Update log

Entries are shown newest first. Each heading has a stable fragment identifier and may be linked directly.

Website Seizure Banner Archive introduced

The complete seized.fyi snapshot is now available as a separate documentary collection without a ransomware-only scope filter.

Dataset Complete snapshot
Imported every valid seized.fyi metadata record and affected-domain value in the current snapshot, including records unrelated to ransomware or existing threat actors.
Added Local media archive
Preserved supported originals locally, generated inert WebP previews, recorded SHA-256 hashes, and separated metadata-only records from locally archived media.
Added Routes and exports
Added a complete collection directory, static record pages, search, category, agency, year, domain, release routes, and per-record TXT, JSON, and CSV domain exports.
Added Search
Indexed seizure records as a separate Pagefind corpus with title, date, domains, media, category, official-publisher, actor, and archive-status metadata.
Security Untrusted media
Kept affected domains inert, prohibited hotlinks and active HTML, disabled autoplay, used static animation and video posters, and validated all local asset hashes and byte signatures.
Added Provenance and cross-links
Documented seized.fyi attribution and rights-review boundaries while limiting actor and lineage cross-links to explicit reviewed mappings.

Actor lineage and alias timeline introduced

Evidence-backed aliases, historical events, typed relationships, and explicit confidence labels now connect both archive corpora.

Added Actor lineage
Added a global lineage directory and reusable actor-page sections for aliases, timelines, predecessors, successors, overlaps, disruptions, and source-linked confidence notes.
Dataset Evidence records
Published 13 curated entities, 5 typed relationships, 25 timeline events, and 28 normalized sources without inferring relationships from name or malware similarity.
Added Cross-linking
Connected lineage context to negotiation records and explicitly mapped ransomware-note pages while retaining every original source label.
Dataset MITRE ATT&CK
Added an explicit mapping manifest and a locally synchronized ATT&CK 19.1 subset; software-name matches do not become group mappings.
Security Documentary media
Published 12 locally archived documentary visuals plus one universal neutral fallback image, with editorial rights review and fail-closed validation for attribution, hashes, hotlinks, unsafe formats, unsupported identity claims, and AI-generated images.
Added Validation
Added lineage, evidence, media, route, source-reference, Pagefind metadata, cross-link, and static-build checks.

Public changelog introduced

Site and dataset changes now have a permanent, searchable record inside extortion.wiki.

Added Infrastructure
Added a statically generated Updates and changelog page backed by a versioned, Zod-validated manifest.
Changed Navigation
Exposed the changelog through the desktop and mobile header, sidebar, footer, homepage, page tools, and sitemap.

Ransomware notes added as a first-class archive

ThreatLabz/ransomware_notes became a separate primary corpus alongside ransomware negotiations.

Dataset Ransomware notes
Imported 332 supported notes across 221 ransomware-family directories from pinned upstream commit 2bbf5b4ecda84837c4a71af1a99c6821920f051a.
Added Routes
Generated static archive, family, note-detail, and notes-only search routes from the normalized local snapshot.
Added Search
Indexed ransomware notes in Pagefind with corpus, family, filename, format, and archive-identifier metadata.
Added Cross-linking
Connected explicitly mapped ransomware-note families with matching threat actors and negotiation records without merging corpus statistics.
Security Document safety
Rendered original note bodies as escaped, selectable source text so archived HTML, scripts, forms, and remote resources cannot execute or load.
Added Validation
Added schema, path, encoding, hash, duplicate, route, attribution, search-metadata, and build validation for the notes snapshot.