721 victims in 30 days: what ransomware leak sites actually show
We crawl 25 active ransomware leak sites over Tor, once every night. Here is what we measured in one month: the numbers, the technical shape of the infrastructure, and why you will not read a single victim name in this post.
The numbers
When a ransomware group breaches an organisation and doesn't get paid, it publishes the victim's name on a dark-web leak site. That's the pressure mechanism: pay, or the data goes public. Those pages are public, which makes them countable.
721
victims published in 30 days
58
distinct groups active
23
new victims per day, on average
Twenty-three new victims a day, every day, from 58 groups operating in parallel. This is not a series of isolated incidents. It is an industry with throughput.
Who is publishing
Victims published per group, 25/06 – 25/07/2026.
Two groups account for 32% of all publications. The remaining 50+ share three quarters of the total, which is why watching one or two “famous” groups tells you almost nothing.
Technical analysis
Three things about this infrastructure that only show up if you crawl it yourself.
Every site is Tor v3
All 25 addresses we monitor are 56-character v3 onion services with ed25519 keys, no legacy v2 anywhere. v2 was deprecated in 2021 and the ecosystem has fully moved. The practical consequence: onion addresses are now long, self-authenticating public keys, so you cannot typo-squat or brute-force a plausible lookalike the way you could with 16-character v2.
Nearly half run mirrors
8 of 17 groups with live sites operate two separate onion services rather than one. That's deliberate redundancy against takedowns and DDoS from researchers and rivals. It also means a naive monitor that tracks “one URL per group” silently misses half the publications when the primary goes dark.
Most monitored sites sit still; a minority churn hard
Each time we crawl a site we hash the page and compare it to the last snapshot. Below is how many times each of the 31 monitored pages changed during the window.
42% of the pages we watch never changed content while we watched them, while 32% changed three or more times. Leak-site infrastructure is not uniformly “live”. A lot of it is parked or abandoned, and a small core does the actual publishing. Monitoring by site count overstates coverage; what matters is whether you are watching the ones that move.
And Greece?
Of the 721 victims published this month, one was a Greek entity. It was posted on 10 July 2026 by one of the two most active groups in the chart above.
“One in 721” is not a reason to relax. It is a single month, groups do not publish the victims who pay, and Greek SMEs rarely disclose incidents. The real figure is higher than the visible one.
How we measure it
First-party collection, not a resold third-party feed.
Every night, for every registered domain.
First-party collection
We fetch the pages of all 25 live leak sites ourselves and match their content against our customers' registered domains. We are not reading somebody else's feed and reselling the result.
Everything over Tor
No connection is ever made from our own address. We don't want to be fingerprinted on the groups' infrastructure, and we don't want to end up on blocklists ourselves.
Public content only
No registration, no login, no bypassing an access control, ever. A leak site's victim list is its public front page. If something is gated, we come back with nothing and log it.
Precision before volume
A registered domain appearing in leak-site content is a high-priority alert. A loose brand-term match stays informational. That distinction exists so a coincidence doesn't wake you at 3am.
What this means in practice
- Publication is the last stage, not the first. By the time your name reaches a leak site, the breach happened weeks ago. The value of monitoring isn't prevention; it's not learning about it from a customer or a journalist.
- Size does not protect you. Those 721 victims span every scale of organisation. These groups scan automatically; they don't pick targets for being important.
- Check what's exposed, not only what's breached. Most intrusions start with something predictable: a service exposed to the internet, a credential in a public repository, a lookalike domain impersonating yours.
- Have a written plan for day one. Who you call, who decides, what you tell customers. Organisations that thought about it in advance lose days. The rest lose weeks.
We monitor leak sites, lookalike domains and dark-web mentions for your own domains and brand, with evidence attached, not just alerts.
All figures come from our own monitoring, 25/06 – 25/07/2026. Live-site list: RansomLook (CC BY 4.0). We publish no victim names, no leaked data, and no leak-site addresses.