Finally, if you want the raw incident data to analyse, Sophos has it, anonymized: https://github.com/sophoslabs/Active_Adversary_Report/blob/main/sophos-aar2501-github-share.csv