What CISA's own ransomware advisories actually name Aggregate data: stopransomware-advisory-census-2026.csv WHAT THIS IS A census of CISA's #StopRansomware advisory series: every cybersecurity advisory CISA publishes whose own title begins '#StopRansomware:', case-insensitively. n = 25 advisories. This is a population, not a sample. One row per advisory. Every figure in this dataset is a count of what a document says. Nothing here is evidence about how ransomware works. An advisory that names no CVE is not evidence that the family exploits no vulnerability - AA23-075A (LockBit 3.0) names none while telling readers to prioritise remediating known exploited vulnerabilities, and AA23-325A lists no Initial Access technique while being specifically about exploitation of Citrix Bleed, which is named in its own title. SNAPSHOT DATE: 2026-09-29 Advisories, the sitemap, the faceted listing, the curated index and the KEV catalogue were all retrieved on 2026-09-29 UTC. Advisories are edited in place, so these counts describe those documents on that date. HEADLINE FIGURES, WITH DENOMINATORS 11 of the 25 advisories name no CVE in the HTML page CISA serves (44.0% of 25). 11 of the 25 name no CVE in either the HTML or the advisory's current companion PDF (44.0% of 25) - the same 11 advisories. The two published bases agree. 10 of the 25 name no CVE in the HTML or in ANY PDF the page links, superseded revisions included (40.0% of 25). This third basis differs on one advisory, AA23-319A (Rhysida): its HTML contains no occurrence of the string 'CVE' and neither does the April 2025 PDF CISA now serves, but the November 2023 file still linked beside it names CVE-2020-1472. Any figure taken from this dataset should name the artefact it was counted from. 64 advisory-CVE mentions across the series, 48 distinct identifiers, 0 to 11 per advisory. 48 of 48 distinct named CVEs are in CISA's KEV catalogue, all of them flagged knownRansomwareCampaignUse 'Known'. KEV catalogVersion 2026.09.27, 1,728 entries, of which 361 (20.9%) carry that flag. CISA maintains both the advisories and the flag, so this is internal consistency between two CISA products, not independent corroboration. 18 of 25 appear in CISA's own curated StopRansomware index; 7 of 25 do not. 19 of 25 publish a version-history block; 6 of 25 publish none at all. 0 of 25 print T1110 Brute Force under the Initial Access tactic. T1110, or one of its sub-techniques, is cited in four advisories and in all four the row is printed under Credential Access. AA24-242A's T1110.003 row nonetheless reads 'RansomHub affiliates may use password spraying to obtain initial access'; the coding follows the tactic each advisory prints. COLUMNS advisory_id: CISA advisory number, upper case, e.g. AA23-075A. One row per advisory. title_as_served: The advisory's own title as CISA served it on 2026-09-29. source_url: The page this row was read from. first_published_date: Date of first publication, from the listing teaser. CISA's page header shows one date only, and relabels it 'Last Revised' after the first revision. page_date_label: 'Release Date' or 'Last Revised', exactly as the page labels it. page_date_iso: The date the page shows under that label. names_any_cve_html: yes/no. Does the HTML page CISA serves name any CVE identifier? cve_count_html: Distinct CVE identifiers named in the HTML page. 0 is a real zero here. cves_named_html: Those identifiers, semicolon-separated. names_any_cve_html_or_companion_pdf: yes/no on the second basis: the HTML page or the advisory's CURRENT companion PDF - the newest advisory-specific PDF the page links, dated by the /YYYY-MM/ segment of its own URL, which is also the file CISA lists first. This column returns the same answer as names_any_cve_html for every advisory in the series. names_any_cve_html_or_any_attached_pdf: yes/no on a third basis: the HTML page or ANY PDF the page links, including superseded revisions CISA leaves attached. Differs from the other two on AA23-319A alone. pdf_attached: yes/no. Two advisories attach no PDF, which is why the HTML is the unit. attached_pdf_count: How many distinct advisory-specific PDFs the page links. 