Research page reference

Archive introduction

extortion.wiki contains two searchable primary-source corpora: documented ransomware negotiations and archived ransomware notes. Both support research, incident response, journalism, and historical analysis while retaining separate provenance, routes, search filters, and statistics.

Records are presented in normalized static documents. Claims remain claims, URLs remain inert, and inconsistent source data is documented rather than quietly transformed into confidence.

Negotiation archive overview

Current normalized Ransomchats negotiation snapshot
Threat actors26Negotiations242
Messages11,480Dated records172
Earliest dated recordAug 11, 2020Latest dated recordFeb 25, 2026
Source datasetCasualtek/RansomchatsDataset snapshotJul 6, 2026, 1:18 PM
Validation statusValidated at buildNormalization issues34

Recently indexed records

Browse all records
Twelve most recent dated or indexed negotiation records
Participants Source Archive status
Nightspire 20260225 48 Nightspire, Victim JSON Indexed
Nightspire 20260217 31 Nightspire, Victim JSON Indexed
Nightspire 20260203 45 Nightspire, Victim JSON Indexed
Nightspire 20260127 62 Nightspire, Victim JSON Indexed
Nightspire 20251218 84 Nightspire, Victim JSON Indexed
Pear 20250720 42 PEAR, Victim JSON Indexed
kairos 20250519 41 Kairos, victim JSON Indexed
Nightspire 20250428 59 Nightspire, Victim JSON Indexed
Akira 20250423 6 Akira, Victim JSON Indexed
Akira 20250425b 15 Akira, Victim JSON Indexed
Akira 20250424 12 Akira, Victim JSON Indexed
Akira 20250423 65 Akira, Victim JSON Indexed

Threat actor index

Browse directory and statistics

A

B

C

D

F

  • fog (6 records)

H

K

L

M

N

P

Q

R

T

Archive notices

Methodology

Zod validates the JSON during the static Astro build. Message order and line breaks survive; locations written inside transcripts remain inert. The input remains JSON, including when it behaves more like a suggestion. Read the methodology.

Known limitations

The corpus is selective, some dates come from filenames, and actor labels reproduce upstream classifications. Counts describe this snapshot, not ransomware prevalence. Software remains unable to repair missing history through confidence.

Dataset attribution

Negotiations come from Casualtek/Ransomchats; ransomware notes come from Zscaler ThreatLabz. Both source records, snapshots, and licenses remain visible, and their statistics are never combined.

Legal use

Use this material only for legitimate journalism, scholarship, defensive security, and public-interest research. Review the handling notice.