claimed victims, including those the criminals themselves left unidentifiable, the matched share is 17.1%. This measures public visibility, not legal compliance, and a leak-site post is an unverified criminal allegation.
  2. Where a claim and a filing are linked to the same incident, the criminal post came first in 91% of cases — and in those, the filing followed a median of 107 days later. A quarter took more than 200 days, one in ten more than eleven months. Counting the 9% that ran the other way, the median across all such pairs is 93 days. Notification clocks run from the organization's own discovery, not from the criminal post, so these intervals say nothing about whether any individual filing was timely.
  3. The one sector with a public federal breach portal is the most visible; the rest do not order neatly. Measured per claim, those against healthcare organizations matched a filing 32.6% of the time; manufacturing, 15.6%; the information sector, 11.5% — and part of that spread is our own coverage, since HHS gives us every reported US healthcare breach affecting 500 or more people while other sectors are visible mainly through 17 state registries.
  4. Matched-filing rates vary two-fold by which gang posted the claim, from BianLian (31.5%) to Akira (15.8%) — a gap that must be read alongside which sectors each gang hunts, and alongside how much of each crew's posting is fabricated or recycled. This is a traceability measure, not a lie detector.
  5. The matched-filing rates here are best read as floors. We can only count filings we can see and matches we can make; the limitations section also quantifies the main bias that runs the other way, and the lag statistics carry their own, different biases.

Two public records of the same crime

When a ransomware crew breaches an American company, the event can enter the public record twice. The first record is criminal: the gang posts its victim on a leak site, usually to pressure payment, sometimes to advertise. The second is regulatory: the victim notifies a state attorney general, HHS, or — for a material incident at a public company — the SEC. In the channels that publish such notices (roughly twenty-one states, HHS for breaches affecting 500 or more individuals, and the SEC), that notice becomes a public filing.

The two records are kept by adversaries, for opposite reasons, and almost nobody has measured how often they meet. The closest prior work is a Dutch study that matched leak-site victims against police reports and incident-response records to estimate the true number of ransomware attacks in the Netherlands. Related survey work found that while 92% of entrepreneurs say they would report a ransomware attack to police, about 18% of actual victims did. Both are Dutch; we found no equivalent measurement for the United States' regulatory record — the channel American breach-notification law actually mandates.

This report is that measurement. We took every leak-site claim posted during calendar 2024 whose victim geography resolved to the United States: 3,106 claims. We resolved each claimed victim to an organization, then searched a corpus of 41,878 formal breach filings for any filing by that organization from 180 days before the claim to 540 days after it. Every claim's window had fully elapsed before measurement, so each claimed victim had the same ~18 months to appear in the regulatory record.

The dark share

Of the 2,747 organizations the criminals claimed as victims, 309 — about 11% — were posted without a usable organization name: the gang published a bare domain, a text fragment, or literally “[Redacted]”. These victims almost never match a filing (2.5% of their claims, and 5 of the 309 organizations, matched anyway), for the obvious reason that there is usually no name to match.

That leaves 2,438 identifiable US organizations publicly claimed by ransomware gangs in 2024. 465 of them — 19.1% — can be matched to any formal breach filing. Counting every US-tagged claimed victim, identifiable or not, the share is 17.1% (470 of 2,747). Counting claims rather than organizations — some victims were posted more than once — it is 19.0% (591 of 3,106). However the ratio is cut, the shape is the same: more than four out of five organizations that ransomware criminals publicly claimed as victims never visibly accounted for it in the regulatory record we can observe.

Figure 1 · From 3,106 criminal claims to 465 organizations with a matching filing

US-geo-tagged leak-site claims posted in 2024, resolved to organizations and matched against 41,878 formal breach filings. The final bar is 19.1% of the 2,438 identifiable organizations. Matching and coverage misses push the true matched share above the one we measure; a smaller false-positive class pushes the other way.

Data table — Figure 1
Cohort funnel from claims posted to organizations matched
StageCount
Claims posted3,106
Organizations named2,747
Identifiable organizations2,438
Matched to a filing465

Two things this number is not. It is not a lawbreaking rate. Many states' notification duties turn on facts we cannot observe from outside: how many residents were affected, whether personal information was actually acquired, whether an exemption applied. An organization may also have notified individuals directly, or a regulator we do not cover, without ever appearing in our matching — the limitations section reports a spot-check that found exactly such a case. And it is not a claim that the gangs' postings are all true: a leak-site post is a criminal allegation, and some fraction of postings are exaggerated or fabricated. What the number does measure is public accountability: how often a publicly alleged breach is followed by any publicly visible formal disclosure.