2 for AA23-319A, AA23-352A and AA24-131A; 1 otherwise; empty for the two advisories that attach none. companion_pdf_url: The PDF that companion-PDF figures are counted from. companion_pdf_cve_count: Distinct CVEs in that companion PDF. Empty when there is none. any_attached_pdf_cve_count: Distinct CVEs across every PDF the page links, current and superseded. html_companion_pdf_cve_agree: yes/no/empty. Whether the companion PDF's CVE set matches the HTML's. It is 'yes' for all 23 advisories that attach a PDF. cves_in_kev_count: How many of this advisory's CVEs are in CISA's KEV catalogue. kev_known_ransomware_use_count: How many carry KEV's knownRansomwareCampaignUse='Known'. initial_access_techniques_tables_only: ATT&CK technique IDs printed in a table scoped to the Initial Access tactic (rule A), semicolon-separated. initial_access_count_tables_only: Count of the above. initial_access_techniques_whole_document: ATT&CK technique IDs the document names under Initial Access anywhere, including prose under a sub-heading the advisory tags TA0001 (rule B). initial_access_count_whole_document: Count of the above. attack_table_layout: Which ATT&CK table convention the advisory uses: L0 no table, L1 one table per tactic with the tactic in the caption, L2 combined table with a full-width row-group header, L4 combined table with the tactic in column 1. version_history_published: yes/no. Does the advisory publish a 'Revisions' or 'Version History' block at all? revision_entries: Number of dated entries in that block. EMPTY means the advisory publishes no block - NULL, not zero. The series does not say whether it was never revised or whether the block is simply absent. in_cisa_curated_stopransomware_index: yes/no. Whether CISA's own curated StopRansomware index links this advisory. duplicate_urls: How many URLs CISA serves this advisory at. 2 for AA22-249A, 1 otherwise. The advisory is still one row. non_endorsement_clause_published: yes/no. Whether the advisory carries a non-endorsement clause. The wording varies and is stored per advisory in the study data. retrieved_utc: When this page was fetched. sha256_of_page: SHA-256 of the exact bytes parsed, so any cell can be checked against the same document. METHOD The population was established three ways, not inherited. CISA's sitemap was walked - 15,172 URL entries - and every /news-events/cybersecurity-advisories/ URL in it was fetched: 178 pages, of which 175 match the regular aaNN-NNNx slug and 3 do not, so that no advisory could be excluded by an assumption about URL shape. Membership was then decided on each advisory's own served title, case-insensitively, never on an index label or a URL pattern. That returns 26 of those 178 URLs and 25 advisories: AA22-249A (Vice Society) is served at two URLs, one of them the irregular slug /aa22-249a-0, with the same title, date and CVE set, and is counted once. The prefix test is applied case-insensitively as a precaution; every one of the 26 carries the exact string '#StopRansomware:', so a case-sensitive test gives the same answer. The faceted fulltext listing was paginated as a second frame and produced the same 25 codes. CISA's curated StopRansomware index was collected as a third frame; it is a subset, not an independent count, and supplies the reconciliation instead. All three frames are CISA's own indexes and two of them are subsets of the sitemap, so an advisory missing from CISA's sitemap would be missed by all three: completeness is asserted against CISA's published indexes, not independently of them. Where an advisory links more than one PDF - AA23-319A, AA23-352A and AA24-131A do - the companion PDF is the newest advisory-specific file, dated by the /YYYY-MM/ segment of its own URL, which on all three is also the file CISA lists first. The union of every attached PDF is carried separately. CVEs were extracted from the page's visible text with a hyphen-tolerant pattern, because AA23-325A writes 'CVE 2023-4966' with a space in its own title and AA23-040A writes 'CVE 2021-44228'. Tags are stripped before the pattern is applied: AA23-325A links to Citrix's own security bulletin, and that link's URL and title carry CVE-2023-4967, which appears nowhere in CISA's visible prose. Counting markup would credit CISA with naming an identifier it does not name. Every CVE set was then re-extracted with a second, differently written pattern as a check. Version history was read from the block headed 'Revisions' on 2022 advisories, or 'Version History' from 2023 onwards - printed in mixed case by nine advisories and in block capitals by four. The heading text is wrapped in inside the heading tag, so the match is on the heading's stripped text. An advisory publishing no block is NULL, never zero. ATT&CK Initial Access was coded twice by different methods and reconciled, re-derived a third way, and cross-checked against a separately written implementation which agreed on 24 of 25. Two counting rules are published because the streams chose differently on one advisory: rule A counts technique IDs printed in a table scoped to Initial Access (59 advisory-technique pairs, 3 advisories listing none); rule B counts IDs the document names under Initial Access anywhere (62 pairs, 2 listing none). They differ on AA23-040A only. The CVEs were joined to CISA's KEV catalogue with count-equals-length assertions on both sides. Fetching obeyed robots.txt, which was retrieved first and stored as