Home › Data feeds
Predictive threat intelligence · open data
Ransomware data feeds
The numbers behind our ransomware tracker, published as free, machine-readable feeds — so you can cite them, chart them, or wire them into your own tooling. JSON content, stable URLs, updated daily.
Files are served with a .js extension but contain JSON
(Content-Type: application/javascript). Fetch and JSON.parse() as normal. This is a
deliberate edge-cache convention, not JSONP. Every feed carries a {generated, source, license, …}
envelope. Reuse freely with attribution to Ninja Labz (ninjalabz.io).
The feeds
Tracked groups
/feeds/ransomware/groups.jsEvery ransomware group we track, ranked by cumulative claimed victims, with its top sector, top country, suspected origin, sanctions flag, dossier URL and a link to its own detail feed.
{
"generated": "2026-10-07T04:17:00+00:00",
"source": "https://ninjalabz.io",
"license": "CC BY 4.0",
"count": 24,
"groups": [
{ "slug": "lockbit", "name": "LockBit", "victims": 1987,
"top_sector": "Manufacturing", "top_country": "US",
"origin": "Russia", "sanctioned": true, "apt": false,
"url": "https://ninjalabz.io/ransomware/lockbit",
"feed": "https://ninjalabz.io/feeds/ransomware/group-lockbit.js" }
]
}
Recent claimed victims
/feeds/ransomware/victims-recent.jsThe most recent dated victim claims across all groups, newest first — date, group (and dossier URL), claimed organisation, sector and country.
{
"generated": "2026-10-07T04:17:00+00:00",
"count": 500,
"victims": [
{ "date": "2026-10-06", "group": "Qilin", "group_slug": "qilin",
"victim": "Example Corp", "sector": "Healthcare", "country": "US",
"url": "https://ninjalabz.io/ransomware/qilin" }
]
}
Monthly statistics
/feeds/ransomware/stats-monthly.jsPer-calendar-month claimed-victim totals with the most active groups, sectors and countries — the series that powers the trend lines and the monthly Predictive Intel Report.
{
"generated": "2026-10-07T04:17:00+00:00",
"months": [
{ "month": "2026-10", "total": 214,
"top_groups": [ { "name": "Qilin", "victims": 41 } ],
"top_sectors": [ { "name": "Manufacturing", "victims": 38 } ],
"top_countries": [ { "name": "US", "victims": 96 } ] }
]
}
Per-group detail
/feeds/ransomware/group-<slug>.jsOne feed per group (group-lockbit.js, group-qilin.js …) — victim count, aliases,
suspected origin and basis, sanctions flag, full sector and country breakdowns, and recent claims. The
feed field of each entry in groups.js points here.
Fields & cadence
| Field (envelope) | Meaning |
|---|---|
generated | ISO-8601 UTC timestamp of the build that produced the file. |
source | Always https://ninjalabz.io. |
license | CC BY 4.0 — reuse with attribution. |
author / publisher | Scott Gardner / Ninja Labz. |
Feeds are regenerated on each ransomware build (currently daily) from the Ninja Signal threat-intelligence graph. Victim entries are groups' own public leak-site claims, aggregated and tracked — not independently verified, and listing is not confirmation a breach occurred. Country codes are ISO-3166 alpha-2 where available.
Example — read a feed in the browser
const res = await fetch("https://ninjalabz.io/feeds/ransomware/groups.js");
const data = await res.json();
console.log(data.count, "groups · generated", data.generated);
for (const g of data.groups.slice(0, 5))
console.log(g.name, g.victims, g.top_sector ?? "—");
See the human-readable tracker on the ransomware index, the narrative monthly Predictive Intel Report, or new victims every morning in the Daily.