extortion.wiki
From extortion.wiki, the ransomware documentary archive
Ransomware and Enforcement Documentary Archive
Archive introduction
extortion.wiki contains two ransomware-focused primary-source corpora—documented negotiations and archived ransom notes—plus evidence-backed actor lineage and a broader documentary collection of website seizure banners. Every collection retains separate provenance, routes, search filters, and statistics.
Records are presented in normalized static documents. Claims remain claims, URLs remain inert, and inconsistent source data is documented rather than quietly transformed into confidence.
Search the archive
The query runs locally against the static Pagefind index. Nobody receives your search, including us.
Negotiation archive overview
| Threat actors | 26 | Negotiations | 242 |
|---|---|---|---|
| Messages | 11,480 | Dated records | 172 |
| Earliest dated record | Aug 11, 2020 | Latest dated record | Feb 25, 2026 |
| Source dataset | Casualtek/Ransomchats | Dataset snapshot | Jul 6, 2026, 1:18 PM |
| Validation status | Validated at build | Normalization issues | 34 |
Recently indexed records
Browse all records| Participants | Source | Archive status | ||||
|---|---|---|---|---|---|---|
| Nightspire | 20260225 | 48 | Nightspire, Victim | JSON | Indexed | |
| Nightspire | 20260217 | 31 | Nightspire, Victim | JSON | Indexed | |
| Nightspire | 20260203 | 45 | Nightspire, Victim | JSON | Indexed | |
| Nightspire | 20260127 | 62 | Nightspire, Victim | JSON | Indexed | |
| Nightspire | 20251218 | 84 | Nightspire, Victim | JSON | Indexed | |
| Pear | 20250720 | 42 | PEAR, Victim | JSON | Indexed | |
| kairos | 20250519 | 41 | Kairos, victim | JSON | Indexed | |
| Nightspire | 20250428 | 59 | Nightspire, Victim | JSON | Indexed | |
| Akira | 20250423 | 6 | Akira, Victim | JSON | Indexed | |
| Akira | 20250425b | 15 | Akira, Victim | JSON | Indexed | |
| Akira | 20250424 | 12 | Akira, Victim | JSON | Indexed | |
| Akira | 20250423 | 65 | Akira, Victim | JSON | Indexed |
Threat actor index
Browse directory and statisticsA
B
- Babuk (2 records)
- BlackBasta (5 records)
- BlackMatter (2 records)
C
D
- Darkside (5 records)
- Dragonforce (14 records)
F
- fog (6 records)
H
- Hive (8 records)
- Hunters International (1 records)
K
- kairos (1 records)
L
- lockbit3.0 (42 records)
M
- Mallox (3 records)
- mount-locker (1 records)
N
- Nightspire (7 records)
- NoEscape (2 records)
P
- Pear (1 records)
Q
- Qilin (2 records)
R
- RansomHub (1 records)
- Ranzy (2 records)
- REvil (20 records)
- RunSomeWares (1 records)
T
- trinity (14 records)
Archive notices
Methodology
Zod validates the JSON during the static Astro build. Message order and line breaks survive; locations written inside transcripts remain inert. The input remains JSON, including when it behaves more like a suggestion. Read the methodology.
Known limitations
The corpus is selective, some dates come from filenames, and actor labels reproduce upstream classifications. Counts describe this snapshot, not ransomware prevalence. Software remains unable to repair missing history through confidence.
Dataset attribution
Negotiations come from Casualtek/Ransomchats; ransomware notes come from Zscaler ThreatLabz; seizure-banner metadata comes from seized.fyi. Source records, snapshots, licenses, and rights-review boundaries remain visible, and their statistics are never combined.
Legal use
Use this material only for legitimate journalism, scholarship, defensive security, and public-interest research. Review the handling notice.