Supply chain attack statistics
How much of this is verified
Most breach statistics mix rumor with record. Every record in the Arasy corpus carries a verification tier, and we publish the split rather than the flattering total:
| Tier | What it means | Records |
|---|---|---|
| Confirmed breach | Corroborated by a regulatory filing or an authoritative disclosure | 48,367 |
| Suspected breach | Strong indicators, not yet corroborated by an authoritative source | 34,103 |
| Security incident | A cyber event without confirmed data compromise | 20,875 |
| Unverified claim | Asserted by a third party such as a ransomware gang, not verified | 24,358 |
| Non-cyber record | Regulatory or contextual record with no cyber event | 29,584 |
| Security event | Low-level event record | 154 |
| Not yet classified | Records the verification pipeline has not yet processed | 64,475 |
Tiers sum to 221,916. Gang-claimed leak-site victims never enter the confirmed tier without an authoritative source.
Incident records by year of publication
| Year | Records published | Count |
|---|---|---|
| 2005-2017 | 16,407 | |
| 2018 | 2,321 | |
| 2019 | 3,132 | |
| 2020 | 5,835 | |
| 2021 | 6,951 | |
| 2022 | 8,726 | |
| 2023 | 14,896 | |
| 2024 | 19,495 | |
| 2025 | 17,017 | |
| 2026 | 33,497 |
Counts reflect corpus coverage, not global incidence: collection began recently and earlier years contain only what historical sources preserve. 93,639 records carry no usable publication date and are excluded from this table only.
Ransomware victims claimed on leak sites, by year
| Year | Leak-site victim posts | Count |
|---|---|---|
| 2025 | 871 | |
| 2026 | 12,709 |
Which industries appear most often
| Industry | Incident records | Count |
|---|---|---|
| Technology | 17,731 | |
| Healthcare | 11,856 | |
| Commercial | 11,809 | |
| Financial Services | 11,652 | |
| Government | 11,003 | |
| Education | 9,033 | |
| Legal | 5,723 | |
| Automotive | 4,465 | |
| Manufacturing | 3,681 | |
| Non-Profit | 3,255 |
Denominator honesty: of 221,916 records, 104,897 carry no industry classification yet and 4,438 are marked not applicable. The table covers the 112,581 classified records.
The supply chain graph behind the incidents
Incident data answers what happened. The ownership and dependency graph shows who else could be exposed: 167,927 organizations connected by 89,058 mapped relationships.
| Relationship type | Edges | Count |
|---|---|---|
| Subsidiary of (corporate ownership) | 75,643 | |
| Uses software (technology dependency) | 9,704 | |
| Acquired by | 3,416 | |
| Vendor of | 244 | |
| Managed by MSP | 51 |
Exposure paths are modeled from ownership and dependency relationships. They do not establish that an incident or compromise propagated between companies.
What regulators are fining
Our GDPR enforcement tracker holds 3,495 enforcement records, of which 3,042 carry a published fine, totaling €7.04 billion:
| Year | Fines issued (EUR) | Total |
|---|---|---|
| 2018 | €458,688 | |
| 2019 | €88,761,764 | |
| 2020 | €171,955,109 | |
| 2021 | €1,268,741,503 | |
| 2022 | €841,904,565 | |
| 2023 | €2,087,091,232 | |
| 2024 | €1,227,578,379 | |
| 2025 | €1,128,444,317 | |
| 2026 | €225,879,175 |
EU and UK data protection fines only, as published by the authorities; wider regulatory enforcement (SEC, FTC, financial regulators, and DPAs across 44 jurisdictions) is tracked separately in the platform.
Methodology
Every figure on this page is computed by a versioned script from a frozen export of the corpus, with per-layer accounting that must sum exactly to the number of records processed; unparseable and unclassified records are counted and disclosed, never dropped. Sources are public and authoritative: SEC filings, the HHS breach portal, state attorney general portals, data protection authorities across 44 jurisdictions, CISA and vendor advisories, verified breach databases, and leak-site monitoring. Cite freely with a link to this page.
Frequently asked questions
How many supply chain attacks happened in 2026?
No complete global count exists; most incidents are never publicly disclosed. What can be measured is disclosure: the Arasy corpus has recorded 33,497 incident records published in 2026 so far, and 1,669 records across all years are categorized as supply-chain incidents. Both figures describe the corpus, not the true global total.
What is a supply chain attack?
An attack that reaches its victims through something they depend on: a software vendor, a service provider, a subsidiary, or an acquired company. One compromise at a supplier can cascade to its downstream customers, which is why the same incident keeps resurfacing across otherwise unrelated organizations.
How reliable are ransomware victim counts?
Leak-site numbers are gang-claimed, not independently verified. Our corpus holds 13,580 victim posts scraped from ransomware leak sites, and they are kept in a separate verification tier from the 48,367 confirmed breaches, which require an authoritative source such as a regulatory filing.
Where does this data come from?
Public, authoritative sources: SEC 8-K filings, the HHS breach portal, US state attorney general portals, data protection authorities across 44 jurisdictions, CISA and vendor advisories, verified breach databases, and ransomware leak-site monitoring. Collection runs continuously and every record keeps its source.
See these incidents on your own supply chain
Overlay your supplier list and see which of your vendors, their parents, or their subsidiaries appear in this corpus. We are running a small number of pilot demos.
Request a pilot demo Estimate your breach cost