Share on social
August 27, 2026
Lorem ipsum
Ransomware leak sites are public-facing platforms operated by ransomware groups to name and shame organizations that have been attacked.
For cybersecurity teams, however, these sites represent more than an extortion mechanism. Ransomware leak sites provide a valuable source of dark web intelligence, revealing information about active ransomware groups, their victims, targeting patterns, operational tempo and, in some cases, the data stolen during an attack.
The ransomware leak site landscape changes constantly. Groups shut down, rebrand, launch new infrastructure and emerge under different names, meaning the most active sites can change over time.
What are ransomware leak sites?
A ransomware leak site is a website used by a ransomware group to publicly identify organizations it claims to have compromised and, in many cases, publish samples or complete datasets stolen during an attack.
Unlike conventional websites, these sites are typically (though not always) hosted on the dark web using Tor and are designed to be difficult to take down or attribute. They form an important part of the modern ransomware ecosystem, alongside ransomware-as-a-service operations, initial access brokers, underground forums and other criminal infrastructure.
The primary purpose of a leak site is pressure. By publicly naming a victim and threatening to release sensitive information, ransomware groups create additional financial, reputational and regulatory pressure on organizations that refuse to pay.
For defenders, however, the information published on these sites creates an opportunity to understand ransomware activity from the attacker's perspective.
How do ransomware leak sites work?
Ransomware groups typically publish information about victims on their leak site after gaining access to an organization's environment and exfiltrating data.
A typical sequence looks like this:
- Initial access: Attackers gain access through methods such as compromised credentials, exploited vulnerabilities, exposed remote services or access purchased from an initial access broker.
- Intrusion and data theft: The attackers establish control of the environment, move through systems and identify valuable information to steal.
- Extortion: The victim is presented with a ransom demand, often alongside a deadline for payment.
- Victim listing: If the ransom is not paid, or sometimes while negotiations are still taking place, the organization may be added to the group's leak site.
- Data publication: Attackers may publish samples of stolen information before releasing larger datasets or threatening further disclosure.
Not every ransomware group follows exactly the same process, and leak-site activity can vary significantly between groups. Some publish detailed victim profiles and large samples of stolen data, while others provide relatively little information.
This variation is itself useful intelligence. Changes in how a group operates can reveal shifts in its tactics, targeting or overall activity.
What information can ransomware leak sites reveal?
Although ransomware groups publish information primarily to pressure their victims, the same information can provide security teams with valuable insight into the threat landscape.
Ransomware group activity
Tracking new victim listings can help reveal how active a ransomware group is and whether its operational tempo is increasing or declining. Sudden increases in activity may indicate a new campaign, a change in targeting or a successful period for the group.
Victimology and targeting
The organizations appearing on a leak site can reveal patterns in the sectors, countries and types of organizations being targeted. Comparing these patterns across groups can help security teams understand which threats are most relevant to their own organization.
Ransomware tactics and techniques
Leak sites can provide clues about how ransomware groups operate, including the technologies and vulnerabilities associated with successful attacks. When combined with other threat intelligence, this information can help defenders understand the techniques being used by specific groups.
Stolen data and breach impact
Published samples can provide an indication of what information was stolen during an attack. For victims and their partners, this can help establish whether sensitive information, intellectual property, personal data or confidential business records may have been exposed. Find out more here: Get to know the Ransomware File Explorer
Supply chain exposure
A ransomware victim's stolen files can contain information belonging to customers, suppliers, partners or other third parties. Monitoring leak sites can therefore uncover potential exposure that would otherwise remain invisible to organizations that were not the direct target.
Changes in ransomware groups
Leak sites can also provide insight into the evolution of ransomware operations. Changes in infrastructure, branding, language, victim-selection patterns and publication practices can help analysts track emerging groups, rebrands and changes in criminal operations.
Why monitor ransomware leak sites?
Monitoring ransomware leak sites allows organizations to move beyond treating ransomware solely as an incident-response problem.
By continuously tracking ransomware activity, security teams can identify emerging threats, understand which groups are active and determine whether their own organization, suppliers or business partners have appeared in ransomware activity.
This is particularly important because ransomware does not begin when files are encrypted. Attackers typically spend significant time identifying opportunities, gaining access, establishing persistence and exfiltrating data before the final extortion stage.
Leak-site intelligence provides visibility into what happens at the end of that process, but it can also be combined with wider dark web and threat intelligence to understand the activity leading up to an attack.
