Headlines and short excerpts only; every click lands on the original publisher, and the per-source cap keeps one busy newsroom from drowning out a quiet research blog. The same stream is the subscribe feed above: cybersecurity-feed.xml.
These are criminal claims, not confirmed breaches
Every entry is a claim made by a criminal extortion group on its own leak site. Groups exaggerate, recycle old breaches, and sometimes name victims they never touched. Nothing here is verified. Data is collected by the ransomware.live project; victim names link to its research pages. This tracker has its own feed: feed.xml.
Loading the latest claims…
Get alerted if your org shows up
Leave an email address and up to five watch terms (organization names or domains, comma-separated). If a new claim matches, you get an email within the hour.
Double opt-in; unsubscribing deletes everything immediately. This is the one feature on this site that stores anything server-side; details in the privacy policy.
Would your org be ready?
Watching the feed is the easy part. The ransomware readiness assessment walks through the controls that decide whether a claim like these becomes your bad week.