Leak sites: a field guide
What a leak-site post is and what its claims are actually worth
Key takeaways
- A leak-site listing is a claim, not a confirmation. Ransomware groups use leak sites as part of their extortion strategy, so defenders should seek corroborating evidence before treating a listing as proof of a breach.
- Leak sites provide useful threat intelligence, but they require context. They can reveal active threat groups, targeted industries and emerging campaigns, but listings may include exaggerated, recycled or unverified claims.
- Focus on trends and exposure, not raw victim counts. The most valuable insights come from identifying which sectors, vendors and organizations are being targeted and determining whether they present risk to your environment or supply chain.
| From the desk of the CISO is authored by Arve Kjoelen, Chief Information Security Officer (CISO) at Barracuda. It examines the strategic implications of emerging security trends — not just the technical mechanics behind them. It is written for IT and security leaders who need to understand what is changing, why it matters and where to focus next — often before there is clear industry consensus. |
Leak sites, the extortion portals where ransomware groups publish stolen data and publicly name their victims, deserve attention from every defender, whether that's a chief information security officer (CISO) with a full security operations center (SOC), a solo admin, or a managed service provider (MSP) juggling dozens of clients.
They tell us which groups are active, which sectors they're hunting, and how fast a quiet incident becomes a public data dump. Security leaders can use that signal to prioritize controls and brief the board on current rather than hypothetical risk. For lean IT shops, the sites can reveal a breached vendor or a campaign sweeping their industry, showing them exactly where to aim scarce resources.
MSPs have the most at stake, because they concentrate risk across many small businesses that attackers love to target, so spotting a client's name first is what separates a contained response from an after-the-fact breach notification.
The criminals built these sites to inflict pressure and publicity. Monitoring them turns that same machinery into free, early, and actionable intelligence.
What they are
A leak site, sometimes called a dedicated leak site (DLS), is the publication arm of a data-extortion operation. It is a website, almost always reachable only over the Tor network, where a ransomware or extortion group lists organizations it claims to have breached. A listing usually pairs the victim's name with a countdown timer, a handful of sample files, and a demand: pay, or the remaining data is published.
Two models dominate. In double extortion, attackers encrypt the victim's systems and threaten to publish stolen data, applying two forms of leverage at once. In data-theft-only extortion there is no encryption, and the entire threat is publication. Either way, the listing exists to apply pressure. It is a negotiating tactic, not a verified disclosure. Its presence on a leak site says more about the group's messaging than about the settled facts of any incident.
How a leak-site extortion operation works: the ransomware-as-a-service economy supplies the attack (top), and the listing on the leak site is the pressure that follows a refused ransom.
Who runs them
Most leak sites are one storefront for a ransomware-as-a-service business. A core operator maintains the ransomware, the negotiation portal and the leak-site brand, while affiliates carry out the intrusions and split the proceeds with the operator. That division of labor explains why a single brand can appear across wildly different victims, sectors and countries: many affiliates, one storefront.
The names turn over constantly. Groups splinter, rebrand after a law-enforcement takedown and occasionally vanish in exit scams that leave their own affiliates unpaid. A group that appears new is frequently a reconstituted old one under a fresh banner. Recent years have seen brands such as LockBit, ALPHV/BlackCat, Cl0p, Play, Akira, Qilin, RansomHub, Medusa, and 8Base, among many others. But the membership of any “most active” list changes from quarter to quarter. This site tracks these groups on its actors' pages; it does not link to their leak sites.
How reliable they are
The single most important thing to understand about a leak-site post is that it is a claim, not a confirmation. Several well-documented patterns inflate the picture:
- Recycled listings. A group may repost an old victim, or pad its list, to look active and capable.
- Name-variant double-counting. The same organization can appear more than once under slightly different names, which slips past simple de-duplication and inflates totals.
- Reputation-building. Newer or struggling groups exaggerate, claiming access they don't have or breaches that didn't happen, to attract affiliates and attention.
- Overstated access. A listing that reads like a catastrophic breach may reflect a minor foothold, third party data, or files of little consequence.
- Claims that are never substantiated. Some listed victims never have any data published at all.
Because of this, the only responsible way to read a listing is on a graded scale. A claim starts unconfirmed and earns credibility only when an independent source, the victim or a regulatory filing corroborates it. This site grades every such story on that ladder (Claimed, then Corroborated, then Confirmed), and it anchors its guidance on the facts that aren't in dispute, such as which product or which class of data is involved, rather than on the group's own telling.
How busy they are
In aggregate, leak-site listings run into the hundreds per month across all active sites, and the trend has risen over recent years as data-theft extortion has spread. But two things make raw totals unreliable. First, the roster of active sites is unstable; takedowns, rebrands and shutdowns churn it continuously. Second, for all the reasons above, the victim count systematically overstates reality.
The honest way to read an aggregate leak-site number is as an upper bound on activity, not a headcount of confirmed breaches. Direction and trend carry more signal than any single week's figure: whether extortion volume is rising, and which sectors are being named more often.
How to read them
For defenders, a few habits keep leak-site noise from becoming leak-site panic:
- Don't escalate on a listing alone. A post is a reason to check, not a reason to declare an incident.
- Treat it as a supply chain signal. Often the most actionable question a listing raises is, “is this organization in my supply chain?” rather than “did this exact breach happen as described?”
- Watch the confirmation rate, not the claim volume. A group that posts constantly but rarely follows through is louder, not necessarily more dangerous. The signal is in what gets corroborated over time.
Leak sites are built to be loud. Reading them well means separating the messaging from the facts, which is exactly what confidence grading, corroboration and a healthy skepticism about counts are for.
About this piece: We describe the leak-site ecosystem to help defenders read it; we do not link to leak sites or name individual victims. Group names are given only as they are commonly tracked in public reporting.
2026 Email Threats Report
Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected
Subscribe to the Barracuda Blog.
Sign up to receive threat spotlights, industry commentary, and more.
The Managed XDR Global Threat Report
Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit