Ransomware leak site
A ransomware leak site is a site, usually reachable over Tor, where an extortion group publishes the names of victims who have not paid and releases the data it claims to have stolen. It is the publication half of double extortion: encryption creates the outage, the site creates the deadline.
Publication is staged deliberately. A victim is first listed by name with a countdown, then a small sample appears, then the full set. Each step is designed to move the decision from a technical team to a board, because the second stage is no longer an availability problem: it is a disclosure that customers, regulators and journalists can read at the same time as the victim.
For an organisation with a data protection obligation the appearance of a sample changes the clock. It is evidence that personal data left the estate, which is what the notification duty turns on, and it is public. Deciding whether to notify while the sample sits online is a materially different conversation from deciding while exfiltration is only suspected.
Two things are worth saying plainly because they are commonly assumed away. Payment buys a promise of deletion and nothing more, and the same data has been re-listed by successor groups afterwards. And the sites are also intelligence: they are where a supplier’s breach becomes visible before any notification arrives. Watching them for a client’s own name, and for their suppliers, is the practical part of dark web work and the reason ransomware exposure is monitored externally, which is what the dark web monitoring that watches these sites for a client’s own name does.