Ransomware Data Resale: The 12-Day Gap After a Leak Site
Ransomware Data Resale: The 12-Day Gap After a Leak Site On 20 August 2026 the ransomware group pear published four victims to its leak site: a plastic surgery institute, a healthcare billing provider

Ransomware Data Resale: The 12-Day Gap After a Leak Site
On 20 August 2026 the ransomware group pear published four victims to its leak site: a plastic surgery institute, a healthcare billing provider, a casino operator and a medical supplier. Mid-market companies, which is who this business mostly hits.
Twelve days later the same four were on sale on a dark web forum. The seller was not pear. It was a broker running a catalogue, and every entry carried the victim's annual revenue.
Ransomware data resale is not new. What we had not seen before is how regular the schedule is.

[IMAGE 1 — timeline: leak-site publication date against forum listing date, showing the 10–18 day band]
How the dark web data broker packages a victim
The seller uses the handle V0idix and has run the same listing format since late July. Each entry fills in six fields: Site, Industry, Location, Revenue, Data Volume, Data Description.
One of them reads healthcare software, USA, $10.8M revenue, 2.7 TB, and then lists the contents as business operations, financial records, provider data, mailboxes and email correspondence, and database exports carrying patient PII and PHI.
The Data Description field is consistent across the whole set. All twenty-three corporate listings advertise mailboxes and email correspondence, three name the victim's Dropbox and one names OneDrive. Nobody here is selling a database extract. What is on offer is the estate — file storage, mail and cloud, everything the company had.
The revenue tags run from $5M to $45M, and they are the part that tells you most about the operation. Pricing a dataset by the victim's turnover means the victim was researched first.

[IMAGE 2 — redacted catalogue listing, showing the six template fields and the revenue tag]
A median lag of twelve days
We ran the catalogue against every ransomware leak site we index. Eleven of the thirteen companies pear named this year appear in it, at intervals of 10, 10, 11, 11, 12, 12, 12, 12, 17 and 18 days.
The listings also arrive in batches rather than a steady trickle. Pear published eight victims between 20 and 22 August, and seven of those went up on the forum on 1 September in a single sitting. Three more victims followed between 3 and 11 September, and all three were listed on 21 September, again in one sitting. That cadence looks like a queue being worked through every fortnight.
Why leak site monitoring leaves a gap
Incident response tends to treat the leak-site post as the end of the matter. The group publishes, you notify, the news cycle passes and monitoring winds down.
The timings argue against that. Ransomware victim data has two separate lives. A leak site is where it works as leverage against one company. A forum is where the same files become stock, sold on to a much wider market, and that second sale lands after the incident has been closed out.
Watching only the extortion sites produces a false negative. The second exposure sits on different infrastructure under a different name, and the victim appears as a domain rather than a brand. Dark web monitoring that stops at leak sites will not catch it.
The window is roughly a fortnight. Where a group resells, the useful time to be reading forum listings is days seven to twenty-one after the leak-site post, rather than the week everyone is still on the incident bridge.
A different buyer means a different risk. Double extortion is aimed at your leadership. A bulk listing is aimed at everyone downstream, because the client and vendor correspondence in those mailboxes, along with the credentials and invoice threads, is what makes business email compromise straightforward.

[IMAGE 3 — chart: listings by victim revenue band against data volume]
One case still open
Pear published a medical company on 27 August. Every other victim from that stretch has since appeared in the catalogue, and that one has not. It may have paid, or it may be sitting in the next batch, and either way the answer should be visible within a couple of weeks.
If your organisation was named on a leak site this month, treat the disclosure as the first of two events. The second one is quieter, it is aimed at a different buyer, and on current evidence it arrives about twelve days behind.