ctipilot.ch

Ransomware.live

ransomware-live · C · active

https://www.ransomware.live/

ransomwarebreachesdiscoverylang: enfetch failures: 0quiet periods: 0last fetch: 2026-08-07

Public extortion-leak observatory — scrapes ransomware groups' shaming sites and exposes new claims (added 2026-05-08). 2026-05-08 audit: WebFetch returned 5 fresh victim entries (5h-old). For automated monitoring, use the JSON API at https://api.ransomware.live/v2/groups (one entry per group with recent victims). Discovery — always corroborate against victim statement / regulator filing before citing as confirmed breach. Candidate — promote to active after 3 runs. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → api: python3 tools/fetch_source.py url https://api.ransomware.live/v2/recentvictims (new victim claims, one record each with victim/group/activity/country/claim_url); /v2/groups for per-group view. AVOID: Do NOT rely on the homepage HTML for automation — use the JSON API. Treat as discovery: every claim is an unverified extortion-site post; corroborate before citing as confirmed breach.. | 2026-07-05 admiralty audit: C — community leak-site tracker (Mousqueton); accurate mirror of extortion posts but claims unverified, corroborate before citing as confirmed breach. Live, active retained.

Cited in 6 entries

Citation cadence

Citation days per ISO week (5 weeks of coverage span, total 5).