Key Takeaways
  • Maze ransomware launched the first dedicated leak site in December 2019. Since then, the number of DLSs has grown by 57% (to 44 sites), with data from 2,886 victim organizations published in a single 12-month window, according to Group-IB’s Hi-Tech Crime Trends report.
  • Every day, stolen data from at least 8 companies appears on DLSs, but this accounts for only 10% of all ransomware victims. The majority of attacks never surface publicly because victims agree to pay ransoms to prevent data from being leaked.
  • Group-IB Threat Intelligence monitors dark web sources and DLS activity in real time, giving security teams early warning when their organization’s data appears. Once it does, Digital Risk Protection executes takedowns.

What is a Dedicated Leak Site (DLS)?

A dedicated leak site (DLS) is a website where ransomware groups publish stolen data belonging to victims who refuse to pay the ransom. Groups use DLSs to execute double extortion: encrypt the victim’s files, exfiltrate the data, and then threaten to publicly release it unless the ransom is paid.

DLSs operate on the Tor network via .onion domains and are publicly accessible within Tor. 

Visibility is the point. An organization’s appearance on a DLS exposes sensitive data, including login credentials, intellectual property, financial records, and personal information, thereby triggering reputational, regulatory, and legal consequences, regardless of whether the full dataset is ever released.

The First Dedicated Leak Sites: Snatch and Maze

Maze ransomware launched the first dedicated leak site in December 2019, using it to publish stolen data from victims who refused to pay and helping establish double extortion as standard ransomware practice: encrypt the victim’s files, exfiltrate the data, then threaten public release unless the ransom is paid.

The Clop ransomware leak site followed shortly after. FIN11 (also known as TA505), the group behind Clop, exploited zero-day vulnerabilities in Accellion’s File Transfer Appliance starting in December 2020 and published stolen victim data on the Clop ransomware leak site. Data from some of those attacks remained publicly accessible years after the initial breach.

Ransomware operators typically publish a small sample of stolen data first to demonstrate scope, then threaten full release. Even when victims pay, deletion is not guaranteed. Links to compromised files have remained accessible after ransoms were met.

Since Snatch and Maze introduced the model, the number of dedicated leak sites has grown continuously, increasing by 57% in a single reporting period, according to Group-IB’s Hi-Tech Crime Trends 2022/2023 report.

Anatomy of a Dedicated Leak Site (How DLS Platforms Operate)

A dedicated leak site has two distinct layers: a public-facing victim listing and a backend affiliate panel. Together, they form an extortion infrastructure. One side applies public pressure on the victim, and the other lets affiliates manage the operation end-to-end.

Both layers run on the Tor network via .onion domains, which makes the infrastructure difficult to take down and the operators difficult to attribute.

The public side is where ransomware operators apply pressure. Victim organizations are listed by name, often with their industry and revenue data, and a sample of stolen files is posted as proof. Some groups add a countdown timer that displays when the full dataset will be released if the ransom goes unpaid. The weapon is the listing itself; the mere presence of a victim on a DLS causes reputational harm even if the exfiltrated data remains unreleased.

The backend panel is where affiliates manage the operation. Group-IB’s analysis of Qilin’s admin panel revealed how sophisticated this infrastructure has become. The panel is divided into dedicated sections:

  • Targets: victim details, ransom amount, payment deadline, company revenue pulled from sources like Zoominfo, and the content of the ransom note.
  • Blogs: where affiliates create and publish posts about non-paying victims.
  • Payments: affiliate wallet balances, transaction history, and revenue splits.
  • Stuffers: team account management and access controls.
  • FAQs: operational documentation for affiliates covering infection types, targeting guidance, and malware usage.

RansomHub’s DLS panel follows a similar model. Each victim gets a separate onion domain. The panel logs target access times, supports negotiation chat rooms, and allows affiliates to create private proof-of-breach pages before going public. 

Group-IB observed single data transfers exceeding 150 GB being staged for publication through these panels.

Affiliates earn between 80% and 90% of every ransom paid. Qilin ransomware pays 80% for payments under $3 million and 85% for payments above it. RansomHub offers a flat 90%. The DLS panel exists to maximize collection: it documents the breach, automates pressure, and tracks payment in one place.

The Recent Surge in Dedicated Leak Sites

The number of dedicated leak sites grew by 57% in a single reporting period, reaching 44 active sites in H2 2021–H1 2022, according to Group-IB’s Hi-Tech Crime Trends 2022/2023 report

Data belonging to 2,886 victim organizations was published across those sites, reflecting a 22% increase from the previous period. Every day, stolen data from at least eight companies appears on DLSs, which account for only 10% of all ransomware victims.

