

Every major ransomware group operating in 2026 maintains a dark web site where they publish the names of organisations they have compromised, typically as a negotiation lever: pay the ransom and the data does not get published; refuse and the data appears progressively. These sites, commonly called leak sites or data leak portals, are primarily designed to coerce victims. They are also, from a defensive intelligence perspective, one of the richest sources of structured information about how ransomware groups operate, what industries they target, how long they maintain access before deploying ransomware, what data they extract, and how they structure their negotiation and extortion processes.
Security researchers and threat intelligence teams who monitor ransomware leak sites systematically have produced insights that are simply not accessible through any other source. The timing information in leak site publications, specifically the gap between when a victim is first listed and when data is published, reveals how much time organisations typically have to respond after a ransomware group announces targeting. The victim lists reveal which industries and geographies each group focuses on, enabling organisations in targeted sectors to heighten their defensive posture when a group is actively campaigning in their space. The data samples published as proof of access reveal the specific data categories that groups extract, giving defenders guidance on what to monitor for exfiltration and what data to protect most aggressively.
Ransomware leak sites follow a broadly consistent structure across different groups, though with variations that reflect each group's operational style and maturity. Most sites divide victims into categories based on negotiation status: organisations currently in negotiation (often listed with a countdown timer showing how long they have before data is published), organisations where the ransom deadline has passed and data is being released progressively, and an archive of past victims whose data was published in previous campaigns.
The active victim section is the highest-value intelligence source for defenders because it reveals active attack campaigns in near-real time. When an organisation appears on a leak site for the first time, the ransomware group is announcing that they have completed their initial compromise, data exfiltration, and deployment of ransomware. This announcement typically happens before the victim has made a public disclosure, which is itself typically delayed by days or weeks while internal response activities are underway. Organisations in the same industry or geography as a newly listed victim can use this signal to heighten their own monitoring and review recent authentication and network activity for indicators of the same compromise technique.
The proof-of-access samples published on leak sites, which typically include screenshots of file directories, samples of specific document types like HR records or financial spreadsheets, and sometimes complete archives of specific data categories, reveal the depth of access the group achieved and the data it extracted. These samples are published to demonstrate to the victim that the threat of data release is credible, but they also reveal to threat intelligence analysts what categories of data the group extracted from each victim, which is consistent enough across victims to reveal the group's collection priorities and the specific data directories they target.
One of the most operationally useful categories of intelligence from ransomware leak sites is temporal: the timing relationships between different stages of an attack. Researchers who track when victims first appear on leak sites and correlate this with when those organisations subsequently disclose the incident can estimate the average dwell time (the period between initial compromise and ransomware deployment) for each group. This estimate has direct operational value: it tells defenders how long they have to detect and respond to an intrusion by that group before ransomware is deployed.
The countdown timers on active victim listings provide another temporal data point: the group's stated negotiation deadline. These deadlines are not always respected, and some groups extend them in response to active negotiation, but they give an indication of the group's patience and the pace at which their campaigns move. A group that consistently enforces 72-hour deadlines operates very differently from a group that maintains victims in negotiation for weeks, and defenders respond accordingly: the short-deadline group requires rapid incident response capability, while the longer-deadline group allows more time for methodical investigation and decision-making.
The cumulative victim list of a ransomware group is a structured dataset of their targeting decisions. Analysis of this dataset, particularly when combined with open-source information about each victim (industry, revenue, employee count, geography, technology stack where identifiable), reveals the group's targeting criteria. Some groups concentrate almost entirely on specific industries: healthcare, legal services, or manufacturing. Others target by revenue band, going after mid-market organisations that have sensitive data but may lack the security maturity of enterprise targets. Others show geographic concentration, targeting specific countries or regions where their native language and cultural knowledge gives them an operational advantage.
This targeting pattern analysis allows organisations to assess their relative risk from each active ransomware group. An organisation in healthcare in a region that LockBit's historical victim list shows heavy concentration in is at materially higher risk from LockBit campaigns than an organisation in manufacturing in a different geography. This risk differentiation is not available from general ransomware threat reporting, which tends to describe groups' capabilities without the victim pattern specificity that leak site analysis provides.
There is an ethical dimension to ransomware leak site monitoring that security practitioners need to navigate carefully. Leak sites publish data that the ransomware group stole from organisations without consent. Accessing, downloading, or distributing that stolen data, even for research or intelligence purposes, raises legal and ethical concerns that vary by jurisdiction. Most security researchers who monitor leak sites for intelligence purposes limit their observation to the public-facing information available on the sites, specifically the victim listings, timing information, and non-sensitive screenshots, without downloading the actual data packages that groups publish for victim coercion.