For example, if intelligence shows that a ransomware group is actively exploiting a particular vulnerability or targeting a particular technology, organizations can compare that information against their own external exposure and prioritize remediation accordingly.
This creates a more proactive approach to ransomware defense: rather than waiting to discover that an organization has been attacked, security teams can use intelligence about active ransomware operations to identify and reduce relevant exposure beforehand.
Top ransomware leak sites
The ransomware leak site landscape is constantly evolving. The following list covers some of the most significant and notable ransomware leak sites, both current and past, including sites associated with major ransomware operations and groups that have played an important role in the development of modern ransomware extortion.
8Base [OFFLINE]
Active Since: April 2022
Top Targeted Geographies: US, Brazil, UK
The 8Base dark web leak site appeared in June 2023 but the group is reported to have been active since early 2022.
Its activity accelerated in the summer of 2023 and was consistent in posting victims, quickly becoming one of the most active groups we tracked
Its top three targeted industries were commercial & professional services, capital goods, and healthcare equipment & services. 8Base used double extortion tactics – as well as encrypting an organization’s data it also exfiltrated data and threatened to leak it on its dark web leak site.
8Base used a variant of Phobos ransomware in its attacks, modified to append a “.8base” extension onto encrypted files. Researchers also noted that 8Base’s leak site bore many textual similarities to the leak site used by data extortion operation RansomHouse, which might suggest a connection between the two groups.
In September 2023, the cybersecurity researcher Brian Krebs demonstrated that at least some of the 8Base leak site code was written by a 36-year-old programmer residing in the capital city of Moldova.
February 2025 Update: 8Base was seized in February 2025, in an international law enforcement operation that led to the arrests of four Russian nationals suspected of leading the group and deploying Phobos ransomware on company networks.
AKIRA
Active Since: March 2023
Top Targeted Geographies: US, UK, Canada
Akira is a prolific ransomware group operating under the RaaS business model. The group was first identified in March 2023 and claimed at least 1200 victims (as of the end of 2025) via their extortion site.
The ransomware variant employed by the group has evolved over time, with first strains being developed using the C++ programming language and giving files the .akira extension when encryption was completed. The group has started using the Megazord ransomware variant as well, which uses the .powerranges extension.
Like many other ransomware groups, Akira’s affiliates obtain initial access from a multitude of sources, such as stealer logs or Initial Access Brokers. Access is also obtained by exploiting technical vulnerabilities found in common commercial solutions such as Cisco or SonicWall VPN software and remote desktop protocol (RDP) apps. Social engineering such as phishing and spearphishing are also part of their tactics.
Once an initial foothold is established, the group often employs an attack technique known as Kerberoasting to dump the Local Security Authority Subsystem Service (LSASS) and obtain additional credentials. Mimikatz and LaZagne have also been used to obtain additional credentials. Exfiltration is done by leveraging legitimate tools including FileZilla, Rclone, WinSCP and WinRAR.
Although Akira is likely a self-established group with no major links to other ransomware groups, past or present, there are some indications that certain elements of the malware itself were inspired by Conti. Moreover, some cryptocurrency payments can be traced to former members of the Conti affiliate program.
The ransomware strain is sophisticated and uses a hybrid encryption method, however, a decryptor was created and shared in the community on two different occasions, one in 2023 and one in early 2025. The latter was particularly interesting as it uses GPUs to bruteforce to decrypt keys. However, it only worked on Linux-based systems and required a significant upfront investment to purchase numerous GPUs. It was also a lengthy process to obtain a decryption key, it took 16 high end GPUs 10 hours to decrypt one single key.
BlackBasta [OFFLINE]
Active Since: April 2022
Known Forum Aliases: BlackBasta
Active Forum Accounts: Exploit
Top Targeted Geographies: US, Germany, UK
BlackBasta was a ransomware operation notable for its high volume of attacks, use of custom tools, and suspected links to cybercriminal group FIN7.
The group was thought to be calculated and selective in its targeting of large organizations, likely contributing to its accrual of over $100 million in ransom payments since its inception in 2022.
There is some evidence that the operators and affiliates of BlackBasta were former members of previous ransomware operations, specifically Conti, including similarities in leak site and victim recovery portals. The group took a muted approach to dark web communications, with only one instance of a suspected BlackBasta persona posting on cybercrime forums offering payment for access to corporate networks in its first month of activity.
