Ransomware.live
ransomware-live · C · active
Public extortion-leak observatory, scrapes ransomware groups' shaming sites and exposes new claims (added 2026-05-08). 2026-05-08 audit: WebFetch returned 5 fresh victim entries (5h-old). For automated monitoring, use the JSON API at https://api.ransomware.live/v2/groups (one entry per group with recent victims). Discovery, always corroborate against victim statement / regulator filing before citing as confirmed breach. Candidate; promote to active after 3 runs. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → api: python3 tools/fetch_source.py url https://api.ransomware.live/v2/recentvictims (new victim claims, one record each with victim/group/activity/country/claim_url); /v2/groups for per-group view. AVOID: Do NOT rely on the homepage HTML for automation, use the JSON API. Treat as discovery: every claim is an unverified extortion-site post; corroborate before citing as confirmed breach.. | 2026-07-05 admiralty audit: C, community leak-site tracker (Mousqueton); accurate mirror of extortion posts but claims unverified, corroborate before citing as confirmed breach. Live, active retained.
Cited in 6 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 6).
- A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site2026-09-17
- A Zurich business school tells students their bank details and sick-leave records were stolen, not from its own systems, but through the infrastructure of an IT service provider whose leak-site listing names seven other Swiss customers alongside it, and does not close the list2026-08-23
- Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to it2026-07-29
- Swiss autism-support foundation Stiftung Autismuslink confirms data-theft cyberattack; INC Ransom claims it2026-07-25
- MedusaLocker leak site lists the Canton of Zürich's Baudirektion, unconfirmed claim2026-07-02
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane2026-06-20