LockBit, Conti, and Hive drove the majority of this activity. The three groups accounted for more than 50% of all data published on DLSs during the period.

The growth continued even as Ransomware-as-a-Service (RaaS) affiliate programs contracted. Ransomware operators ran DLS infrastructure independently, without relying on affiliate networks to identify targets or deploy malware. The DLS model had become self-sustaining.

Two additional uses have emerged beyond the core double-extortion model. When victims refuse to pay and do not engage in negotiation, some groups sell the stolen data directly through their DLS rather than releasing it for free. This has occurred in documented cases, though it has not yet become standard practice. 

Groups also use DLS publications to extract a second round of leverage: personal data posted on a DLS can be weaponized to launch targeted phishing or fraud campaigns against the individuals named in the leak, compounding the damage beyond the initial breach.

Group-IB Threat Intelligence monitors dark web sources and DLS infrastructure in real time, providing security teams with early warning when their organization’s data is being staged for publication.

Dark Web vs Dedicated Leak Sites: Key Differences

Dedicated leak sites and the dark web are not the same thing, though DLSs run on the Tor network. The dark web is a broad ecosystem of underground forums, marketplaces, and criminal communities. A DLS is a single-purpose extortion tool, built and operated by one ransomware group to apply pressure on a specific set of victims. 

The table below summarizes the key differences.

Feature Dark Web Forums and Markets Dedicated Leak Sites
Purpose Buy, sell, and trade stolen data, access, and tools Publish victim data as extortion leverage
Operator Multi-party marketplace with many sellers and buyers Single ransomware group or their affiliates
Audience Cybercriminals seeking to purchase access or data Victims, their clients, the media, and the public
Access Often requires registration, vetting, or invitation Publicly accessible within Tor — visibility is the point
Content Compromised credentials, network access listings, malware Victim organization data, proof-of-breach samples, ransom demands
Monetization Direct sale of stolen assets Ransom payment in exchange for non-release
Persistence Forums can operate for years across multiple operators Tied to a specific group; goes offline when the group is disrupted

Dark web forums are where ransomware groups recruit affiliates, purchase initial access from brokers, and occasionally sell data when victims refuse to engage. A DLS is where they execute the final stage of that chain, turning exfiltrated data into public leverage. 

Group-IB identified 58 DLSs in active use during H2 2021–H1 2022, each tied to a specific ransomware operator.

The two ecosystems do intersect. When victims neither pay nor respond, some groups move stolen data from their DLS to underground markets for direct sale. At that point, the extortion model has failed, and the data becomes a commodity. But that is the exception. The primary function of a DLS is pressure, not profit from data sales.

What Are the Types of Data Found on a DLS?

Ransomware groups publish whatever gives them the most leverage, typically data sensitive enough to cause reputational, financial, or legal damage if made public. 

Three categories appear most frequently:

1. Credentials: Attackers can cause significant damage with credentials, gaining access to systems, data, and resources they are not authorized to use. Offenders can penetrate deeper into a company’s infrastructure using stolen data, causing irreparable damage or even withdrawing business-owned information or funds.

2. Payment methods: This cyber risk usually concerns the banking sector. Payment method information can be a valuable target for attackers, as it can be used for financial gain. When obtaining the bank customers’ card data, the attackers may demand a ransom and, if it’s not paid, put all the data on their DLS for public access.

3. Access: Even if all attention is focused on keeping the data secure, there is always a chance that an attacker will use third-party vendors connected to the targeted infrastructure to gain access.  Needless to say, once attackers gain access to your infrastructure, they can carry out a wide range of malicious activities that can cause significant damage to your organization.

What Is the Compromised Data Used For?

Data that appears on a dedicated leak site has already served one purpose: forcing the victim to pay. But ransomware groups extract value from stolen data at multiple stages, not just during the ransom negotiation.

Ransomware operators typically leverage exfiltrated information in four primary ways:

1. Ransom calibration

Before issuing a demand, attackers analyze the exfiltrated data to accurately size the ransom. RansomHub affiliates cross-reference stolen financial records with publicly available revenue data to determine what a victim can pay. A $50 million ransom demand is not arbitrary, but reflects what the attackers found inside the network.

2. Credential reuse

Stolen credentials published on a DLS do not expire when the original breach ends. Other threat actors collect them and use them to target the same organization again or to attack partners and suppliers who share authentication infrastructure.

3. Data sales

When victims refuse to pay and do not engage in negotiation, some groups sell the exfiltrated data on dark web forums rather than releasing it publicly. At that point, the data becomes a commodity, traded independently of the original attack.