Within these constraints, substantial intelligence value is available: the victim lists, the timing patterns, the industry concentrations, and the proof-of-concept screenshots that reveal attack depth are all observable without accessing stolen data files. Security vendors and threat intelligence platforms that systematically monitor leak sites have developed automated collection and analysis pipelines that extract this intelligence at scale across dozens of active leak sites, providing organisations with structured and searchable intelligence about ransomware group activity without exposing those organisations to legal risk from directly accessing stolen data. Dark web monitoring that covers ransomware group activity is the operational implementation of this intelligence capability for organisations that cannot maintain their own monitoring of these sources.
The intelligence value of ransomware leak site monitoring is highest when it is integrated into existing security operations processes rather than consumed as a separate research activity. Several integration points make this intelligence immediately actionable. New victim listings in the same sector or geography as the monitored organisation should trigger a review of threat hunting queries, looking for indicators associated with the active group in internal logs and network traffic. The techniques and infrastructure patterns of active groups shift over time, and a group that is actively listing victims in your sector is likely to be targeting similar organisations using similar techniques.
An organisation that is listed on a ransomware leak site has an immediate need for a specific type of intelligence: what is the group likely to publish, how much time remains before publication, and has any data already been accessed by third parties who downloaded it from the site. These questions require monitoring the specific listing closely from the moment of detection, tracking the data release progression, and alerting the legal and communications teams who need to factor this intelligence into their response and disclosure decisions.
The historical archive of a leak site is also valuable for incident response context: if an organisation is compromised by a specific group, reviewing the historical victim listings of that group reveals what data categories the group has published from previous victims, which gives the incident response team a target list for their data exfiltration investigation. If the group consistently publishes HR records and financial spreadsheets from victims in the same sector, the response team knows to prioritise those data categories in their exfiltration impact assessment.
One of the most actionable applications of ransomware leak site intelligence is sector-level threat awareness. When a ransomware group lists multiple victims in the same industry within a short timeframe, this clustering suggests that the group is either deliberately targeting that sector in a campaign, has acquired a set of credentials or an exploit that is particularly effective against a technology stack common to that sector, or has developed industry-specific knowledge that makes targeting organisations in that vertical easier. Each of these scenarios has different defensive implications, but all of them suggest that peer organisations in the same sector should be on elevated alert.
Security teams in sector-specific information sharing communities like ISACs (Information Sharing and Analysis Centres) use leak site monitoring as one input into their shared situational awareness. When one ISAC member has been compromised, the appearance of that organisation on a ransomware leak site signals to other members in the same sector that the group targeting them is actively campaigning in their space. The ISAC context is important because it provides additional intelligence about the compromised organisation's technology environment and entry point, enabling peer organisations to check for the same vulnerabilities in their own environments.
Supply chain considerations add another dimension to leak site intelligence. A ransomware victim that is a managed service provider, a software vendor, or a key supplier to your organisation may not directly affect your infrastructure if their ransomware deployment is contained to their own environment. But the data exfiltrated from them before ransomware deployment may include your credentials, your data, or information about your organisation's network architecture if your organisation is a customer of theirs. Monitoring leak site publications for the names of your key suppliers and partners, not just your own organisation's name, is a supply chain risk management application of threat intelligence that leak site monitoring uniquely enables. Automated monitoring that covers both your organisation's name and your key third-party relationships provides this extended visibility.
The volume varies significantly by period and by which groups are actively campaigning. Research teams that monitor leak sites continuously have tracked periods of 200-400 new victim listings per month across all major ransomware groups during peak campaign periods. Individual groups like LockBit and ALPHV/BlackCat at their peaks were listing dozens of victims per week. Following law enforcement actions against major groups, the numbers typically dip before new groups emerge or surviving affiliates reconstitute under new names. The data is published by multiple threat intelligence teams including those at Recorded Future, Mandiant, and numerous OSINT researchers who make their tracking data publicly available.
In theory, paying the ransom demand is supposed to result in the removal of the victim's listing and the destruction of the exfiltrated data. In practice, there is no way to verify that the ransomware group has deleted their copy of the data, and some groups have been documented re-extorting previous victims by claiming to have retained copies despite prior payment. The data may also have been sold to third parties before or after the extortion event, making full removal practically impossible once data has been exfiltrated by a well-organised ransomware group.
