Cross-Sector Cyber Threat Intelligence

A structured record of the cyberattacks targeting America's critical infrastructure.

The Observatory documents 3,519 verified cyber incidents across 16 CISA critical infrastructure sectors: 3,303 enriched with severity scoring and actor extraction, plus 216 regulator-documented breaches. Built for the institutions that defend and study the systems Americans depend on.

CISA 16 Critical Infrastructure SectorsLive
Information Technology
718
Government Facilities
649
Financial Services
367
Communications
361
Emergency Services
336
Critical Manufacturing
314
Healthcare and Public Health
296
Energy
291
Transportation Systems
247
Commercial Facilities
232
Defense Industrial Base
211
Food and Agriculture
131
Water and Wastewater Systems
130
Nuclear Reactors, Materials, and Waste
106
Chemical
106
Dams
36
16 of 16 sectors · 3,519 total incidents
Independent research with a cited track record

Research built on this record — including From Vietnam to Volt Typhoon— has been cited by the CTO of the UK National Cyber Security Centre and syndicated by RealClearDefense, the ISEAS–Yusof Ishak Institute, the Australian Centre for International Studies, and Indian Strategic Studies.

3,519
Incidents verified
16
CI sectors covered
Versioned
Dated, citable releases
What's Inside

Dossiers on the campaigns that matter

Each adversary is tracked as a structured record: attribution, targeted sectors, observed tradecraft, timeline, and sourcing. Two of the most consequential campaigns against U.S. infrastructure:

Active Campaign

Volt Typhoon

Pre-positioning inside critical infrastructure for potential disruptive operations.

Attribution
PRC nexus
Primary sectors
Energy, Water
Spillover
Transportation, Comms
Status
Ongoing tracking
Open dossier →
Active Campaign

Salt Typhoon

Intrusions into U.S. telecommunications networks and lawful-intercept systems.

Attribution
PRC nexus
Primary impact
Government, IT (spillover from telecom intrusions)
Status
Ongoing tracking
Open dossier →
Who The Observatory Serves

Cross-sector intelligence a single feed can't give you

Most threat data lives inside one sector or one vendor. The Observatory's value is the connective tissue: the same adversary, mapped across every sector it touches.

01

ISACs & Sector Bodies

Cross-sector context your members cannot get from a single-sector feed, mapped to the framework they already use.

02

Universities & Research

A citable, versioned dataset for scholarship on nation-state cyber operations and infrastructure risk.

03

Government & Policy

Attribution and trend analysis organized against the sixteen-sector critical infrastructure model.

04

Enterprise Security

Adversary tracking correlated directly to the infrastructure and dependencies your organization relies on.

Methodology

Built to be trusted, and to be cited

Sourced
Every incident traces back to public reporting, government advisories, and primary disclosures, with the source retained alongside the record.
Structured
A consistent schema across all 3,305 incidents: actor, sector, tradecraft, date, and confidence, so the data is queryable rather than narrative.
Cross-mapped
Each incident is tagged to one or more of the 15 covered CISA sectors, making the connective view between sectors the core unit of analysis.
Versioned
Releases are dated and citable, so a finding made today can be referenced and reproduced by a researcher tomorrow.
Independent
Compiled and maintained as independent research, free of any single vendor's telemetry or commercial slant.
About the Author

Built by Christopher Braccia

Author & Maintainer
Christopher Braccia
Cyber Threat Intelligence & National Security Researcher

Christopher Braccia began building The Observatory in the early 2020s, hand-compiling fragmented public reporting on nation-state intrusions into a single, structured intelligence record. What began as a personal research archive grew into a comprehensive platform mapping adversary activity against the systems Americans depend on every day.

His work focuses on high-value cyber and national security analysis, correlating campaigns like Salt Typhoon and Volt Typhoon with the broader strategic picture of critical infrastructure risk, attribution, and resilience.

The research compiled within The Observatory served as the basis for his paper From Vietnam to Volt Typhoon, which traces the evolution of national security threats into the modern era of nation-state cyber operations, and which has been cited by the CTO of the UK National Cyber Security Centre and syndicated internationally.

Institutional Licensing

License The Observatory for your institution

Access the full incident record, the dossier library, and the structured dataset under an institutional license for ISACs, universities, research institutes, and government. Tell us about your use case and we'll follow up with access terms.