Ransomware Groups
Ransomware crews run their own extortion sites, and they publish there before anyone tells the victim. We watch 620 of those sites. This page is the reference on the groups behind them — what each one is, what it goes after, and whether it is still running.
What a ransomware leak site is
Most ransomware groups no longer just encrypt files. They copy the data out first, then threaten to publish it. To make the threat credible they run a public extortion site — usually on Tor — where they name the company, count down to a deadline and eventually release whatever they took.
That naming is the moment a breach stops being private. It happens without warning, it is often the first time a victim's customers and suppliers hear anything, and it can precede any regulatory filing by weeks.
How this list is built
Every group here has a leak site we check on a schedule. When one is reachable we record what changed on it and when. When a site stops answering we keep the group and mark it offline, because crews go quiet and come back under the same name more often than they disappear.
Group descriptions are compiled from open reporting; status and timing are ours. Treat a group's own claims about its size with suspicion — several exist mainly to look busy, list the same target twice, or post sandbox runs as victims.
Every group we track
- Tridentlocker18h ago
- Ramp18h ago
- Nullbulge18h ago
- Daixin18h ago
- Imn Crew18h ago
- Kelvin Security18h ago
- Settra18h ago
- Unsafe18h ago
- Sabbath18h ago
- Bianlian18h ago
- Money Message18h ago
- Genesis18h ago
- Shiba18h ago
- Netrunner18h ago
- Barracuda18h ago
- Ragnarlocker18h ago
- Inc Ransom18h ago
- Nitrogen18h ago
- Radar18h ago
- Krybit18h ago
- Ransomexx18h ago
- Secp018h ago
- Wiper Leak18h ago
- 0mega18h ago
- Audit Team18h ago
- Chaos18h ago
- Doommageddon18h ago
- 0apt18h ago
- Late.Lol18h ago
- Cyberleek18h ago
- Falcon18h ago
- Weyhro18h ago
- Osyolorz Collective18h ago
- Scattered Lapsus$ Hunters18h ago
- Xpl0itrs18h ago
- Exfilsquad18h ago
- Threatmarket18h ago
- Leakeddata18h ago
- Payload18h ago
- Bjorka18h ago
- Werewolves18h ago
- Tooda18h ago
- Crpx018h ago
- Antibrok3rs18h ago
- Handala18h ago
- Justice_blade18h ago
- Lsd18h ago
- Panzer18h ago
- Payoutsking18h ago
- Toufan18h ago
- Clop18h ago
- Lapsus$18h ago
- Robinhood18h ago
- Leaknet18h ago
- Linkc18h ago
- Sovcali18h ago
- Ransomedvc218h ago
- Cry018h ago
- Insomnia18h ago
- Medusa18h ago
Common questions
How many ransomware groups are there?
More than most lists suggest, and the number moves constantly. We track over six hundred distinct leak sites, but only a fraction are publishing at any given time. Crews rebrand after law-enforcement action, split into affiliates, and reappear under new names, so a count is a snapshot rather than a fact.
What does it mean when a leak site is offline?
Usually less than people hope. Sites go down for infrastructure trouble, deliberate quiet periods, or a takedown — and many come back weeks later under the same name. We keep the group listed and record the status rather than deleting the entry.
Does a group appearing here mean it is currently active?
No. This is the full list of leak sites we track, including dormant and defunct ones. Filter to sites that are responding, or sort by recent activity, to see who is actually moving.
Where do the group descriptions come from?
Public reporting and vendor research, compiled per group. They describe how a crew has historically operated, so they can lag its current behaviour. Live status and timing come from our own checks.
Can I be told when a specific company appears on one of these sites?
Yes, and that is what SINON is for. You give it the names, domains and suppliers you care about, and it watches these sites and other sources for them continuously instead of you refreshing a page.
Find out before the countdown starts
This page tells you who is out there. SINON watches these same sites for your company, your domains and your suppliers, and tells you the moment one of them appears.