4. Secondary targeting

Personal data published on a DLS, such as employee records, customer details, and executive contact information, gives other attackers the material to launch follow-on phishing, fraud, or social engineering campaigns against the individuals named in the leak.

The breach does not end when the ransom deadline passes. For organizations whose data has been published, the exposure compounds over time.

Most-Used Methods: How Do Attackers Gain Unauthorized Access

Ransomware groups reach their victims through a small number of repeatable techniques. Phishing, stolen credentials, and exploitation of vulnerabilities account for the majority of initial access events documented by Group-IB. Physical access is rare enough to be negligible in the ransomware context.

1. Phishing

Attackers send emails impersonating organizations or individuals the victim trusts. Qilin affiliates use spear phishing emails with malicious links as a primary entry point. According to Group-IB research, 80% of ransomware cases begin with corporate email as the initial access vector.

2. Compromised credentials and RDP

Ransomware operators increasingly skip the early stages of an attack by purchasing pre-compromised access from Initial Access Brokers (IABs) on dark web forums. Group-IB detected 2,348 corporate access listings for sale in H2 2021–H1 2022, which is nearly double the previous period. RDP and VPN credentials account for the majority of what IABs sell. 

RansomHub affiliates, for example, typically enter via a publicly exposed RDP service on a Windows server without multi-factor authentication, using accounts sourced from stealers such as LummaC2.

3. Vulnerability exploitation

Unpatched software gives attackers a direct path into the network. EstateRansomware exploited CVE-2023-27532, a known vulnerability in Veeam Backup & Replication, to gain access to backup infrastructure, despite the patch having been available for over a year. Qilin similarly targets unpatched VPN appliances and RDP interfaces as initial access vectors.

4. Third-party and vendor access

Attackers also pivot through trusted third parties connected to the target network. Once inside a vendor’s environment, they use that trusted relationship to reach the primary target without triggering perimeter defenses.

Which Entities Are Most Affected by a Data Breach?

Data published on a dedicated leak site typically affects three categories of victims: government bodies, businesses, and individuals. Each faces a different type of damage, and in most cases, the exposure compounds over time.

1. Government

For public-sector organizations, a DLS publication can expose information with national security implications. This includes details of military operations, access credentials for critical infrastructure, and internal communications between government agencies. The damage extends beyond the organization itself.

It also includes citizens whose personal data is held by government systems that are exposed. Group-IB recorded 105 government and military organizations as victims of DLS in H2 2021–H1 2022.

2. Businesses

For companies, the consequences are financial, reputational, and legal. Attackers frequently exfiltrate customer data, and once that appears on a DLS, the reputational damage reaches both current and prospective clients.

Regulatory exposure compounds the financial impact: organizations operating under data protection frameworks face potential fines in addition to remediation costs. Transportation, financial services, and healthcare were the three most targeted industries in H2 2021–H1 2022, according to Group-IB’s Hi-Tech Crime Trends 2022/2023 report.

3. Individuals

Employees, customers, and executives named in a leak face direct personal exposure. The most commonly published personal data includes identification details, addresses, and billing information. This data feeds follow-on attacks: phishing campaigns, fraud, and social engineering targeting the individuals named in the breach. Unlike a corporate breach, an individual has no legal team, no IR retainer, and no takedown capability.

Industry-Wise Breakdown of DLS Attack Targets

Manufacturing and real estate are the most frequently targeted industries, together accounting for over 20% of all ransomware victims whose data appeared on DLSs in H2 2021–H1 2022, according to Group-IB’s Hi-Tech Crime Trends 2022/2023 report.

While no industry is off-limits, ransomware groups tend to concentrate on sectors where operational disruption creates maximum pressure to pay quickly and where the data held causes serious damage if published.

Industry Victims on DLSs 
Manufacturing 295
Real estate 291
Professional services 226
Transportation 224
Financial services 181
Healthcare 144
Information technology 120
Education 116
Government and military 105
Food and beverage 104

Source: Group-IB Hi-Tech Crime Trends 2022/2023 report

Manufacturing and transportation organizations run operational technology environments where downtime costs money immediately. Ransomware operators know that a plant that cannot produce or a logistics company that cannot move freight faces pressure to pay quickly, regardless of what data attackers exfiltrated.

Healthcare and education institutions hold large volumes of personal and regulated data. A DLS publication exposes patient records, student information, and research data, triggering both reputational damage and regulatory scrutiny. Qilin prioritizes healthcare specifically because the sensitivity of the data and the cost of regulatory exposure make victims more likely to pay.

Financial services and professional services firms hold client financial data and privileged communications. Publication directly threatens client relationships, creating pressure that extends beyond the organization itself.

