Search claims across the full archive and monitor the latest ransomware activity.
Victim entries represent claims reported by ransomware groups and may not be independently verified.
Many modern ransomware groups publicly name organizations they claim to have compromised on dedicated leak sites. These claims are often used as part of double extortion schemes, where attackers threaten to publish stolen data if a ransom is not paid.
Monitoring ransomware claims helps security professionals, journalists, researchers, and affected organizations identify newly disclosed incidents, follow threat actor activity, and better understand the evolving ransomware landscape. While not every claim can be independently verified, they often provide an early indication of emerging cyber incidents.
Tracking ransomware claims can reveal valuable intelligence about active threat groups, industries being targeted, and emerging attack trends. Security teams use this information to improve threat awareness, investigate potential incidents, and understand how ransomware campaigns evolve over time.
A searchable archive also makes it easier to research previous victim claims, identify recurring threat actors, and compare historical activity across countries, industries, and organizations without manually visiting multiple ransomware leak sites.
Many ransomware groups operate public leak sites where they publish the names of organizations they claim to have compromised. These sites are commonly used to pressure victims into paying a ransom by threatening to release stolen data.
It's important to remember that a listing on a ransomware leak site does not automatically confirm a successful breach. Claims should always be evaluated alongside official statements, security research, and other publicly available evidence. Monitoring these disclosures provides valuable context, but independent verification remains essential.