Key Takeaways
- Ransomware.live aggregates victim claims, group activity, indicators, ransom notes, and other intelligence for defenders tracking extortion campaigns.
- Claim-based monitoring provides an early view of ransomware activity, but criminal posts are not independently verified incident records.
- Rising victim claims alongside fluctuating payments suggest that attack volume and criminal revenue are moving along different paths.
Ransomware.live has updated its ransomware intelligence data as security teams continue to grapple with a basic visibility problem: no single reporting channel captures the full scale of digital extortion.
The service brings together victim listings, ransomware-group profiles, statistics, geographic data, and press coverage. Its intelligence sections also cover negotiations, ransom notes, YARA rules, indicators of compromise, and API access. That combination makes Ransomware.live more than a running list of breached businesses. It functions as an open-source collection point for analysts trying to identify changes in targeting, group behavior, and campaign tempo.
Claim volume shows why such tracking attracts attention. An Emsisoft review counted 8,159 claimed victims in Ransomware.live during 2025. Emsisoft also cautioned that claim-based figures likely understate total ransomware activity because many incidents are not disclosed publicly or posted to leak sites.
There is another caveat. A listing is an allegation made by a criminal operation, not confirmation that encryption occurred, sensitive information was stolen, or a ransom was paid. Some groups exaggerate access, repost older victims, or name businesses while negotiations are still unfolding. Duplicate listings can also appear when affiliates move between ransomware brands.
Still, these feeds have operational value. What other near-real-time source shows which sectors multiple extortion groups are naming this week? Defenders can compare new entries against their supplier base, geographic exposure, and industry peers. Incident-response teams can examine associated ransom notes and indicators, while researchers can use the API to enrich internal datasets.
The public numbers do not move in lockstep. A Varonis ransomware statistics roundup cites 3,156 ransomware complaints received by the FBI's IC3 for 2024, an 11.7% increase from the prior year. The same research context points to a Chainalysis estimate that ransomware gangs collected about $813.5 million in 2024, down 35% from the record $1.25 billion recorded in 2023 (source).
In other words, more reported incidents do not automatically mean more money reaching attackers. Payment resistance, law-enforcement disruption, sanctions exposure, and better recovery capabilities can affect revenue even when extortion attempts remain frequent. Criminal groups may respond by increasing victim volume, shortening negotiation windows, or relying more heavily on data-theft pressure.
Organizations should avoid treating any one counter as the definitive ransomware total. Leak-site claims, law-enforcement complaints, insurance cases, and blockchain payment estimates measure different parts of the problem. Ransomware.live-style data is most useful when combined with endpoint telemetry, identity logs, vulnerability information, and trusted industry-sharing channels.
Security teams can organize that work through the NIST Cybersecurity Framework, mapping external intelligence to governance, identification, protection, detection, response, and recovery activities. A new victim claim involving a close supplier, for example, could prompt exposure checks, credential reviews, and closer monitoring rather than immediate assumptions about compromise.
Analysts can also map observed behavior to MITRE ATT&CK. Indicators frequently change, but techniques such as credential theft, remote-service abuse, data staging, and backup interference can remain useful for detection engineering. This shifts attention from a criminal group's branding to the activity defenders may actually observe.
That said, speed still matters. Leak-site monitoring can provide warning before traditional disclosures reach customers, regulators, or business partners. Procurement, legal, communications, and security leaders can use that signal to begin measured checks and prepare questions for affected suppliers.
Ransomware.live therefore provides a useful, if imperfect, open-source repository for defenders tracking extortion campaigns. Its updated data can help enterprises spot patterns and prioritize investigation, provided criminal claims are treated as leads rather than established facts. The distinction sounds small. During a fast-moving extortion event, it can shape every decision that follows.
⬇️