Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Temple University’s Critical Infrastructure Ransomware Attacks (CIRA) dataset is a research record of ransomware incidents affecting critical infrastructure that were publicly disclosed in media or security reports. Temple’s current project page identifies version 12.16, with 2,291 records covering incidents from November 2013 through December 31, 2025. The dataset is mapped to MITRE ATT&CK; Temple says it is not accepting dataset requests at this time.

What Temple’s CIRA project tracks

CIRA is maintained by Temple University’s CARE Lab, whose work applies a social-science approach to cybersecurity. The project began in September 2019 and collects information about publicly disclosed ransomware incidents involving critical infrastructure. Temple says the dataset has been used by students, educators, industry, and government.

Its public-disclosure basis is important: CIRA describes incidents that appeared in media or security reporting, not every attack that occurred. Undisclosed incidents and incidents that were never reported in those sources may be absent, so the record should not be read as a complete count of ransomware activity.

Temple CARE Lab overview | Official CIRA project page

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Current version, coverage, and access

Item What Temple’s current page says
Dataset version 12.16
Records 2,291
Incident period November 2013 through December 31, 2025
Collection basis Public disclosures in media or security reports
Framework mapping Mapped to MITRE ATT&CK
Requests fulfilled 1,806, as reported on Temple’s current page
New dataset requests Not currently accepted

These are counts and dates for Temple’s version 12.16 dataset page, not a measurement of total ransomware prevalence. The page’s request notice states: “PLEASE NOTE: We are not accepting dataset requests at this time.” It does not establish whether copies distributed earlier remain available for use or whether Temple will offer another version later.

The current project page does not enumerate the full version 12.16 field schema. A September 2020 SecurityWeek report described fields in the dataset at that time, including target organization, attack year and start date, location, sector, duration, ransomware family, ransom amount and payment details, information source, related incidents, and ATT&CK links based on ransomware family. Treat that as a historical description, not confirmation that every field remains unchanged in version 12.16.

SecurityWeek’s September 12, 2020 report recorded 687 incidents through August 2020 and described a free Excel file available through a request process at that time. Those details are historical; Temple’s current page is the reference for today’s version, record count, coverage end date, and access status.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to cite the dataset

Temple asks people who use the dataset in analysis, publication, presentations, or other dissemination to cite it. The requested reference is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Rege, A. (2026). “Critical Infrastructure Ransomware Attacks (CIRA) Dataset”. Version 12.16. Temple University. Online at https://sites.temple.edu/care/cira/. ORCID: 0000-0002-6396-1066.

For a project report or article, identify the version used and distinguish dataset records from estimates of all attacks. That makes the analysis reproducible in context and avoids treating disclosed incidents as a census.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.