ervik.as

Ransomware Tracker 2026

Live tracking of active ransomware campaigns and victim disclosures. Updated continuously as new attacks are posted to leak sites.

Recent Victims
0
Active Groups
0
Top Group
(0 posts)
0 results
CountryNotes
Loading ransomware feed…

Sources: ransomlook.io + ransomware.live · aggregates public leak-site posts, deduplicated across both feeds

Frequently Asked Questions

Where does this ransomware data come from?

Victim disclosures are aggregated from public ransomware leak-site monitors, RansomLook and ransomware.live, which track posts made by ransomware groups on their own extortion/leak sites.

Does a listing here mean the attack is confirmed?

Listings reflect what ransomware groups themselves have publicly claimed on their leak sites — this is the attacker's own claim, not independent third-party confirmation, though it is the standard method threat intelligence teams use to track ransomware activity.

How often is this updated?

Continuously, refreshed automatically as new posts appear on tracked leak sites, typically within minutes of publication.

What does double extortion mean?

Double extortion is when a ransomware group both encrypts a victim's data and threatens to publish stolen data publicly, using the leak site itself as additional leverage beyond the ransom demand for decryption.

Advertisement