Ransomware Groups
Ransomware crews run their own extortion sites, and they publish there before anyone tells the victim. We watch 620 of those sites. This page is the reference on the groups behind them — what each one is, what it goes after, and whether it is still running.
What a ransomware leak site is
Most ransomware groups no longer just encrypt files. They copy the data out first, then threaten to publish it. To make the threat credible they run a public extortion site — usually on Tor — where they name the company, count down to a deadline and eventually release whatever they took.
That naming is the moment a breach stops being private. It happens without warning, it is often the first time a victim's customers and suppliers hear anything, and it can precede any regulatory filing by weeks.
How this list is built
Every group here has a leak site we check on a schedule. When one is reachable we record what changed on it and when. When a site stops answering we keep the group and mark it offline, because crews go quiet and come back under the same name more often than they disappear.
Group descriptions are compiled from open reporting; status and timing are ours. Treat a group's own claims about its size with suspicion — several exist mainly to look busy, list the same target twice, or post sandbox runs as victims.
Every group we track
- Minteye8mo ago
- Locus8mo ago
- Lyrix9mo ago
- Noname9mo ago
- Wikileaksv29mo ago
- Dark Shinigami9mo ago
- Kryptos9mo ago
- Rustylocker9mo ago
- Helldown9mo ago
- Global9mo ago
- El Dorado9mo ago
- Trinity9mo ago
- Skira Team9mo ago
- Ranion10mo ago
- Silent10mo ago
- Ransombay10mo ago
- Cicada330110mo ago
- Radiant Group10mo ago
- White Lock10mo ago
- 8base10mo ago
- Zircon10mo ago
- Desolator11mo ago
- Xleaks11mo ago
- Krypt11mo ago
- Apos11mo ago
- Miga11mo ago
- Dunghill1y ago
- Octovillan1y ago
- Izis1y ago
- Yurei1y ago
- Frag1y ago
- Sphinx1y ago
- Teamxxx1y ago
- D4rk4rmy1y ago
- Cephalus1y ago
- C3rb3r1y ago
- Fsociety1y ago
- Tssxx251y ago
- Kawa1y ago
- Nemesis1y ago
- Xinglocker1y ago
- Blackbasta1y ago
- Bytesfromheaven1y ago
- Blackbit1y ago
- Zeta Leaks1y ago
- Bober1y ago
- Lcryptorx1y ago
- Monti1y ago
- Bert1y ago
- Hunters1y ago
- Blackhunt1y ago
- Vicesociety1y ago
- Unknown1y ago
- Sugar1y ago
- Sifrecikis1y ago
- Sharpboys1y ago
- Ransomcartel1y ago
- Pandora1y ago
- Mindware1y ago
- Sekhmet1y ago
Common questions
How many ransomware groups are there?
More than most lists suggest, and the number moves constantly. We track over six hundred distinct leak sites, but only a fraction are publishing at any given time. Crews rebrand after law-enforcement action, split into affiliates, and reappear under new names, so a count is a snapshot rather than a fact.
What does it mean when a leak site is offline?
Usually less than people hope. Sites go down for infrastructure trouble, deliberate quiet periods, or a takedown — and many come back weeks later under the same name. We keep the group listed and record the status rather than deleting the entry.
Does a group appearing here mean it is currently active?
No. This is the full list of leak sites we track, including dormant and defunct ones. Filter to sites that are responding, or sort by recent activity, to see who is actually moving.
Where do the group descriptions come from?
Public reporting and vendor research, compiled per group. They describe how a crew has historically operated, so they can lag its current behaviour. Live status and timing come from our own checks.
Can I be told when a specific company appears on one of these sites?
Yes, and that is what SINON is for. You give it the names, domains and suppliers you care about, and it watches these sites and other sources for them continuously instead of you refreshing a page.
Find out before the countdown starts
This page tells you who is out there. SINON watches these same sites for your company, your domains and your suppliers, and tells you the moment one of them appears.