Directly accessing ransomware leak sites on the Tor network introduces operational security and legal considerations that security teams should evaluate with their legal counsel. For most organisations, the practical answer is to use a managed threat intelligence service that monitors these sites on their behalf and alerts on relevant listings rather than having internal analysts access dark web sites directly. This approach provides the intelligence value without exposing analysts to the legal and reputational risks of direct dark web interaction, and typically provides faster and more structured alerting than manual monitoring could achieve.
Systematic analysis of ransomware leak site data over time enables the construction of detailed operational profiles for each active ransomware group. These profiles, maintained by threat intelligence teams and published by research organisations, aggregate information across all documented victims and all documented campaigns to characterise each group's targeting preferences, operational tempo, negotiation behaviour, and technical characteristics. For defenders, these profiles provide the context that transforms a general ransomware threat into a specific understanding of which groups are most relevant to their organisation and what those groups look like in terms of initial access methods and post-compromise behaviour.
Group profiles derived from leak site analysis typically include industry targeting patterns: which sectors make up the largest proportion of each group's victim list, and whether that targeting appears deliberate (reflecting sector-specific knowledge or tooling) or opportunistic (reflecting exploitation of a broadly applicable vulnerability that happens to affect organisations across sectors). Healthcare and education organisations appear in the victim lists of virtually every ransomware group because their security maturity is typically lower than financial services or technology organisations; this broad targeting reflects opportunity rather than specific sector expertise. Financial services organisations, on the other hand, appear more selectively in victim lists that tend to belong to groups with specific financial sector targeting capabilities.
Negotiation behaviour analysis, derived from published negotiations (which some groups publish when victims refuse to pay) and from incident reports of organisations that have disclosed their ransomware experiences, reveals each group's typical ransom demand relative to victim size, their willingness to negotiate reductions, and their follow-through on publishing data when ransoms are not paid. This intelligence directly informs the business decision about ransomware response, though the decision ultimately depends on factors specific to each organisation including their insurance coverage, their data sensitivity, and their obligation to customers whose data may be affected.
Organisations considering how to monitor ransomware leak sites face several practical decisions that go beyond whether to monitor. The first is coverage: which leak sites to monitor. The number of active ransomware groups maintaining leak sites has fluctuated between 40 and over 100 at different points between 2022 and 2026, and each group's site may be on a different .onion address that changes when the group faces law enforcement action or infrastructure disruption. Maintaining current, accurate coverage of all active leak sites requires dedicated effort and access to sources that track site locations across the regular changes.
The second practical decision is alerting scope. An organisation can monitor solely for its own name and domain in leak site listings, or it can monitor for a broader set of terms including subsidiary names, brand variations, and the names of key suppliers and partners. Broader scope produces more alerts but also more relevant intelligence for organisations with complex corporate structures or significant supply chain dependencies. Defining the alerting scope to match the organisation's actual risk priorities is the intelligence requirements planning exercise applied to this specific monitoring use case.
The third consideration is response protocols. When a leak site alert fires, what happens? Who receives the alert, in what timeframe, and through what channel? What is the escalation path if the alert is confirmed as a genuine listing of your organisation or a close partner? Having these protocols defined and tested before an alert fires is the difference between an organised response and a chaotic one. Table-top exercises that simulate the receipt of a leak site alert and work through the decision tree are a practical way to test the protocol before it is needed. The intelligence has value only if the response process is ready to convert it into action within the time window available.
The volume of data published on ransomware leak sites is also a source of intelligence about the data categories that each ransomware group prioritises for exfiltration. Groups that consistently publish financial documents, customer databases, and intellectual property from their victims are signalling what types of data they extract in order to maximise their extortion pressure. This signalling informs defenders about what data to prioritise for the most aggressive protection, monitoring for exfiltration, and incident response containment. A ransomware group that has never published healthcare data from its victims, but whose victim profile suggests they are targeting healthcare organisations, may be extracting different data than one whose published samples consistently include patient records.
The dark web intelligence described in this article, ransomware leak site monitoring, initial access broker tracking, and criminal forum surveillance, is valuable precisely because it is external to your perimeter and operates on a timeline that precedes most attacks. An organisation listed on a ransomware leak site has already been compromised; the value of monitoring is detecting that listing before the public announcement and before the data is downloaded by third parties. An organisation whose credentials appear in an IAB listing has a window to revoke those accesses before the buyer deploys ransomware.
Defendis monitors ransomware leak sites, initial access broker forums, and criminal marketplaces continuously, with alerts targeted to your organisation's identifiers, domains, IP ranges, employee data, and brand name. Intelligence surfaces in time to act, not after the fact.
Book a demo to see how Defendis monitors ransomware groups and IAB activity for your sector.