Press "Enter" to skip to content

Critical Infrastructure Ransomware Attacks (CIRA)

In September 2019, we started a dataset of Critical Infrastructures Ransomware Attacks (CIRAs). These are based on publicly disclosed incidents in the media or security reports. This dataset (version 12.16) now has 2,291 records assembled from publicly disclosed incidents between November 2013 and December 31, 2025, and has been mapped to the MITRE ATT&CK Framework. To date, we have fulfilled 1,806 requests. Some publicly known uses of the dataset can be found in research papers and reports.

If you use the dataset, in whole or in part, for any analysis, publication, presentation, or any other dissemination (including social media), you agree to cite this dataset in your reference list as:
Rege, A. (2026). “Critical Infrastructure Ransomware Attacks (CIRA) Dataset”. Version 12.16. Temple University. Online at https://sites.temple.edu/care/cira/. ORCID: 0000-0002-6396-1066.

PLEASE NOTE: We are not accepting dataset requests at this time.

Our dataset has been featured in Security Week (2025), Security Week (2022), Security Week (2020), Gartner, BRINK, Security Magazine, SentinelOne, Bleeping Computer, Dark Reading, Cyber Peace Institute, the Washington Post, Bloomberg, USA Today, Institute for New Economic Thinking, The Dallas Morning News, Business Insider, California News Times, Financial Times, CIO Dive, and eSecurity Planet!

To learn how we developed the CIRA dataset in greater detail, you can read our paper: Rege, A. & Bleiman, R.(2022) . “A Free and Community-driven Critical Infrastructure Ransomware Dataset”. Proceedings from the IEEE Cyber Science Conference.

Other ransomware datasets

Ransomware.live
Comparitech’s Map of worldwide ransomware attacks (updated daily)

Check out these fantastic resources for ICS security.

 

var sc_project=12360776;
var sc_invisible=1;
var sc_security=”ddf74f40″;

Web Analytics