In May 2024 the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Health and Human Services (HHS), and Multi-State Information Sharing and Analysis Center (MS-ISAC) issued a joint Cybersecurity Advisory (CSA) on BlackBasta, warning that the group had encrypted and stolen data from at least 12 out of 16 critical infrastructure sectors in the US alone. This advisory coincided with reports of a novel social engineering campaign linked to BlackBasta operators, in which threat actors combine spam emails and calls to trick targeted users at an organization into providing remote access to their computer.
February 2025 Update: BlackBasta shut down in February 2025, following the leak of its internal chat logs revealing the group’s inner workings and daily operations. It is believed that former BlackBasta affiliates moved on to work in other ransomware gangs, including INCRansom and Lynx.
BlackCat [OFFLINE]
Active Since: November 2019
Known Forum Aliases: alphv, BlackCat46, ransom
Active Forum Accounts: XSS, Exploit, Ramp
Top Targeted Geographies: US, UK, Canada
The RaaS group BlackCat (also known as ALPHV or Noberus) was believed to include developers and money launderers from the former DarkSide ransomware group, most infamous for the Colonial Pipeline attack.
BlackCat was also suspected to have recruited former members of the REvil operation. It was noteworthy for being one of the first high-profile ransomware families to be written in Rust, a relatively modern programming language with features that make the malware harder to reverse engineer and defend against. It has also been reported that BlackCat let its affiliates keep a larger share of the profits than other RaaS platforms. In February 2023 BlackCat announced a new variant of its ransomware, named Sphynx.
BlackCat was ranked as one of the top three most prolific ransomware groups (by listed victims) in 2022 and 2023. Some of the group’s most notable listed victims from this year were Constellation Software, Sun Pharmaceuticals, Western Digital, Five Guys, and Reddit. BlackCat drew particular attention for its listing of MGM Casinos in September, which was attacked by its suspected affiliate, Scattered Spider.
It looked like the game might be up for BlackCat by the end of 2023, when the U.S. Department of Justice announced its disruption of the BlackCat ransomware gang in December, in collaboration with global law enforcement partners. The FBI shared a decryption tool to help victims to restore their systems and a seizure notice was displayed on BlackCat’s dark web leak site. However, the ransomware gang soon regained control of the site and down-played the significance of the law enforcement action and added victims to its new dark web leak site.
In March 2024 it was reported that BlackCat may have exit-scammed after their dark web leak site went offline. The group claimed that it was closing the site and selling its source code in response to law enforcement action. However, in spite of the seizure notice that appeared on its leak site, agencies like the UK’s National Crime Agency denied any involvement in this takedown. Meanwhile, one of the group’s affiliates claimed on the RAMP cybercrime forum that BlackCat had taken the entire ransom from its attack on Change Healthcare, without sharing the profits – which has prompted the speculation that it has exit-scammed. Its dark web leak site remains offline.
BlackSuit [OFFLINE]
Active Since: May 2023
Top Targeted Geographies: US, UK, Canada
BlackSuit’s ransomware code was notable for its similarity to the Royal ransomware strain.
As is typical of most ransomware operations, BlackSuit targeted a range of industries with a geographical bias towards those located in the United States. Its highest-profile attack to date is thought to be against CDK Global, a Software-as-a-Service provider for car dealerships.
July 2025 Update: BlackSuit was seized in July 2025, in a US-led law enforcement operation that recovered over $1 million of virtual currency.
CoinbaseCartel
Active Since: April 2025
CoinbaseCartel started off promoting database breaches on cybercrime forums, before graduating to a fully-fledged extortion operation around September 2025.
While it still eschews ransomware in favour of exfiltration-only attacks, CoinbaseCartel has maintained a steady output of high-profile victims, including Amcor, Ralph Lauren, and, most recently, construction manufacturer Caterpillar.
CL0P
Active Since: February 2019
Top Targeted Geographies: US, UK, Canada
Cl0p ransomware is known to be used by the cybercriminal enterprise tracked as TA505 and FIN11.
Cl0p is notable for its approach of using vulnerabilities in supply chain software to target multiple organizations, announcing them in a batch at a later date. This was a tactic it used to great effect into 2023, with two “mass-hacks” making Cl0p the third most prolific ransomware group of the year by number of listed victims (after LockBit and BlackCat).
In March of that year, Cl0p exploited the vulnerability CVE-2023-0669 in Fortra’s GoAnywhere MFT secure file transfer tool to target more than 130 organizations, listing them in quick succession. Then in June, Cl0p repeated this approach in one of the biggest and most notable cyberattacks of the year, exploiting a zero day vulnerability (CVE-2023-34362) in the Progress Software file transfer software tool, MOVEit.
