you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 18 min ago 255 onions tracked
home / news / market watch
27 January 2026 market watch 4 min read

Ransomware Leak Sites on Tor: How Extortion Blogs Became Criminal Infrastructure

Every serious ransomware operation now ships two products: an encryptor and an extortion blog. The leak site has become standard infrastructure, tracked daily by journalists, insurers, negotiators and researchers. Its uptime, more than any press release, reveals whether a crew is alive.

From encryptor to hostage photo

The era began in late 2019, when the Maze gang released nearly 700 MB of files stolen from security staffing firm Allied Universal after a missed deadline. Until then, crews had threatened to publish stolen data but never actually did. As Lawrence Abrams of BleepingComputer noted at the time, Maze was the first to carry the threat through in such a visible way (BleepingComputer). Days later, Maze stood up a public shaming page listing companies that refused to pay, complete with stolen documents as proof of compromise.
"Represented here companies dont wish to cooperate with us, and trying to hide our successful attack on their resources," the site announced.
KrebsOnSecurity verified one listed victim and predicted the practice would spread fast. It did (KrebsOnSecurity).

Why the onion

Leak sites settled on Tor hidden services because onion addressing solves several problems at once. It conceals the hosting provider, keeps the operator anonymous, and lets a blog survive long after any clearnet domain would have been seized or sinkholed. Reachability matters just as much. A countdown timer only pressures victims if someone can actually see it, so groups publish their .onion addresses across forums, Telegram channels and mirror lists. Negotiation portals usually run on separate onion endpoints, keeping the whole pipeline off the open web.

The shaming playbook

By 2021 the format had hardened into a template: a wall of victim logos, per-entry deadlines, sample file listings described as proofs, and staged photographs of stolen passports or client records. Researchers call them hostage photos for good reason. The imagery is chosen to make abstract data theft feel personal and immediate. The playbook keeps escalating. When unknown attackers hammered multiple leak sites with denial-of-service traffic in August 2022, Cisco Talos observed LockBit responding by advertising DDoS itself as a third extortion layer alongside encryption and leaks (Cisco Talos). Pressure tactics now routinely extend to regulator emails, phone calls and even direct harassment of executives.

Downtime as signal

For analysts, outage patterns are intelligence. A University of Cambridge study tracking 176 groups between 2019 and 2025 treated leak site uptime as a proxy for organizational survival, finding that arrests, seizures and affiliate disputes all sharply shortened how long sites stayed live (talks.cam.ac.uk). The pattern repeats. In February 2024, Operation Cronos replaced LockBit's shaming pages with seizure banners and free decryption tools across 34 servers (KrebsOnSecurity). BlackSuit's blogs fell to Operation Checkmate in July 2025. Hunters International simply announced its closure and pivoted toward the extortion-only World Leaks project, which Recorded Future analyst Allan Liska read as cutting ties with old infrastructure before law enforcement arrived (TechCrunch). Reading the tea leaves takes experience:
  • Brief intermittent outages usually mean DDoS attacks or routine maintenance, not collapse.
  • A long blackout with no new victim entries suggests a takedown, arrest wave or bitter affiliate dispute.
  • Mirror churn plus a fresh name often signals a quiet rebrand rather than retirement.
  • Sudden free decryption offers are rarely goodwill; they typically precede a pivot to a new brand.

Watching the watchers

None of this means the leak site is going away. Coveware's casework found data exfiltration in 76 percent of incidents during Q3 2025, even as overall payment rates sank to a record-low 23 percent (Coveware). Weaker conversion pushes crews toward louder public shaming, not quieter operations. That makes continuous monitoring worthwhile for defenders and curious readers alike. Our status checker tracks the availability of major onion endpoints in near real time, and our tor network notes cover the infrastructure shifts behind the headlines. The blogs are hostages' windows. Learn to read the blinds.

more notes

all news ›