35,563 ransomware posts.
Tracked in the open.

Open-source intelligence on 631 ransomware groups, markets and threat actors. Updated live since 2022.

Activity · last 30 days vs prev 7d ▼ -23.6%
2026-09-11 — 7 posts 2026-09-12 — 22 posts 2026-09-13 — 9 posts 2026-09-14 — 61 posts 2026-09-15 — 34 posts 2026-09-16 — 30 posts 2026-09-17 — 21 posts 2026-09-18 — 37 posts 2026-09-19 — 11 posts 2026-09-20 — 14 posts 2026-09-21 — 40 posts 2026-09-22 — 27 posts 2026-09-23 — 45 posts 2026-09-24 — 37 posts 2026-09-25 — 17 posts 2026-09-26 — 26 posts 2026-09-27 — 53 posts 2026-09-28 — 71 posts 2026-09-29 — 57 posts 2026-09-30 — 35 posts 2026-10-01 — 31 posts 2026-10-02 — 32 posts 2026-10-03 — 9 posts 2026-10-04 — 14 posts 2026-10-05 — 40 posts 2026-10-06 — 41 posts 2026-10-07 — 42 posts 2026-10-08 — 29 posts 2026-10-09 — 38 posts 2026-10-10 — 16 posts

This week

220
posts · last 7 days
▼ -23.6%
46
active groups
▼ -6.1%
2
new groups this week
NEW
The Gentlemen
top group
38 posts · 17.3%

Top movers

7d vs prev 7d

Latest posts

see more →
  • TEXMA International Co., Ltd Dragonforce
  • Royal Thai Air Force The Gentlemen
  • Helwan University (HITU) Umbra
  • Glenhardie Country Club Qilin
  • LD Constructora Qilin

Torrent intelligence

passive swarm scan · IP/ASN pivot · BEP-48 tracker scrape · webseed mirrors
1424
swarms tracked
268
alive
79
seeders total
1793
cross-group IPs
pivot signal
631 groups · 147 markets · 32 actors · 4769 leaks · 936 ransom notes · 11192 crypto addrs · 20 in-house analyses