Geographically, the United States accounted for 1,237 of the 2,886 victims documented during the period, representing 43% of the global total, followed by Germany (147), the UK (128), and Canada (128).

Real-World Case Studies of Major DLS Attacks

The following cases illustrate how ransomware groups build and weaponize dedicated leak sites across different operational models, from established RaaS programs to emerging groups exploiting unpatched vulnerabilities.

BlackMatter (2021)

BlackMatter ransomware emerged in July 2021, two weeks after REvil’s infrastructure went offline. Group-IB analysis of BlackMatter samples confirmed direct technical overlap with both DarkSide and REvil, including identical encryption algorithms (Salsa20 and RSA-1024) and shared obfuscation techniques, suggesting the same development team continued operations under a new name.

BlackMatter targeted Windows and Linux environments, including ESXi servers, and operated its own DLS to publish victim data. Its first documented victim was a US architecture firm. When the ransom deadline passed without payment, BlackMatter increased the demand rather than negotiating down. The group shut down in November 2021 following law enforcement pressure, but its infrastructure and affiliates fed directly into successor groups.

Qilin (2022-2023)

Qilin ransomware operates as a RaaS program using ransomware written in Rust and Go, targeting companies in critical sectors including healthcare, financial services, and energy. The group runs a proprietary DLS listing victims by company ID with leaked account details and exfiltrated files published as proof of breach.

In March 2023, Group-IB’s Threat Intelligence team infiltrated Qilin’s affiliate admin panel, revealing the full operational structure behind the DLS. Affiliates earn 80% of ransoms under $3 million and 85% above that threshold.

By May 2023, the DLS listed 12 confirmed victims across Australia, Brazil, Canada, France, Japan, the Netherlands, Serbia, the United Kingdom, and the United States. Qilin gains initial access primarily through phishing and exploiting unpatched VPN appliances, then moves laterally before deploying ransomware and publishing data on the DLS to pressure payment.

RansomHub RaaS (2024)

RansomHub RaaS launched its affiliate program in February 2024, introducing itself on the RAMP dark web forum and offering affiliates a 90% revenue split, among the most favorable terms in the RaaS market. The group recruited former Scattered Spider affiliates and allowed affiliates to work concurrently with other RaaS programs.

RansomHub operates a dedicated DLS panel on a .onion domain where each victim receives a separate onion address. Affiliates use the panel to manage negotiations, publish proof-of-breach data, and track payments. Initial access typically comes through exposed RDP services on public-facing Windows servers without multi-factor authentication. 

Before encryption, affiliates exfiltrate data to Mega using rclone. Group-IB observed single transfers exceeding 150 GB. RansomHub primarily targets healthcare, finance, and government organizations, with ransom demands reportedly reaching $50 million in attacks on companies in Northern Africa.

Estate (2024)

EstateRansomware demonstrates how quickly emerging groups move to exploit newly disclosed vulnerabilities. In April 2024, Group-IB’s DFIR team investigated an incident in which EstateRansomware gained initial access through a dormant VPN account on a FortiGate SSL VPN, then exploited CVE-2023-27532, a known Veeam Backup & Replication vulnerability, to access backup infrastructure directly.

The attacker deployed a persistent backdoor disguised as svchost.exe, conducted lateral movement via RDP, disabled Windows Defender using DC.exe, and deployed ransomware across all servers and workstations using PsExec. The vulnerability had been patched by Veeam in March 2023. The affected systems were running versions released years before the patch. The case illustrates a consistent pattern: DLS-backed extortion is most effective when attackers eliminate the victim’s recovery options before issuing the ransom demand.

Clop (2020–present)

TA505, the threat actor behind Clop ransomware, has operated one of the most persistent dedicated leak sites in the ransomware ecosystem. The group pioneered the mass exploitation of file-transfer vulnerabilities as an attack vector, using the Clop ransomware leak site to publish stolen data at scale.

In late 2020 and early 2021, TA505 exploited zero-day vulnerabilities in Accellion’s File Transfer Appliance, publishing victim data on the Clop ransomware leak site across multiple targeted organizations. In May 2023, the group escalated significantly: TA505 exploited CVE-2023-34362, a critical SQL injection vulnerability in MOVEit Transfer, compromising hundreds of organizations, including multiple US government agencies. 

Clop posted responsibility on their dedicated leak site and threatened to publish data from all victims by June 14, 2023, if ransoms were not paid. The US State Department responded by offering a $10 million reward for information linking the Clop ransomware gang to a foreign government.

How to Prevent Data Breaches

Defending against ransomware-driven data theft requires controls that map to the specific techniques attackers use to gain access, move through the network, and exfiltrate data before deploying ransomware. 

