Ransomware Leak Sites on Tor: How Extortion Blogs Became Criminal Infrastructure
Every serious ransomware operation now ships two products: an encryptor and an extortion blog. The leak site has become standard infrastructure, tracked daily by journalists, insurers, negotiators and researchers. Its uptime, more than any press release, reveals whether a crew is alive.
From encryptor to hostage photo
The era began in late 2019, when the Maze gang released nearly 700 MB of files stolen from security staffing firm Allied Universal after a missed deadline. Until then, crews had threatened to publish stolen data but never actually did. As Lawrence Abrams of BleepingComputer noted at the time, Maze was the first to carry the threat through in such a visible way (BleepingComputer). Days later, Maze stood up a public shaming page listing companies that refused to pay, complete with stolen documents as proof of compromise."Represented here companies dont wish to cooperate with us, and trying to hide our successful attack on their resources," the site announced.KrebsOnSecurity verified one listed victim and predicted the practice would spread fast. It did (KrebsOnSecurity).
Why the onion
Leak sites settled on Tor hidden services because onion addressing solves several problems at once. It conceals the hosting provider, keeps the operator anonymous, and lets a blog survive long after any clearnet domain would have been seized or sinkholed. Reachability matters just as much. A countdown timer only pressures victims if someone can actually see it, so groups publish their .onion addresses across forums, Telegram channels and mirror lists. Negotiation portals usually run on separate onion endpoints, keeping the whole pipeline off the open web.The shaming playbook
By 2021 the format had hardened into a template: a wall of victim logos, per-entry deadlines, sample file listings described as proofs, and staged photographs of stolen passports or client records. Researchers call them hostage photos for good reason. The imagery is chosen to make abstract data theft feel personal and immediate. The playbook keeps escalating. When unknown attackers hammered multiple leak sites with denial-of-service traffic in August 2022, Cisco Talos observed LockBit responding by advertising DDoS itself as a third extortion layer alongside encryption and leaks (Cisco Talos). Pressure tactics now routinely extend to regulator emails, phone calls and even direct harassment of executives.Downtime as signal
For analysts, outage patterns are intelligence. A University of Cambridge study tracking 176 groups between 2019 and 2025 treated leak site uptime as a proxy for organizational survival, finding that arrests, seizures and affiliate disputes all sharply shortened how long sites stayed live (talks.cam.ac.uk). The pattern repeats. In February 2024, Operation Cronos replaced LockBit's shaming pages with seizure banners and free decryption tools across 34 servers (KrebsOnSecurity). BlackSuit's blogs fell to Operation Checkmate in July 2025. Hunters International simply announced its closure and pivoted toward the extortion-only World Leaks project, which Recorded Future analyst Allan Liska read as cutting ties with old infrastructure before law enforcement arrived (TechCrunch). Reading the tea leaves takes experience:- Brief intermittent outages usually mean DDoS attacks or routine maintenance, not collapse.
- A long blackout with no new victim entries suggests a takedown, arrest wave or bitter affiliate dispute.
- Mirror churn plus a fresh name often signals a quiet rebrand rather than retirement.
- Sudden free decryption offers are rarely goodwill; they typically precede a pivot to a new brand.