Ransomware Leak Site Monitoring: How to Know Before Your Name Appears
Ransomware groups publish victims on leak sites days before the press reports them. Here is how leak site monitoring works, what it catches, and why the gap is the most useful thing about it.

A ransomware group that steals your data has a problem. Stolen files are worthless unless someone believes they exist, so the group has to advertise. That advertisement is the leak site, and it goes up before most victims have told anyone.
The gap between a listing appearing and the incident reaching the news is usually measured in days. Ransomware leak site monitoring is the practice of watching that gap. It is one of the few areas in security where the defender can be early rather than late.
What a ransomware leak site actually is
Every significant extortion group runs one. It is a Tor-hosted page listing organisations the group claims to have compromised, usually with a countdown, a sample of stolen files, and a ransom demand. Groups use them for leverage: publish the name, start the clock, let the victim's customers and regulators find out on the group's schedule.
The sites are public in the sense that anyone with Tor can read them. They are difficult to watch consistently because groups rotate domains, sites go down under load, and listings are edited or deleted once a victim pays. A page you read on Tuesday may be gone on Thursday, which is why monitoring means capturing rather than checking.
The window most organisations never use
In August 2026 a group posted a listing carrying 5.79 TB and a file-by-file inventory, with no victim named. It said only Coming soon. Seven days later the same listing was published with the name attached: the state of Berlin. The press reported it the following day.
That teaser existed for a week. Anyone monitoring the site had the inventory, the volume and the categories of stolen data before the victim was public, and the victim itself had a week in which its own breach was being advertised in a form it could have read.
This pattern is ordinary. Staged reveals are a negotiating tactic, so the teaser is common and the interval is real. The question worth asking is whether your organisation, or any supplier you depend on, would notice.
What monitoring actually catches
Three things, in rough order of how often they matter.
Your own name. The obvious case, and the least common. If you are listed you will usually know already, because the group will have contacted you. The value is confirmation of what they claim to hold, which is often the first inventory a victim sees.
Your suppliers. This is where leak site monitoring earns its cost. Your payroll provider, your logistics partner, the agency holding your customer list — a listing naming any of them is your incident too, and you will hear about it from the leak site long before you hear about it from them. Supply chain exposure is the reason most teams start watching.
Your sector, ahead of time. Groups work in campaigns. A crew that lists four regional hospitals in a fortnight is running a campaign against a shared piece of software, and the fifth hospital has a few days to check whether it is exposed the same way.
Why victim counts are the wrong metric
Most published ransomware statistics count victims per group per month. It makes for a clean chart and tells you very little, because the number reflects how loudly a group advertises rather than how much damage it does. A crew that lists thirty small companies is not more dangerous than one that quietly extorts three large ones.
More useful questions: is this group active this week, what sectors has it named recently, and has it changed the kind of organisation it targets? A group that spent two years on small manufacturers and has started naming hospitals has changed something, and that is worth knowing before the pattern reaches you.
Doing it yourself, and where that stops working
You can monitor leak sites manually. Install Tor Browser, collect the current addresses for the groups you care about, and check them on a schedule. For two or three groups this is an afternoon a week and it works.
It stops working for three reasons. Groups rotate domains without notice, so a bookmarked address goes dead and the silence looks like inactivity. Listings are removed after payment, so anything you did not capture is gone. And the number of active groups is in the hundreds, which is beyond what a person can check by hand while doing anything else.
At that point it becomes a tooling problem: continuous capture, alerting on the names and suppliers you nominate, and an archive of listings that no longer exist on the live site.
What to watch, practically
- Your legal entities, not just your brand. Groups list the name on the paperwork, which is often not the name on your website.
- Your top suppliers by data access, rather than by spend. The vendor holding your HR records matters more than the one with the biggest invoice.
- Subsidiaries and recent acquisitions. They are listed under their old names, and they are usually the weakest part of a merged estate.
- Sector and region, as a standing feed rather than an alert. This is context, and treating it as an alert trains people to ignore it.
The honest limits
Leak site monitoring sees what groups choose to publish. A victim who pays quickly may never be listed at all, so absence from every leak site proves nothing. Everything in a listing is the attacker's claim, including the volume, the file count and the inventory, and attackers inflate all three.
What it does reliably is shorten the distance between a group deciding to name you and you finding out. On the evidence of the last three years, that distance is usually several days, and several days is enough to matter.
SINON tracks ransomware groups continuously and alerts on the names, domains and suppliers you nominate. You can browse the groups we track, one profile at a time, on the ransomware groups directory.