Data & Downloads

The Atlas dataset is open. Export it, inspect the field definitions, and reproduce every derived score yourself.

36 documented casesData cutoff 2024-12License CC BY 4.0

CSV is a flat, one-row-per-case export (good for spreadsheets). JSON preserves the full nested record structure. Both are generated from the same source data that powers the site.

Codebook

Field definitions for the CSV export. Derived scores (unpeace, entanglement) are documented in methodology §06 and can be recomputed from the other columns.

FieldDescription
idStable unique identifier for the incident record.
slugURL slug (matches /cases/<slug>).
nameFull incident name.
shortNameShort display name.
yearPrimary year of the operation.
dateRangeHuman-readable date range.
incidentTypeespionage | destructive | ransomware | influence | sabotage | hybrid.
attributedToNamed responsible actor (as publicly attributed).
attributionCountryAttributed state nexus.
attributionConfidenceconfirmed | high | moderate | low | contested.
peakTierPeak escalation tier: probing…strategic.
unpeaceScoreComposite severity, 0–100 (see methodology §06).
entanglementScoreCross-dimension spread, 1–10 (see methodology §06).
targetSectorsAffected sectors (semicolon-separated).
targetCountriesAffected countries/regions (semicolon-separated).
thresholdCrossingsEscalation thresholds crossed (semicolon-separated).
governanceFlagsGovernance mechanisms triggered (semicolon-separated).
attackTechniquesMITRE ATT&CK technique IDs (semicolon-separated).
lastUpdatedDate the record was last reviewed (if set).

Changelog

  1. 2024-12

    Landmark cases (NotPetya, SolarWinds, Stuxnet, WannaCry, Viasat KA-SAT) reviewed; verified primary-source URLs and additional academic/journalistic references added; per-record review dates set.

  2. 2024

    Dataset expanded with 2024 operations and additional globally-sourced and attribution-focused cases.

  3. 2023

    Initial corpus assembled: 20 seed cases across escalation, infrastructure, and governance lenses.

Candidate cases under consideration are tracked in docs/dataset-todo.md and are not added until fully sourced.