threatcluster/threat-incident-clusters
Threat incident clusters Security incidents as deduplicated stories rather than individual articles. Each row is one incident that at least two outlets reported, with a generated title and prose summary, the entities involved, the reporting outlets, scores and the reporting window. Built from the ThreatCluster corpus. 19,205 rows, snapshot generated 2026-09-06. Fields Field Description cluster_id Short identifier; the page is… See the full description on the dataset page: https://huggingface.co/datasets/threatcluster/threat-incident-clusters.
Threat incident clusters
Security incidents as deduplicated stories rather than individual articles. Each row is one incident that at least two outlets reported, with a generated title and prose summary, the entities involved, the reporting outlets, scores and the reporting window.
Built from the ThreatCluster corpus. 19,205 rows, snapshot generated 2026-09-06.
Fields
Important caveats
Titles and summaries are MODEL-GENERATED from the underlying articles and are not human-verified; they may contain errors. Source article text is not included (third-party copyright) — only ThreatCluster's own summaries and metadata. Scores are ThreatCluster's editorial ranking, not a standard severity scale.
Clusters scoring below 10 are excluded: at that level the corpus is conference announcements, vendor awards and hiring posts rather than incidents. This is a noise filter, not an importance filter — plenty of significant incidents score in the 20s, so do not read threat_score as severity.
Also available at
- GitHub — raw JSONL for all three datasets
- Kaggle — the three published together
- threatcluster.io/datasets — what each one covers, and its limits
Provenance and refresh
ThreatCluster continuously ingests security reporting and collects ransomware leak sites first-hand. This dataset is a periodic snapshot; the live data is available through the API, which has a free tier, and through the public feeds at https://threatcluster.io/feeds.
Licence and citation
Released under CC-BY-4.0. Attribution is required:
@misc{threatcluster_threat_incident_clusters},
title = {Threat incident clusters},
author = {ThreatCluster},
year = {2026},
url = {https://huggingface.co/datasets/threatcluster/threat-incident-clusters}
}Ethical use
This data is published to support defensive security research, measurement and education. It names organisations that criminal groups have claimed as victims; they are the injured parties. Do not use it to target, harass or profile them.
