extortion.wiki
From extortion.wiki, the ransomware documentary archive
Ransomware Negotiations and Notes Research Archive
Archive introduction
extortion.wiki contains two searchable primary-source corpora: documented ransomware negotiations and archived ransomware notes. Both support research, incident response, journalism, and historical analysis while retaining separate provenance, routes, search filters, and statistics.
Records are presented in normalized static documents. Claims remain claims, URLs remain inert, and inconsistent source data is documented rather than quietly transformed into confidence.
Search the archive
The query runs locally against the static Pagefind index. Nobody receives your search, including us.
Negotiation archive overview
| Threat actors | 26 | Negotiations | 242 |
|---|---|---|---|
| Messages | 11,480 | Dated records | 172 |
| Earliest dated record | Aug 11, 2020 | Latest dated record | Feb 25, 2026 |
| Source dataset | Casualtek/Ransomchats | Dataset snapshot | Jul 6, 2026, 1:18 PM |
| Validation status | Validated at build | Normalization issues | 34 |
Recently indexed records
Browse all records| Participants | Source | Archive status | ||||
|---|---|---|---|---|---|---|
| Nightspire | 20260225 | 48 | Nightspire, Victim | JSON | Indexed | |
| Nightspire | 20260217 | 31 | Nightspire, Victim | JSON | Indexed | |
| Nightspire | 20260203 | 45 | Nightspire, Victim | JSON | Indexed | |
| Nightspire | 20260127 | 62 | Nightspire, Victim | JSON | Indexed | |
| Nightspire | 20251218 | 84 | Nightspire, Victim | JSON | Indexed | |
| Pear | 20250720 | 42 | PEAR, Victim | JSON | Indexed | |
| kairos | 20250519 | 41 | Kairos, victim | JSON | Indexed | |
| Nightspire | 20250428 | 59 | Nightspire, Victim | JSON | Indexed | |
| Akira | 20250423 | 6 | Akira, Victim | JSON | Indexed | |
| Akira | 20250425b | 15 | Akira, Victim | JSON | Indexed | |
| Akira | 20250424 | 12 | Akira, Victim | JSON | Indexed | |
| Akira | 20250423 | 65 | Akira, Victim | JSON | Indexed |
Threat actor index
Browse directory and statisticsA
B
- Babuk (2 records)
- BlackBasta (5 records)
- BlackMatter (2 records)
C
D
- Darkside (5 records)
- Dragonforce (14 records)
F
- fog (6 records)
H
- Hive (8 records)
- Hunters International (1 records)
K
- kairos (1 records)
L
- lockbit3.0 (42 records)
M
- Mallox (3 records)
- mount-locker (1 records)
N
- Nightspire (7 records)
- NoEscape (2 records)
P
- Pear (1 records)
Q
- Qilin (2 records)
R
- RansomHub (1 records)
- Ranzy (2 records)
- REvil (20 records)
- RunSomeWares (1 records)
T
- trinity (14 records)
Archive notices
Methodology
Zod validates the JSON during the static Astro build. Message order and line breaks survive; locations written inside transcripts remain inert. The input remains JSON, including when it behaves more like a suggestion. Read the methodology.
Known limitations
The corpus is selective, some dates come from filenames, and actor labels reproduce upstream classifications. Counts describe this snapshot, not ransomware prevalence. Software remains unable to repair missing history through confidence.
Dataset attribution
Negotiations come from Casualtek/Ransomchats; ransomware notes come from Zscaler ThreatLabz. Both source records, snapshots, and licenses remain visible, and their statistics are never combined.
Legal use
Use this material only for legitimate journalism, scholarship, defensive security, and public-interest research. Review the handling notice.