The 107-day exposure window

For the victims who appear in both records, the ordering is stark. Among incident-linked matched pairs — the strictest match tier, where a claim and a filing are linked to the same incident — the criminals published first in 90.6% of cases. Within those, the filing came a median of 107 days later: a quarter took more than 200 days (the 75th percentile is 229) and one in ten more than 346 days — roughly eleven months. Counting the 9.4% of pairs that ran the other way, the median across all incident-linked pairs is 93 days.

Figure 2 · How long the regulatory record stayed silent

308 incident-linked claim-to-filing pairs from the 2024 US cohort. The amber column holds the 29 pairs where the filing came first — a different ordering, not a shorter lag. The median marker describes the 279 pairs where the criminal post came first. Lags are computed on timestamps; calendar-date differencing shifts the median by one day.

Data table — Figure 2
Distribution of days from criminal post to first regulatory filing
Days after the postPairs
Filing came first29
0–29 days36
30–5945
60–8939
90–11929
120–14927
150–17911
180–20913
210–23915
240–26913
270–2994
300–32913
330–3597
360 or more27

Those are not abstract intervals. The leak post is the moment the victim's data is publicly advertised as stolen — and, where the gang follows through, circulating and searchable. The regulatory filing is the point at which the breach enters the public record on the victim's side. Between the two lies an exposure window in which the data is advertised to criminal buyers while no public record exists on the victim's side. These lag statistics describe the matched population in aggregate; they imply nothing about the timeliness of any individual filing, because notification clocks start from facts — the organization's own discovery date, law-enforcement delay requests, statutory exemptions — that are not observable from outside.

Those 9.4% that ran the other way are worth a sentence: the organization filed before the gang posted. Prompt disclosure, in other words, does not prevent criminal publication — but it does close the exposure window, which is the part a victim organization controls.

Visibility tracks who has to file publicly

The sharpest split in the data is sectoral.

Figure 3 · Share of 2024 US claims that matched a regulatory filing, by sector

Claim-level: n is US-geo-tagged 2024 claims; the rate is the share whose claimed victim matched a filing. Healthcare is the one sector we observe through a national portal: 18 of its 136 matches came only through HHS, and without that channel it reads 28.3% rather than 32.6% — no other sector loses more than one match. The amber row is a coverage reference, not a sector: claims whose victim carried no sector tag match at 15.4%, inside the tagged sectors' range. Whiskers are approximate 95% bands — the healthcare-to-information gap is well outside sampling error, but several adjacent rows are not separable and should not be read as ranked. Sector codes are two-digit family tags. A further 111 claims fall in sectors with fewer than 100 claims each.

Data table — Figure 3
Matched-filing share by sector, with approximate 95% bands
SectorClaimsMatched
Health care (62)41732.6% ±4.5
Education (61)18328.4% ±6.5
Finance & insurance (52)15724.2% ±6.7
Public administration (92)13118.3% ±6.6
Transportation (48)15617.3% ±5.9
Manufacturing (31)41615.6% ±3.5
Professional services (54)95115.4% ±2.3
No sector tag27915.4% ±4.2
Information (51)30511.5% ±3.6

The gradient is consistent with who is obliged to file publicly. Healthcare sits under HIPAA's breach-notification rule and a public federal breach portal. Finance carries genuine overlapping duties of its own — the GLBA Safeguards Rule, the banking agencies' incident rules, NYDFS Part 500. Education is a weaker case for a sectoral story: FERPA mandates no breach notification at all. Manufacturing — ranked ransomware's most-attacked sector by several major trackers — has no sector-specific federal breach-notification duty, and its claims match a filing less than half as often as healthcare's.

Duty is not the whole story, and the table says so. Professional services — the largest bucket here, and covered by the same general state statutes as everyone else — matches at 15.4%, statistically indistinguishable from manufacturing; public administration sits below both education and finance. So the defensible reading is narrower than “regulation creates visibility”: a sector-specific duty that produces a public filing, as HIPAA's portal does, puts a sector at the top of this table. What orders the rest is not something a cross-section like this one can identify.

Part of the gradient is also ours, not the sectors'. HHS gives us national reach on healthcare breaches — every reported breach affecting 500 or more people, in all fifty states. Every other sector is visible mainly where it filed in one of the 17 state registries we ingest. A manufacturer that lawfully notified in a state we do not observe is counted dark; a hospital in that same state is not.

Half of that asymmetry is measurable. Eighteen of healthcare's 136 matches came only through the HHS portal; drop that channel and healthcare falls from 32.6% to 28.3%. No other sector loses more than one match — manufacturing is unchanged at 15.6% — so the healthcare-to-manufacturing gap narrows from 17.0 points to 12.7, and about three quarters of it survives. The other half cannot be measured at all: a filing made in one of the roughly thirty states we do not ingest is invisible by construction, and that loss falls on every sector except healthcare. Both halves point the same way, so even 28.3% against 15.6% is an upper bound on the true gap rather than a correction of it.

