Skip to main content
Cybersecurity

Ransomware Leak-Site Monitoring Victim announcements, as the groups publish them

We ingest public ransomware leak sites and surface each victim post with its group, its timestamp, and the infrastructure indicators we can correlate to it. This is leak-site coverage — not forum, marketplace, or credential monitoring.

No credit card required · Free API key

Capabilities

Key features. Everything you need to protect your infrastructure and users.

Leak-Site Ingestion

Victim posts collected from public ransomware leak sites via the RansomLook and Ransomfeed feeds.

Group Profiles

Per-group pages with victim history and observed activity over time.

Correlated Indicators

IPs, domains, and hashes tied to a group are cross-referenced against the wider indicator set.

Breach-Associated Domains

Domains tied to known breaches are ingested as credential-leak indicators, alongside the rest of the catalogue.

Applications

Use cases. How security teams use this tool.

Victim Awareness

See when an organisation in your supply chain is named on a leak site.

Group Research

Follow a single ransomware group’s activity and the infrastructure attributed to it.

Third-Party Risk

Check whether a vendor domain appears in leak-site posts or among breach-associated domains.

Support

Frequently asked questions.

What exactly do you monitor?

Public ransomware leak sites, ingested from the RansomLook and Ransomfeed feeds. When a group posts a victim, that post is captured along with the group, the timestamp, and any infrastructure indicators we can correlate.

Do you monitor underground forums, marketplaces, or Telegram?

No. We do not operate forum, marketplace, paste-site, or Telegram collection, and we do not index credential dumps. If you need that, you need a dedicated dark web monitoring vendor — this is not one.

Can you tell me if my employees’ passwords have leaked?

No. We ingest the domains associated with known breaches as indicators, tagged as credential-leak. We do not hold, search, or alert on individual credentials.

How current is the data?

Leak-site feeds are polled continuously and new victim posts appear in the ransomware tracker shortly after they are published by the group.
Get started

Ready to get started?

Join thousands of security teams using isMalicious to protect their infrastructure.

No credit card required · Free API key