ctipilot.ch

Ransom-ISAC

ransom-isac · C · active

https://ransom-isac.org/blog/

researchbreacheslang: enfetch failures: 0quiet periods: 2last fetch: 2026-08-17

Ransomware/data-extortion ISAC publishing retrospective post-incident case studies with negotiation transcripts and actor-model analysis. Surfaced by S4 on 2026-07-05 as the PRIMARY for the Kairos data-theft-only extortion case study (US county ~$1M payout). Candidate — promote to active after 3 contributing runs. FETCH -> webfetch https://ransom-isac.org/blog/ (listing), then WebFetch the article URL. Discovery/analysis source; verify actor/victim claims against corroborating journalism before citing specifics. | 2026-07-05 admiralty audit: C (MEDIUM->C) — original extortion case studies but newer/niche with self-noted unverified attributions; corroborate specifics. Keep candidate. Note: canonical domain is ransom-isac.org (not .com). | 2026-07-28: status candidate -> active. State digest reported it in sources.promotion_due with 3 contributing runs, meeting the three-contributing-run promotion bar. | 2026-08-15: the /blog/ path is a client-rendered shell with no server-side post list; the site's own /feed.xml works cleanly and is the recipe to use.

Cited in 5 entries

Citation cadence

Citation days per ISO week (5 weeks of coverage span, total 3).