What is a ransomware leak site?¶
The practical answer¶
A ransomware leak site is an online location used to publish claims, victim names, sample data or stolen information as part of extortion.
The key evidential caution¶
The dangerous assumption is that a victim listing proves the named group attacked the organisation or holds all the data claimed.
It does not.
A leak site may contain:
Key points¶
- victim names
- countdown timers
- sample files
- download links
- negotiation claims
- contact details
- group branding
- statements about payment
Evidence to preserve¶
Investigators should preserve:
Key points¶
- the page content
- URL or hidden-service address
- timestamps
- screenshots
- downloadable files
- file hashes
- victim entry identifiers
- publication changes
- hosting or infrastructure records where available
A sample may prove possession of that item.
A listing may also be copied from news, another group or an earlier breach.
Evidential limits¶
Do not access or download material beyond lawful authority and operational need.
The site may change rapidly or disappear, so preservation timing matters.
Group branding remains an attribution lead rather than conclusive proof.
If sample material is downloaded lawfully, preserve the original archive, page context, hashes and access time. Do not assume the site’s folder names or claimed file counts are accurate. Publication may be partial, duplicated or designed primarily to increase pressure.
Publication timing should be compared with negotiations and payment. A listing may appear before contact, during pressure or after talks fail. Changes to the page can help reconstruct the extortion sequence without proving who personally made each update.
Operational takeaway¶
Preserve the leak-site entry and any samples, then verify data possession, incident linkage and group attribution independently.