The group had so many victims from the MOVEit breach that it had to explore new ways of leaking data, including using torrents. While hundreds of companies were listed on its leak site, it was reported that there were in fact more than 1,000 organizations impacted by the MOVIEit attacks. Noteworthy victims included the BBC, British Airways, Emsisoft, U.S. government services contracting company Maximus, and the French government’s unemployment agency, Pôle emploi.
In the aftermath, the U.S. State Department offered a $10 million bounty for information on Cl0p and the group’s activity has fluctuated since then.
DragonForce
Active Since: November 2023
DragonForce emerged in late 2023, and since then has repeatedly proved itself as a force to reckoned with.
Originally a hacktivist operation, DragonForce pivoted to a RaaS model and has since innovated on the concept, with its “ransomware cartel” program in which threat actors can use its malware under their own separate branding. This offer was put to use with destructive effect in the attacks on British retailers Marks & Spencer, Co-op and Harrods in Spring 2025, which were attributed to the Scattered Spider threat group using DragonForce ransomware. DragonForce has even used adversarial tactics against its competitors, seemingly being implicated in the disintegration of at least two other RaaS operations (RansomHub and BlackLock).
In September 2025, on a closed Russian hacking forum, DragonForce announced a coalition with other RaaS operators, namely Qilin and LockBit. The proposed aim of the coalition was to pool resources and work together to increase overall income. Since this announcement, as evidenced by our data, Qilin’s victim count and prominence increased, potentially demonstrating another example of the success of the ‘Super Group’ collaboration model.
Everest
Active Since: December 2020
Everest has been around since at least 2020, making it one of the oldest ransomware operations still active after LockBit and Cl0p.
Initially using the now-popular technique of double extortion – encrypting a victim’s data in addition to stealing and threatening to publish it on its dark web leaks site – Everest has claimed in recent years to eschew ransomware and engage in data extortion-only attacks. The gang has also been observed moonlighting as an initial access broker, providing unauthorized corporate network access to other threat actors for a fee.
INC Ransom
Active Since: June 2023
IncRansom is a financially motivated group that emerged in 2023. The group have operated a RaaS model and so victims are spread across sectors/industries and geographically. As with many ransomware groups, double extortion, the encrypting, downloading and applying pressure on the victim is the general tactic utilized. Again, similar to many RaaS operators, a mixture of initial access vectors are exploited, ranging from using purchased credentials, conducting phishing campaigns or exploiting known vulnerabilities.
LockBit
Active Since: September 2019
Known Forum Aliases: LockBitSupp, LockBit
Active Forum Accounts: XSS, Exploit
Top Targeted Geographies: US, France, Italy
LockBit is a Ransomware-as-a-service (RaaS) operation that targets organizations across a broad range of industries and regions.
Originally dubbed ABCD, LockBit has developed several versions of its malware, including LockBit Red, Black and Green. On its latest Tor leak site, LockBit 3.0, there are options on some victims’ listings to either extend the countdown timer by 24 hours, “destroy” the stolen data, or download the stolen data, for varying price points. LockBit actively engages with its fans and detractors on dark web forums like XSS, promoting its attacks and investing effort into its branding.
LockBit was the most active ransomware group by number of listed victims on its dark web leak site in 2022 and 2023. LockBit claimed more than a thousand victims last year, including high profile organizations such as the UK Ministry of Defense, Boeing, CDW, Portuguese water company Aguas do Porto, and TSMC, the world’s largest contract chipmaker.
In April 2023 researchers spotted samples of LockBit (which previously targeted Windows, Linux, and VMware ESXi servers) designed to target macOS, a first for major ransomware operations of this scale. In November 2023 a Cybersecurity Advisory was issued warning that LockBit was among many threats exploiting the CVE 2023-4966 Citrix Bleed Vulnerability.
In February 2024 LockBit suffered major disruption at the hands of the NCA, FBI, Europol, and other partners in “Operation Cronos”. The numbers behind Operation Cronos were impressive – two individuals arrested, 28 servers taken down, 200 crypto accounts frozen, and 1k decryption keys obtained – in addition to seizing LockBit’s source code, infrastructure for data exfiltration, and a vast amount of intelligence. The disruption was welcome news to cybersecurity defenders around the world but we observed that the cybercriminal community of the dark web were less impressed.
One of the actors behind the ransomware group LockBit issued a lengthy statement a week later. The actor acknowledged the attack, blaming their own complacency and claiming that law enforcement compromised an old version of PHP, which they had failed to update in their infrastructure. The administrator finished their statement by confirming that the group will carry on operating and even called for new affiliates to join their team.
