Supply chain attack statistics

The Arasy corpus holds 221,916 cyber incident records collected from public authoritative sources. 48,367 are confirmed breaches, 33,796 are categorized as ransomware, and 1,669 as supply-chain incidents. Ransomware gangs have posted 13,580 victim claims on leak sites we monitor, and data protection regulators in our tracker have issued €7.04 billion in fines. Every number on this page is a property of the corpus, not an estimate of the global total; most incidents worldwide are never publicly disclosed.
221,916
Incident records in the corpus
48,367
Confirmed breaches (authoritative source required)
89,058
Supply chain relationships mapped

How much of this is verified

Most breach statistics mix rumor with record. Every record in the Arasy corpus carries a verification tier, and we publish the split rather than the flattering total:

TierWhat it meansRecords
Confirmed breachCorroborated by a regulatory filing or an authoritative disclosure48,367
Suspected breachStrong indicators, not yet corroborated by an authoritative source34,103
Security incidentA cyber event without confirmed data compromise20,875
Unverified claimAsserted by a third party such as a ransomware gang, not verified24,358
Non-cyber recordRegulatory or contextual record with no cyber event29,584
Security eventLow-level event record154
Not yet classifiedRecords the verification pipeline has not yet processed64,475

Tiers sum to 221,916. Gang-claimed leak-site victims never enter the confirmed tier without an authoritative source.

YearRecords publishedCount
2005-2017
16,407
2018
2,321
2019
3,132
2020
5,835
2021
6,951
2022
8,726
2023
14,896
2024
19,495
2025
17,017
2026
33,497

Counts reflect corpus coverage, not global incidence: collection began recently and earlier years contain only what historical sources preserve. 93,639 records carry no usable publication date and are excluded from this table only.

Ransomware victims claimed on leak sites, by year

YearLeak-site victim postsCount
2025
871
2026
12,709
These are gang-claimed victim posts scraped from ransomware leak sites, not independently confirmed breaches. Gangs exaggerate, repost, and sometimes fabricate victims, which is exactly why this data lives in its own verification tier.

Which industries appear most often

IndustryIncident recordsCount
Technology
17,731
Healthcare
11,856
Commercial
11,809
Financial Services
11,652
Government
11,003
Education
9,033
Legal
5,723
Automotive
4,465
Manufacturing
3,681
Non-Profit
3,255

Denominator honesty: of 221,916 records, 104,897 carry no industry classification yet and 4,438 are marked not applicable. The table covers the 112,581 classified records.

The supply chain graph behind the incidents

Incident data answers what happened. The ownership and dependency graph shows who else could be exposed: 167,927 organizations connected by 89,058 mapped relationships.

Relationship typeEdgesCount
Subsidiary of (corporate ownership)
75,643
Uses software (technology dependency)
9,704
Acquired by
3,416
Vendor of
244
Managed by MSP
51

Exposure paths are modeled from ownership and dependency relationships. They do not establish that an incident or compromise propagated between companies.

What regulators are fining

Our GDPR enforcement tracker holds 3,495 enforcement records, of which 3,042 carry a published fine, totaling €7.04 billion:

YearFines issued (EUR)Total
2018
€458,688
2019
€88,761,764
2020
€171,955,109
2021
€1,268,741,503
2022
€841,904,565
2023
€2,087,091,232
2024
€1,227,578,379
2025
€1,128,444,317
2026
€225,879,175

EU and UK data protection fines only, as published by the authorities; wider regulatory enforcement (SEC, FTC, financial regulators, and DPAs across 44 jurisdictions) is tracked separately in the platform.

Methodology

Every figure on this page is computed by a versioned script from a frozen export of the corpus, with per-layer accounting that must sum exactly to the number of records processed; unparseable and unclassified records are counted and disclosed, never dropped. Sources are public and authoritative: SEC filings, the HHS breach portal, state attorney general portals, data protection authorities across 44 jurisdictions, CISA and vendor advisories, verified breach databases, and leak-site monitoring. Cite freely with a link to this page.

Frequently asked questions

How many supply chain attacks happened in 2026?

No complete global count exists; most incidents are never publicly disclosed. What can be measured is disclosure: the Arasy corpus has recorded 33,497 incident records published in 2026 so far, and 1,669 records across all years are categorized as supply-chain incidents. Both figures describe the corpus, not the true global total.

What is a supply chain attack?

An attack that reaches its victims through something they depend on: a software vendor, a service provider, a subsidiary, or an acquired company. One compromise at a supplier can cascade to its downstream customers, which is why the same incident keeps resurfacing across otherwise unrelated organizations.

How reliable are ransomware victim counts?

Leak-site numbers are gang-claimed, not independently verified. Our corpus holds 13,580 victim posts scraped from ransomware leak sites, and they are kept in a separate verification tier from the 48,367 confirmed breaches, which require an authoritative source such as a regulatory filing.

Where does this data come from?

Public, authoritative sources: SEC 8-K filings, the HHS breach portal, US state attorney general portals, data protection authorities across 44 jurisdictions, CISA and vendor advisories, verified breach databases, and ransomware leak-site monitoring. Collection runs continuously and every record keeps its source.

See these incidents on your own supply chain

Overlay your supplier list and see which of your vendors, their parents, or their subsidiaries appear in this corpus. We are running a small number of pilot demos.

Request a pilot demo Estimate your breach cost