Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a ransomware leak site?

A ransomware leak site publishes victim claims, samples or stolen material to support extortion. A listing proves what the site displayed, not that its operators attacked the victim or possess the entire claimed dataset.

Preserve a changing publication

Record the URL or hidden-service address, page and victim-entry IDs, timestamps, screenshots, changes, download links and infrastructure where available. If lawfully necessary to obtain a sample, retain the original archive, page context, access time and hashes.

Do not assume folder names, file counts or descriptions are accurate. Content may be partial, duplicated, copied from news or another breach, or displayed mainly to increase pressure.

Connect publication to the incident

Compare genuine samples with source data and align publication changes with negotiation and payment. Distinguish advertising, partial display and material made available for download.

Access only within lawful authority and operational need. Group branding remains an attribution lead; establish incident linkage and operator identity through separate technical and provider evidence.

Key takeaway

Preserve the leak entry and lawful samples as time-sensitive publication evidence, then verify possession, incident linkage and group attribution independently.

Reference: CIM-192Cyber Incidents & Offender Methods