Ransomware Groups
Ransomware crews run their own extortion sites, and they publish there before anyone tells the victim. We watch 620 of those sites. This page is the reference on the groups behind them — what each one is, what it goes after, and whether it is still running.
What a ransomware leak site is
Most ransomware groups no longer just encrypt files. They copy the data out first, then threaten to publish it. To make the threat credible they run a public extortion site — usually on Tor — where they name the company, count down to a deadline and eventually release whatever they took.
That naming is the moment a breach stops being private. It happens without warning, it is often the first time a victim's customers and suppliers hear anything, and it can precede any regulatory filing by weeks.
How this list is built
Every group here has a leak site we check on a schedule. When one is reachable we record what changed on it and when. When a site stops answering we keep the group and mark it offline, because crews go quiet and come back under the same name more often than they disappear.
Group descriptions are compiled from open reporting; status and timing are ours. Treat a group's own claims about its size with suspicion — several exist mainly to look busy, list the same target twice, or post sandbox runs as victims.
Every group we track
- Lockbit2y ago
- Locky2y ago
- Blackmatter2y ago
- Crypt Ransomware2y ago
- Playboy2y ago
- Cryptbb2y ago
- Meow2y ago
- Nokoyawa2y ago
- Tommyleaks2y ago
- Sensayq2y ago
- Schoolboys2y ago
- Revil2y ago
- Relic2y ago
- Redalert2y ago
- Quantum2y ago
- Red Ransomware2y ago
- Royal2y ago
- Sparta2y ago
- Prometheus2y ago
- Netwalker2y ago
- Lv2y ago
- Luckbit2y ago
- Lorenz2y ago
- Jaff2y ago
- Icefire2y ago
- Hellokitty2y ago
- Hades2y ago
- Gwisin2y ago
- Grief2y ago
- Gandcrab2y ago
- Ftcode2y ago
- Doppelpaymer2y ago
- Dataf Locker2y ago
- Dagonlocker2y ago
- Cyclops2y ago
- Cryptxxx2y ago
- Bitransomware2y ago
- Avaddon2y ago
- Ako2y ago
- Killsec2y ago
- Dan0n2y ago
- Valencia Leaks2y ago
- Mad Liberator2y ago
- Ransomcortex2y ago
- U-Bomb2y ago
- Qiulong2y ago
- Hellogookie2y ago
- Lockdata2y ago
- Holyghost2y ago
- Adminlocker2y ago
- Clop Torrents2y ago
- Fsteam2y ago
- La Piovra2y ago
- Good Day2y ago
- Synapse2y ago
- Zero Tolerance Gang (Ztg)2y ago
- Rabbit Hole2y ago
- Trisec2y ago
- Donex3y ago
- Siegedsec3y ago
Common questions
How many ransomware groups are there?
More than most lists suggest, and the number moves constantly. We track over six hundred distinct leak sites, but only a fraction are publishing at any given time. Crews rebrand after law-enforcement action, split into affiliates, and reappear under new names, so a count is a snapshot rather than a fact.
What does it mean when a leak site is offline?
Usually less than people hope. Sites go down for infrastructure trouble, deliberate quiet periods, or a takedown — and many come back weeks later under the same name. We keep the group listed and record the status rather than deleting the entry.
Does a group appearing here mean it is currently active?
No. This is the full list of leak sites we track, including dormant and defunct ones. Filter to sites that are responding, or sort by recent activity, to see who is actually moving.
Where do the group descriptions come from?
Public reporting and vendor research, compiled per group. They describe how a crew has historically operated, so they can lag its current behaviour. Live status and timing come from our own checks.
Can I be told when a specific company appears on one of these sites?
Yes, and that is what SINON is for. You give it the names, domains and suppliers you care about, and it watches these sites and other sources for them continuously instead of you refreshing a page.
Find out before the countdown starts
This page tells you who is out there. SINON watches these same sites for your company, your domains and your suppliers, and tells you the moment one of them appears.