Home › Data feeds

Predictive threat intelligence · open data

Ransomware data feeds

The numbers behind our ransomware tracker, published as free, machine-readable feeds — so you can cite them, chart them, or wire them into your own tooling. JSON content, stable URLs, updated daily.

Files are served with a .js extension but contain JSON (Content-Type: application/javascript). Fetch and JSON.parse() as normal. This is a deliberate edge-cache convention, not JSONP. Every feed carries a {generated, source, license, …} envelope. Reuse freely with attribution to Ninja Labz (ninjalabz.io).

The feeds

DailyJSON~25 groups

Every ransomware group we track, ranked by cumulative claimed victims, with its top sector, top country, suspected origin, sanctions flag, dossier URL and a link to its own detail feed.

{
  "generated": "2026-10-07T04:17:00+00:00",
  "source": "https://ninjalabz.io",
  "license": "CC BY 4.0",
  "count": 24,
  "groups": [
    { "slug": "lockbit", "name": "LockBit", "victims": 1987,
      "top_sector": "Manufacturing", "top_country": "US",
      "origin": "Russia", "sanctioned": true, "apt": false,
      "url": "https://ninjalabz.io/ransomware/lockbit",
      "feed": "https://ninjalabz.io/feeds/ransomware/group-lockbit.js" }
  ]
}
DailyJSONlatest 500

The most recent dated victim claims across all groups, newest first — date, group (and dossier URL), claimed organisation, sector and country.

{
  "generated": "2026-10-07T04:17:00+00:00",
  "count": 500,
  "victims": [
    { "date": "2026-10-06", "group": "Qilin", "group_slug": "qilin",
      "victim": "Example Corp", "sector": "Healthcare", "country": "US",
      "url": "https://ninjalabz.io/ransomware/qilin" }
  ]
}
DailyJSONtime series

Per-calendar-month claimed-victim totals with the most active groups, sectors and countries — the series that powers the trend lines and the monthly Predictive Intel Report.

{
  "generated": "2026-10-07T04:17:00+00:00",
  "months": [
    { "month": "2026-10", "total": 214,
      "top_groups":    [ { "name": "Qilin", "victims": 41 } ],
      "top_sectors":   [ { "name": "Manufacturing", "victims": 38 } ],
      "top_countries": [ { "name": "US", "victims": 96 } ] }
  ]
}

Per-group detail

/feeds/ransomware/group-<slug>.js
DailyJSONone per group

One feed per group (group-lockbit.js, group-qilin.js …) — victim count, aliases, suspected origin and basis, sanctions flag, full sector and country breakdowns, and recent claims. The feed field of each entry in groups.js points here.

Fields & cadence

Field (envelope)Meaning
generatedISO-8601 UTC timestamp of the build that produced the file.
sourceAlways https://ninjalabz.io.
licenseCC BY 4.0 — reuse with attribution.
author / publisherScott Gardner / Ninja Labz.

Feeds are regenerated on each ransomware build (currently daily) from the Ninja Signal threat-intelligence graph. Victim entries are groups' own public leak-site claims, aggregated and tracked — not independently verified, and listing is not confirmation a breach occurred. Country codes are ISO-3166 alpha-2 where available.

Example — read a feed in the browser

const res  = await fetch("https://ninjalabz.io/feeds/ransomware/groups.js");
const data = await res.json();
console.log(data.count, "groups · generated", data.generated);
for (const g of data.groups.slice(0, 5))
  console.log(g.name, g.victims, g.top_sector ?? "—");

See the human-readable tracker on the ransomware index, the narrative monthly Predictive Intel Report, or new victims every morning in the Daily.