The recommendations below address each stage of the attack chain:

1. Enforce multi-factor authentication on all remote access services 

Exposed RDP without MFA is the most common initial access vector Group-IB observes in RansomHub investigations. Enforce OTP-based MFA on VPN, RDP, and remote desktop services to eliminate the most frequently exploited entry point.

2. Patch known vulnerabilities before attackers exploit them 

EstateRansomware exploited CVE-2023-27532 in April 2024 using a patch that Veeam had released more than a year earlier. Prioritize patching for internet-facing services, backup software, and VPN appliances. The longer a known vulnerability remains unpatched, the higher the probability that an IAB or affiliate has already identified it.

3. Protect corporate email 

According to Group-IB research, in 80% of cases, attackers gain initial access to IT infrastructure via corporate email. Phishing is Qilin’s primary initial access method. Deploy email protection capable of analyzing content in depth and blocking malicious links before they reach end users.

4. Monitor and audit accounts regularly

EstateRansomware gained access through a dormant VPN account that had not been disabled. Disable inactive accounts, restrict privileged access to the minimum required, and review remote access permissions on a regular schedule.

5. Protect backup infrastructure

Ransomware groups specifically target backup servers to eliminate recovery options before issuing the ransom demand. Store offline backup copies, segment backup infrastructure from the primary network, and use separate accounts with MFA to access backup systems.

6. Monitor for DLS exposure in real time.

By the time stolen data appears on a dedicated leak site, the breach has already occurred. Group-IB Threat Intelligence continuously monitors dark web sources and DLS infrastructure, giving security teams early warning when their organization’s data is being staged for publication before the countdown timer runs out.

Enable Real-Time Data Protection with Group-IB

Dedicated leak sites turn stolen data into a public liability. Once an organization’s files appear on a DLS, the window to contain the damage is short. Group-IB’s capabilities are built to address the full DLS threat chain: monitoring dark web infrastructure for early warning before publication and executing takedowns when data surfaces.

Here is how Group-IB helps:

  • Threat Intelligence. Monitors dark web forums, DLS infrastructure, and closed criminal communities in real time to detect when your organization’s data is staged for publication. 
  • Digital Risk Protection. Detects the illegitimate use of your organization’s data across the open web, the dark web, code repositories, and data leak channels. 

Learn how Group-IB Threat Intelligence and Digital Risk Protection can identify DLS threats before attackers publish your data.

Frequently Asked Questions

Are dedicated leak sites still active after ransomware groups are shut down?

arrow_drop_down

The site usually goes offline, but the data does not disappear. Published data persists through mirrors, archives, and dark web reposts. Affiliates from disrupted groups migrate to new RaaS programs and continue operating. BlackMatter shut down in November 2021, but its affiliates fed directly into successor groups.

How quickly is stolen data published on a DLS after an attack?

arrow_drop_down

Groups publish a small sample early in negotiations to prove exfiltration occurred. Full publication follows if the victim stops engaging or refuses to pay. Critically, exfiltration happens before ransomware is deployed, meaning data is already staged before the victim knows an attack is underway.

 

Can organizations remove their data from a DLS?

arrow_drop_down

Not directly. Ransomware groups control their own infrastructure. The practical response is to limit downstream exposure by identifying reused credentials, monitoring for brand impersonation, and initiating takedowns when the data resurfaces. Group-IB Digital Risk Protection achieves an 85% pretrial takedown rate across these channels.

 

How do cybersecurity teams track dedicated leak sites?

arrow_drop_down

Manually monitoring DLS infrastructure is not viable at scale. Group-IB Threat Intelligence automates this, monitoring dark web forums and DLS infrastructure in real time and alerting teams when their organization’s data is staged for publication.

 

What industries are most frequently targeted by DLS operators?

arrow_drop_down

Manufacturing and real estate lead all sectors, accounting for over 20% of DLS victims in H2 2021–H1 2022. Transportation, financial services, and healthcare follow. Groups prioritize sectors where operational disruption creates immediate pressure to pay and where published data carries regulatory consequences.

 

Are dedicated leak sites illegal to access or monitor?

arrow_drop_down

Accessing a DLS to monitor your own organization’s data is generally lawful as a defensive security activity. Redistributing data found on a DLS carries significant legal risk. Organizations that discover their data on a DLS should consult legal counsel before taking action beyond internal containment.

 

 

What is the role of ransomware in powering DLS ecosystems?

arrow_drop_down

Ransomware makes a DLS operationally effective. Encryption alone pressures victims to restore access. A DLS adds a second threat: public exposure of exfiltrated data. Together, they create double extortion.

Group-IB: Fight
against cybercrime