Federal incident-reporting policy is already moving into this space — but with a caveat this data makes concrete: CIRCIA's critical-infrastructure reporting rules, once in force, deliver incident reports to CISA confidentially, exempt by statute from FOIA and state public-records laws alike. They would close the government-visibility gap, not the public-accountability gap measured here. Closing the public gap requires rules that produce a public record, as HIPAA's portal does.

Who posted the claim changes whether the public ever hears

Matched-filing rates also vary two-fold by which gang posted the claim — but the table must be read together with its last column, and with its error bands. It lists every gang with at least 110 US-tagged 2024 claims; approximate 95% bands run ±5 to ±8 points at these n, so the BianLian-to-Akira span is outside sampling error while the mid-table ordering is not. Adjacent rows should not be read as ranked — which is why this one stays a table rather than becoming a ranked chart.

Matched-filing share and healthcare claim share, by gang
GangUS claimsMatchedIn healthcare
BianLian14931.5%24.2%
Hunters International12726.8%12.6%
INC Ransom12725.2%27.6%
Black Basta11024.5%10.0%
Medusa16024.4%13.1%
BlackSuit11423.7%17.5%
Play35518.9%1.7%
Qilin13617.6%19.1%
LockBit 3.023017.0%15.7%
RansomHub25316.2%14.6%
Akira19015.8%3.7%

This is a traceability measure, not a lie detector. Gangs that hunt regulated sectors — BianLian and INC Ransom, with roughly a quarter of their claims against healthcare organizations — leave a paper trail, because their claimed victims are the ones with filing duties. Gangs whose claimed victims skew toward manufacturers and service firms — 1.7% of Play's claims and 3.7% of Akira's are against healthcare — leave far fewer traces. Sector mix does not explain the whole ordering — the two highest-healthcare crews are not the two highest matchers — though the mid-table differences sit inside sampling error and should not be over-read. And a crew that posts more fabricated or recycled victims will land lower on this table for a reason that has nothing to do with its victims' filing behaviour.

What this study cannot show

Every matched-filing rate above is best read as a floor; the report quantifies what it can of the gap above each one and names what it cannot. Claimed victims are matched by resolved organization identity: a name-normalized twin scan bounds the same-name subclass of resolution misses at 0.15% of dark victims, but misses across different name forms — subsidiaries, d/b/a names, filings made by counsel — are undetectable by that scan and remain unquantified.

The main bias runs the other way, and we quantified its one detectable signature. Because a claim counts as matched when the same organization filed anything in the window, a filing about a different incident can produce a spurious match. Of the 591 matched claims, only 30 have their matching filing attached to an incident that already contains a different leak claim — the signature of a genuinely separate event. Treating all 30 as false positives would move the claim-level rate from 19.0% to 18.1%. A spurious match to an incident no gang ever claimed carries no such signature, so this quantifies the detectable class, not every possible false positive; the method appendix adds a distributional test pointing the same way.

Coverage is the larger limit. We observe 17 states' attorney-general filings, HHS, and the SEC. A victim that notified only a non-covered or non-publishing state, or only affected individuals, is invisible to us and counted dark. In a four-victim manual spot-check of dark victims, three showed no notification evidence anywhere on the public web; one had filed with a state regulator whose archive our corpus does not yet reach. A sample of four bounds nothing — it demonstrates the class exists, not its size.

The lag statistics carry different biases from the match rates: they are measured only on matched, incident-linked pairs — a regulated-sector-skewed subsample — so selection could move the median in either direction, and the 540-day matching window right-truncates the tail. Every claim received the identical, fully-elapsed window, so there is no differential censoring within the cohort; the operative truncation is the 540-day cap itself, plus residual source-ingestion lag near the window's edge.

The full method appendix — corpus definition, the junk-name predicate, window sensitivity (the claim-level rate moves only between 18.3% and 19.3% across three matching windows), a capture-recapture estimate of the true US victim population and why we present it only as a research direction — is published with the report. Every figure derives from SQL over the production corpus, and the queries are available on request.

Reproduce this in the product

Every record behind these figures is browsable. The claims feed carries the criminal record and the disclosures feed the regulatory one; an uncorroborated claim shows a corroboration watch — whether a formal filing has yet been linked to it. That feature applies the strict, incident-level test; this study runs the same question backward over a year of history and reports the more generous organization-level answer beside it.

Sources & prior work

Corrections: corrections@disclosurelens.com — 48-hour SLA. Leak-site claims are sourced from Ransomware.live and used under its commercial terms (source: Ransomware.live). Structured extraction is LLM-assisted with a complete per-field audit trail back to each source document; every figure in this report was human-audited.