On Tuesday May 7 the US Department of Justice unsealed charges against the admin and developer of the LockBit ransomware group. Dimitry Yuryevich Khoroshev is subject to 26 criminal counts as well as financial and travel sanctions in the US, UK and Australia. The DoJ has also offered a $10m reward for information that could lead to his arrest or conviction. The hijacked leak site was also brought back online by Operation Cronos, displaying information relating to affiliates who worked as part of LockBit’s ransomware-as-a-service (RaaS) scheme, and data points highlighting the effectiveness of the original law enforcement action in diminishing the group’s ability to launch new attacks and attract recruits after the damage done to its reputation.
You can read a full overview of Operation Cronos in our blog or listen to our episode of The Dark Dive podcast: The LockBit Takedown.
November 2025 Update: As of 2025 LockBit is still active, albeit severely degraded, with a new version of its ransomware LockBit 5.0 being identified in the wild.
Lynx
Active Since: July 2024
Lynx is a ransomware group that appeared in 2024 which is believed to be derived from IncRansom.
The group employs the ransomware-as-a-service business model and recruits affiliates via the RAMP cybercrime forum.
Medusa
Medusa is one of few legacy ransomware brands still active; it launched its dark web leak site in January 2023.
This longevity has not diminished Medusa’s relevance, with a surge in activity observed in 2025 and reports suggesting North Korean state-sponsored threat actor Lazarus Group has adopted its malware for extortion campaigns. Like most ransomware actors, Medusa favours targets in the United States, with its most-victimized industries including capital goods, commercial and professional services, and healthcare.
Play
Active Since: June 2022
Top Targeted Geographies: US, UK, Canada
Play ransomware is named after the “.play” extension it appends to the files it encrypts.
It has been noted that tactics used by Play are shared by fellow ransomware campaigns Nokoyawa and Hive, suggesting a connection between the operations. There is also indication that Play ransomware shares some of the infrastructure to stage its attacks with Quantum RaaS.
Play keeps a fairly low profile on the dark web aside from its leak site, not advertising via forum accounts and recently had to fend off accusations it had introduced a RaaS model. The gang claims on its site to be a closed group to “guarantee the secrecy of deals”.
Qiin
Active Since: Mid 2022
Known Aliases: Haise
Qilin is a prolific ransomware group using the RaaS business model. The group became active in mid 2022, initially using the name “Agenda”. At the time of writing this report, the group has claimed over 1300 victims via its extortion site.
The initial ransomware variant was developed using the Go programming language, however, this was rewritten using Rust and later C. Variants target systems using the Windows, Linux and ESXi operating systems. The group is known to heavily rely on social engineering techniques to gain initial access.
A member of the Ramp cybercrime forum using the ‘Haise’ handle is a representative of the ransomware group and often advertises the affiliate program with the intention of recruiting new members. The forum user claimed that the ransomware is capable of delivering four types of encryption, encrypting a file in full or in part. Successful candidates for the RaaS scheme are granted access to a panel featuring the build configurator, dialogue support, and spam calling and SMS services.
Qilin made several updates over the course of 2025, and added an option to
conduct distributed denial-of-service (DDoS) attacks against victims to pressure them
into paying the ransom. This is known as triple extortion. Additionally, affiliates are offered legal advice on how to negotiate with victims based on their jurisdiction and type of compromised data, tailoring, and streamlining their negotiation process to each victim.
In the latest update, the Qilin spokesperson stated that a call center available in seven languages would be soon opened to contact victims and their customers. All of this suggests an acceleration of activity and - indeed - compared to the other most active groups, Qilin has generally posted more victims month-on-month.
RansomHub
Active Since: February 2024
Known Forum Aliases: Koley
Active Forum Accounts: RAMP
Top Targeted Geographies: US, Brazil, Italy
Despite only emerging in February 2024, RansomHub quickly became one of the most active RaaS operations we tracked.
Its representatives have been spotted recruiting affiliates on dark web forums, offering a fixed 10 percent fee and the option to collect ransom payments directly from victims before paying the core group.
RansomHub’s rapid rise to prominence can potentially be explained by links to BlackCat, an extremely prolific ransomware group that retired earlier this year after attacking the healthcare technology company Change Healthcare. It is suspected that RansomHub could have contained former affiliates of the BlackCat ransomware group, especially as the group also listed Change Healthcare as a victim.