evidence. It disallows /core/, /profiles/, /admin/, /search/, /media/oembed and four specific /user/ paths, and gives PetalBot Disallow: /; it sets no Crawl-delay and excludes none of the paths used here. Fetching ran one request in flight at 1.2-second spacing with an identifying User-Agent. The stored manifests record 625 snapshot requests across 238 distinct URLs and a 178-page sweep of every advisory URL in the sitemap, every one of them HTTP 200, with no 429 and no 5xx. A further 22 requests were made for licence, policy and prior-art context: 18 returned 200, 3 returned 404 and 1 failed to connect. The failures are reported rather than hidden; none of those pages carries a figure in this study. The analysis stage makes no network request and runs from the stored snapshot. LIMITS n = 25. A census of a named series, so no sampling error - but a small corpus, where one advisory is four percentage points and every cell has to be right. Each row carries its source URL, retrieval timestamp and the sha256 of the exact page parsed. Per-year cuts have denominators of 11 or fewer (2022: 6, 2023: 11, 2024: 4, 2025: 3, 2026: 1) and are reported as counts. No percentage is given on them. AA23-040A is in the series by the title rule but is not a per-family advisory: it describes state-sponsored activity funded by ransomware. 'Ransomware families' describes 24 of the 25; the correct noun for the population is 'advisories'. Advisories cite five different MITRE ATT&CK framework versions (v12, v15, v16, v17, v19), so tactic placement is not strictly comparable between advisories. Two advisories print, in their Initial Access tables, techniques ATT&CK assigns to another tactic (AA23-061A lists T1021.001, AA23-352A lists T1059.001). They are counted as CISA printed them. We found no prior published count of this series. That is a negative search result, not proof that none exists, and no claim of being first is made. PERSONAL DATA None in the dataset. No individual is named in any row, in any finding or in any figure; no staff email address appears; no victim organisation is identified; and no leak-site or dark-web source was used. Every fact comes from CISA's own published documents. Prior work cited alongside the study is credited to the organisation or project that published it, as its licence requires. LICENCE AND ATTRIBUTION Source material: CISA advisories and the KEV catalogue are works of the US federal government and are not subject to US copyright in the United States under 17 U.S.C. 105(a). CISA publishes no explicit public-domain notice; the position rests on the statute and on CISA's TLP:CLEAR default. The KEV catalogue additionally carries an explicit CC0 1.0 Universal dedication, verified at https://www.cisa.gov/sites/default/files/licenses/kev/license.txt. Each advisory carries its own non-endorsement wording, and the wording differs between advisories. Anyone quoting an advisory should carry that advisory's own clause. Neither the DHS seal nor the CISA logo is reproduced anywhere in this study, and nothing in it implies endorsement by CISA, the FBI or any co-sealing agency. This derived dataset: Creative Commons Attribution 4.0 International (CC BY 4.0), https://creativecommons.org/licenses/by/4.0/ Attribution: Servnet, "What CISA's own ransomware advisories actually name", https://www.servnetuk.com/research/stopransomware-advisory-census-2026 PRIOR WORK The closest work in shape is ENISA's Threat Landscape for Ransomware Attacks (July 2022, CC BY 4.0), which could not establish an initial-access route for 594 of the 623 incidents it studied - 95.3% - a public body counting what the record does not say. ENISA counted third-party incident reports about incidents; this study counts one publisher's own document series, document by document, against a closed and re-derivable denominator. The ICS Advisory Project (ODbL v1.0) and the Open ICS Advisory Dataset are direct methodological precedents for treating a CISA advisory series as a countable corpus. The Open ICS Advisory Dataset reads CISA's machine-readable CSAF output, which CISA publishes for the ICS series only, not for the AA-numbered advisories counted here. MITRE ATT&CK The plain-language technique names printed beside the identifiers, and the Initial Access tactic those identifiers are grouped under, come from MITRE ATT&CK. The technique identifiers themselves, and which of them each advisory lists, are read from the advisories. (c) 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. ATT&CK is a registered trade mark of The MITRE Corporation. No endorsement by MITRE is implied. Terms of use: https://attack.mitre.org/resources/legal-and-branding/terms-of-use/ GENERATED BY scripts/research/stopransomware-advisory-census-2026/analyse.py - no network access at analysis time.