Desk live·
ForensicPost
Ransomware/Verification/File 25-1218b

What “publicly Disclosed” Leaves Out

Every ransomware total in this corpus counts publicly disclosed attacks. Four categories are excluded by construction, and one of them is the organisations that handled it well.

Constructed geometry · not a chart of case data
TargetRansomware measurement
ActorMultiple
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

This file enumerates what a "publicly disclosed ransomware attacks" figure — the basis of 25-1210b, 25-1230 and every ransomware total in this database — cannot include.

One: Victims Who Paid Before Publication

A leak-site listing exists to apply pressure. An organisation that pays during negotiation is generally never listed, so the counts systematically exclude successful extortion.

Which produces an uncomfortable inversion: the more effective an extortion operation is at extracting payment, the less of its activity appears in the statistics used to measure it.

Two: Attacks That Were Stopped

Pakistan Petroleum detected and isolated on the day, at 25-0807. Princeton ejected an intruder within 24 hours, at 25-1026. Neither is a ransomware statistic anywhere.

This desk filed at 25-0807 that a corpus assembled from disclosures records failures in detail and successes almost never. The totals inherit that: they count the incidents that got far enough to be worth publishing.

Three: Groups That Do Not Run Leak Sites

Not every operation publishes victims. Some encrypt without exfiltration and have nothing to leak; some prefer quiet negotiation; some are too small to maintain infrastructure.

The fragmentation file at 25-1226 recorded 73 new brands in one year, and a new brand’s first act is usually to establish a leak site — which means the counts may over-represent new entrants and under-represent quiet operators.

Four: Jurisdictions The Trackers Do Not Cover

The four filters at 25-0502 — mandatory disclosure, collective redress, a research industry, publication in English — shape which incidents anyone records. The regional files at 25-1116 and 25-0709 found leak sites functioning as the primary public record precisely where disclosure is not mandatory.

What That Leaves

A count of attacks that failed to extract payment, succeeded far enough to matter, were conducted by groups that advertise, against organisations in jurisdictions researchers watch.

That is a real and useful population. It is not "ransomware attacks in 2025", and every file in this corpus that quotes such a total — including this desk’s own — should be read with the four exclusions attached.

This is an analysis file

It describes structural exclusions in the incident counts used throughout this database. Sources below support the totals it examines. Corrections: corrections@forensicpost.com.

Sources
  1. Record number of ransomware victims and groups in 2025Infosecurity Magazine
  2. Ransomware in healthcare: the attack timelineCybelAngel
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary