Ransomware Groups
Ransomware crews run their own extortion sites, and they publish there before anyone tells the victim. We watch 620 of those sites. This page is the reference on the groups behind them — what each one is, what it goes after, and whether it is still running.
What a ransomware leak site is
Most ransomware groups no longer just encrypt files. They copy the data out first, then threaten to publish it. To make the threat credible they run a public extortion site — usually on Tor — where they name the company, count down to a deadline and eventually release whatever they took.
That naming is the moment a breach stops being private. It happens without warning, it is often the first time a victim's customers and suppliers hear anything, and it can precede any regulatory filing by weeks.
How this list is built
Every group here has a leak site we check on a schedule. When one is reachable we record what changed on it and when. When a site stops answering we keep the group and mark it offline, because crews go quiet and come back under the same name more often than they disappear.
Group descriptions are compiled from open reporting; status and timing are ours. Treat a group's own claims about its size with suspicion — several exist mainly to look busy, list the same target twice, or post sandbox runs as victims.
Every group we track
- The Gentlemen15h ago
- Direwolf16h ago
- Qilin17h ago
- Akira17h ago
- Storm17h ago
- M3rx17h ago
- Shinyhunters17h ago
- Lockbit317h ago
- Interlock17h ago
- Killsec317h ago
- Black X17h ago
- Lynx17h ago
- Dark Project17h ago
- Crypto2417h ago
- 3am17h ago
- Ailock17h ago
- Space Bears17h ago
- Global Secret Group17h ago
- Team Underground17h ago
- Embargo17h ago
- Ms13-08917h ago
- Rhysida17h ago
- Dysphor1a17h ago
- Sarcoma17h ago
- Deadlock17h ago
- Ransomhouse17h ago
- Termite17h ago
- Meowciety40317h ago
- Ethics17h ago
- Alphv17h ago
- Satanlock17h ago
- Black Nevas17h ago
- Pear17h ago
- Eraleign (Apt73)17h ago
- Morpheus17h ago
- Blackout17h ago
- Brain Cipher17h ago
- Eclipse17h ago
- Rtm Locker17h ago
- Play17h ago
- Waissbein17h ago
- Orova17h ago
- Prinz Eugen17h ago
- Satancd17h ago
- Ulose17h ago
- 0day17h ago
- Titan17h ago
- Vexy17h ago
- Atomsilo17h ago
- Wallstreet17h ago
- Lockbit517h ago
- Booba Team17h ago
- Cmd Organization17h ago
- Fulcrumsec17h ago
- Blackwater17h ago
- Bravox17h ago
- Bavacai17h ago
- Dragonforce17h ago
- Run Some Wares17h ago
- Qilin-Securotrop17h ago
Common questions
How many ransomware groups are there?
More than most lists suggest, and the number moves constantly. We track over six hundred distinct leak sites, but only a fraction are publishing at any given time. Crews rebrand after law-enforcement action, split into affiliates, and reappear under new names, so a count is a snapshot rather than a fact.
What does it mean when a leak site is offline?
Usually less than people hope. Sites go down for infrastructure trouble, deliberate quiet periods, or a takedown — and many come back weeks later under the same name. We keep the group listed and record the status rather than deleting the entry.
Does a group appearing here mean it is currently active?
No. This is the full list of leak sites we track, including dormant and defunct ones. Filter to sites that are responding, or sort by recent activity, to see who is actually moving.
Where do the group descriptions come from?
Public reporting and vendor research, compiled per group. They describe how a crew has historically operated, so they can lag its current behaviour. Live status and timing come from our own checks.
Can I be told when a specific company appears on one of these sites?
Yes, and that is what SINON is for. You give it the names, domains and suppliers you care about, and it watches these sites and other sources for them continuously instead of you refreshing a page.
Find out before the countdown starts
This page tells you who is out there. SINON watches these same sites for your company, your domains and your suppliers, and tells you the moment one of them appears.