Its “affiliate-friendly” model could also be seen as a direct response to BlackCat’s retirement, where it is believed that the operators of the group perpetrated an “exit scam”, taking the entire ransom payment from Change Healthcare without properly compensating the affiliate responsible for the attack. Most of RansomHub’s victims were located in the United States.
March 2025 Update: RansomHub went offline in March 2025, after its site was taken over and defaced by rival ransomware gang DragonForce.
Rhysida
Active Since: May 2023
Top Targeted Geographies: US, UK, Italy
Rhysida has quickly risen to notoriety due to high profile attacks on the organizations such as the British Library, which took the cherished UK institution’s website, systems, and some on-site services offline.
Just weeks later, the gang took aim at another British institution – the royal family – threatening to leak data from a private London hospital, which it claimed contained sensitive information on the royals.
The group is noteworthy for its focus on organizations in the education industry, followed by those in health care equipment & services, and the public sector.
Some cybersecurity analysts have identified similarities in the Tactics, Techniques and Procedures (TTPs) of Rhysida and those used by Vice Society. Other correlatory factors include temporal crossover – after Rhysida’s appearance only two victims were posted on Vice Society’s leak site before it stopped being active – and similarity in victimology.
Royal [OFFLINE]
Active Since: May 2023
Top Targeted Geographies: US, UK, Italy
Royal isn’t a RaaS group and doesn’t appear to work with affiliates.
There is speculation that Royal is composed of former members of Conti ransomware gang, due to their use of similar ransom notes and callback phishing techniques.
Royal initially used third-party ransomware including BlackCat and Zeon before developing its own malware, written in C++, that infects Windows systems and deletes all Volume Shadow Copies to prevent data recovery. In February 2023, Royal operators added the ability to encrypt Linux devices and target VMware ESXi virtual machines.
In March 2023, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) released a joint Cybersecurity Advisory on Royal, warning that the group targets critical infrastructure sectors.
Royal’s leak site hasn’t been active since July 2023 and researchers have drawn similarities between its ransomware strain and that of a newer operation, BlackSuit, which could suggest Royal has rebranded.
Safepay
Active Since: November 2024
Safepay was first discovered in late 2024 and have been seen abusing compromised credentials to eventually deploy ransomware ever since.
The ransomware strain used by the group has common traits with LockBit 3.0. The group also uses social engineering as an initial access vector.
Sinobi
Active Since: June 2025
Sinobi began activity in June 2025, and has since maintained a consistent rhythm of attacks against a range of industries and geographies.
It is believed to be linked to the IncRansom and Lynx operations, with their leak sites sharing multiple visual similarities.
ShinyHunters
While not technically a ransomware group, we would be remiss not to mention ShinyHunters, formerly ScatteredLapsusHunters.
Known for its voluminous data extortion attacks on high-profile organizations, ShinyHunters often leverages weaknesses in widely-used software products to compromise downstream targets, referred to as supply chain compromise.
TheGentlemen
Active Since: September 2025
First observed in September 2025, the Gentlemen is believed to be a former affiliate of Qilin, known as ArmCorp, which spun off to form its own RAAS program following a payment dispute.
Since then, the Gentlemen has maintained a steady stream of victims, using sophisticated custom tools to bypass endpoint protections and leveraging Bring-Your-Own-Vulnerable-Driver (BYOVD) attacks. The group targets multiple geographies and industries, with a focus on manufacturing, information technology and healthcare.
Update June 2026: In May 2026, The Gentlemen suffered a data breach where internal communications orginating from the group’s Rocketchat servers were leaked. The leaks gave insight into the group’s TTPs, organizational structure and potential personnel crossover with now-defunct ransomware schemes Conti and BlackBasta.
Using ransomware leak site intelligence for proactive security
Ransomware leak sites should not be viewed in isolation. Their greatest value comes from combining leak-site intelligence with other sources of threat intelligence and an understanding of an organization's own exposure.
By monitoring ransomware groups and their activity, security teams can understand who is actively targeting organizations like theirs, what techniques those groups are using and which vulnerabilities or access methods may be relevant.
Combining this intelligence with Attack Surface Management allows organizations to map active ransomware threats against their own externally exposed assets. If a ransomware group is exploiting a vulnerability affecting a particular technology, for example, security teams can identify whether that technology is exposed within their environment and prioritize remediation.
This shifts ransomware defense away from simply responding to encryption and extortion and toward preventing attackers from gaining the foothold they need in the first place.
For a broader understanding of how organizations can use threat intelligence and exposure management to prevent attacks before they happen, explore our guide to Preemptive Cybersecurity.


.webp)
