Update log
Entries are shown newest first. Each heading has a stable fragment identifier and may be linked directly.
Website Seizure Banner Archive introduced
The complete seized.fyi snapshot is now available as a separate documentary collection without a ransomware-only scope filter.
- Dataset Complete snapshot
- Imported every valid seized.fyi metadata record and affected-domain value in the current snapshot, including records unrelated to ransomware or existing threat actors.
- Added Local media archive
- Preserved supported originals locally, generated inert WebP previews, recorded SHA-256 hashes, and separated metadata-only records from locally archived media.
- Added Routes and exports
- Added a complete collection directory, static record pages, search, category, agency, year, domain, release routes, and per-record TXT, JSON, and CSV domain exports.
- Added Search
- Indexed seizure records as a separate Pagefind corpus with title, date, domains, media, category, official-publisher, actor, and archive-status metadata.
- Security Untrusted media
- Kept affected domains inert, prohibited hotlinks and active HTML, disabled autoplay, used static animation and video posters, and validated all local asset hashes and byte signatures.
- Added Provenance and cross-links
- Documented seized.fyi attribution and rights-review boundaries while limiting actor and lineage cross-links to explicit reviewed mappings.
Actor lineage and alias timeline introduced
Evidence-backed aliases, historical events, typed relationships, and explicit confidence labels now connect both archive corpora.
- Added Actor lineage
- Added a global lineage directory and reusable actor-page sections for aliases, timelines, predecessors, successors, overlaps, disruptions, and source-linked confidence notes.
- Dataset Evidence records
- Published 13 curated entities, 5 typed relationships, 25 timeline events, and 28 normalized sources without inferring relationships from name or malware similarity.
- Added Cross-linking
- Connected lineage context to negotiation records and explicitly mapped ransomware-note pages while retaining every original source label.
- Dataset MITRE ATT&CK
- Added an explicit mapping manifest and a locally synchronized ATT&CK 19.1 subset; software-name matches do not become group mappings.
- Security Documentary media
- Published 12 locally archived documentary visuals plus one universal neutral fallback image, with editorial rights review and fail-closed validation for attribution, hashes, hotlinks, unsafe formats, unsupported identity claims, and AI-generated images.
- Added Validation
- Added lineage, evidence, media, route, source-reference, Pagefind metadata, cross-link, and static-build checks.
Public changelog introduced
Site and dataset changes now have a permanent, searchable record inside extortion.wiki.
- Added Infrastructure
- Added a statically generated Updates and changelog page backed by a versioned, Zod-validated manifest.
- Changed Navigation
- Exposed the changelog through the desktop and mobile header, sidebar, footer, homepage, page tools, and sitemap.
Ransomware notes added as a first-class archive
ThreatLabz/ransomware_notes became a separate primary corpus alongside ransomware negotiations.
- Dataset Ransomware notes
- Imported 332 supported notes across 221 ransomware-family directories from pinned upstream commit 2bbf5b4ecda84837c4a71af1a99c6821920f051a.
- Added Routes
- Generated static archive, family, note-detail, and notes-only search routes from the normalized local snapshot.
- Added Search
- Indexed ransomware notes in Pagefind with corpus, family, filename, format, and archive-identifier metadata.
- Added Cross-linking
- Connected explicitly mapped ransomware-note families with matching threat actors and negotiation records without merging corpus statistics.
- Security Document safety
- Rendered original note bodies as escaped, selectable source text so archived HTML, scripts, forms, and remote resources cannot execute or load.
- Added Validation
- Added schema, path, encoding, hash, duplicate, route, attribution, search-metadata, and build validation for the notes snapshot.