Work Expertise Process About Notes Contact on LinkedIn

Note

“We’re on a ransomware leak site”

Someone in the company saw a blog on Tor. Your name is on it. There is a countdown, or a “files coming,” or a zip that will not open. Legal wants to know if this is a disclosure event. Comms wants to know if this is a journalist event. The CEO wants to know if it is already out.

A leak-site listing is a claim. What was published — if anything — is a different fact.

Listings lie in boring ways

Ransomware blogs copy each other. Affiliates recycle victim names. A screenshot of a post is not the post. A post is not a file. A file named Company_HR.zip is not your HR drive until you have hashed it, opened it in a lab, and found something that could only have come from you.

Empty indexes happen. “Coming soon” happens. A group that never had access will still put a logo on a page because the page is the shakedown. The press will still screenshot the logo.

The other failure mode is the opposite: the listing is thin and the archive is huge. Nobody on the incident call has pulled the archive, because pulling it feels like negotiating. So the room argues about the blog post while the actual zip sits on a mirror.

What “we were named” does not tell you

It does not tell you they had a foothold. It does not tell you they exfiltrated. It does not tell you what to notify, or whom.

It tells you someone wanted you to think those things, on a deadline, in public.

If your IR firm is already in the tenant, they should be asking for the files, not for a briefing on the group’s Twitter. If nobody has the files, you do not have a leak assessment. You have a press clip.

The pass that actually changes the decision

Get the listing, intact. Group, date, URL, any ID they assigned you. Note whether there is a download or only a paragraph.

Get the object, if there is one. Isolated fetch. Hash. Do not open it on a laptop that also has Outlook. If there is no object, say that out loud. “Named, no dump” is a real state. It is not the same as “named, 400 GB.”

Look for you, not for drama. Internal hostnames, mailbox formats, badge photos, a contract number, a SharePoint URL. Commodity OSINT about your company is not proof of access. A unique file that never left the building is.

Size is not the story. “2 TB” on a leak blog is a marketing number. Row counts, file types, and whether the archive is complete are the story. A 40 GB pack of someone’s old file server is not “the crown jewels” because a countdown clock said so.

Name collisions. Another company with your trade name. A subsidiary you sold. A vendor that stored your data and got hit, so you appear as a folder, not as the victim. That last one is how people notify the wrong regulator.

What not to do

Do not pay from the listing page to “see the sample.” The sample is the rest of the shakedown.

Do not have a well-meaning analyst browse the blog from the corporate Wi-Fi and call that collection.

Do not let “we monitor leak sites” stand in for “we read this dump.” Monitoring tells you that a name appeared. Reading tells you whether the name earned it.

I do this work from the outside. No agent, no tenant admin, no need to pretend the blog post is the incident. If you are on a ransomware leak site today, the only question that matters in the first hour is: is there a file, and is it yours.

Until you can answer that, you are reacting to a webpage.

Cite: Fabio Correia, ““We’re on a ransomware leak site””, 2026-09-17. https://www.fabiocti.com/notes/ransomware-leak-site-listing/. Markdown: https://www.fabiocti.com/notes/ransomware-leak-site-listing.md

Comments

Public thread on the canonical URL. GitHub login keeps this off a spam hole; replies are copied here on the next build so crawlers and models see them in the HTML.

No public replies yet.

Add a comment
All notes