Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
Ransomware.live is a free, independent, and continuously updated threat intelligence platform tracking ransomware groups and their victims worldwide. It passively monitors ransomware groups' Data Leak Sites (DLS) on the dark web and clearnet, aggregates publicly disclosed victim data, and presents it in a structured, actionable format — no paywall, no ads, no corporate backing.
Beyond victim tracking, the platform maintains a broader threat-intelligence dataset on each group: indicators of compromise (IOCs), MITRE ATT&CK technique mappings, YARA detection rules, leaked ransom notes, and negotiation chat transcripts — all sourced from what threat actors themselves have made publicly visible.
Journalists and researchers regularly use the platform as a primary source for reporting on ransomware trends, individual incidents, and threat actor activity. Ransomware.live does not host or distribute any leaked data, and does not engage in speculation or intrusion — only what is already publicly visible on the internet.
The project has been running independently since 2022, built and maintained outside of working hours by its author, with no venture funding or corporate ownership.
Ransomware.live is free to reference in articles, reports, and research. When citing our data, please:
For interview requests, data questions, or comment on a story, reach out directly: