Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Press & Media

About Ransomware.live

Ransomware.live is a free, independent, and continuously updated threat intelligence platform tracking ransomware groups and their victims worldwide. It passively monitors ransomware groups' Data Leak Sites (DLS) on the dark web and clearnet, aggregates publicly disclosed victim data, and presents it in a structured, actionable format — no paywall, no ads, no corporate backing.

Beyond victim tracking, the platform maintains a broader threat-intelligence dataset on each group: indicators of compromise (IOCs), MITRE ATT&CK technique mappings, YARA detection rules, leaked ransom notes, and negotiation chat transcripts — all sourced from what threat actors themselves have made publicly visible.

Journalists and researchers regularly use the platform as a primary source for reporting on ransomware trends, individual incidents, and threat actor activity. Ransomware.live does not host or distribute any leaked data, and does not engage in speculation or intrusion — only what is already publicly visible on the internet.

The project has been running independently since 2022, built and maintained outside of working hours by its author, with no venture funding or corporate ownership.

Using Our Data in Your Reporting

Ransomware.live is free to reference in articles, reports, and research. When citing our data, please:

  • Attribute the source as Ransomware.live with a link to ransomware.live
  • Avoid presenting victim listings as confirmed breaches — entries reflect claims made by threat actors on their leak sites, not verified incidents
  • Reach out beforehand if you need context, historical data, or a comment for a story

Press Contact

For interview requests, data questions, or comment on a story, reach out directly: