CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Ransom-ISAC

ransom-isac · C · active

https://ransom-isac.org/blog/

researchbreacheslang: enfetch failures: 0quiet periods: 5last fetch: 2026-09-14

Ransomware/data-extortion ISAC publishing retrospective post-incident case studies with negotiation transcripts and actor-model analysis. Surfaced by S4 on 2026-07-05 as the PRIMARY for the Kairos data-theft-only extortion case study (US county ~$1M payout). Candidate; promote to active after 3 contributing runs. FETCH -> webfetch https://ransom-isac.org/blog/ (listing), then WebFetch the article URL. Discovery/analysis source; verify actor/victim claims against corroborating journalism before citing specifics. | 2026-07-05 admiralty audit: C (MEDIUM->C), original extortion case studies but newer/niche with self-noted unverified attributions; corroborate specifics. Keep candidate. Note: canonical domain is ransom-isac.org (not .com). | 2026-07-28: status candidate -> active. State digest reported it in sources.promotion_due with 3 contributing runs, meeting the three-contributing-run promotion bar. | 2026-08-15: the /blog/ path is a client-rendered shell with no server-side post list; the site's own /feed.xml works cleanly and is the recipe to use. | 2026-08-23: RECIPE FIX, direct WebFetch returns HTTP 403; the bridge's `url` subcommand recovers the full Next.js SSR listing. fetch_method webfetch -> bridge. | 2026-10-03 S4: https://ransom-isac.org/feed.xml works directly (15 dated items, newest 2026-09-25). (2026-10-03T0404Z-intel)

Cited in 2 entries

Citation cadence

Citation days per ISO week (3 weeks of coverage span, total 2).