Chronological feed of ransomware victim claims with sanitized mirrors and MITRE-aligned enrichment.
Threat Group Directory
Monitored ransomware threat groups, mirror health status, aliases, and tactical profiles.
Site Status
Threat Group
Known Aliases
Total Claims
Last Activity
Action
CTI.FYI Blog
Threat intelligence analysis, platform announcements, and weekly ransomware digests.
Loading blog posts…
Loading API reference…
Data Collection & Analysis Methodology
Principles, limitations, and counting rules governing ransomware intelligence on CTI.FYI.
Core Counting Rules & Definitions
Ransomware tracking metrics often conflate raw actor blog posts with verified enterprise breaches. CTI.FYI explicitly differentiates between three levels of observation:
Listing (Claim)
An extortion record published on an actor's darknet leak blog or press portal. Represents an unverified extortion assertion by the syndicate. Multiple listings may target the same organization across time or re-extortion cycles.
Unique Organisation
A deduplicated real-world legal entity or institution identified via canonical naming, web domain resolution, and entity normalization. Resolves multi-group syndication, aliases, and repeat postings into a distinct victim entity.
Confirmed Incident
An attack independently corroborated through regulatory disclosures (SEC 8-K, GDPR/ENISA notifications, state breach registries), external forensics, or public victim acknowledgment. An extortion listing does not automatically constitute a confirmed incident.
Coverage & Darknet Infrastructure
CTI.FYI continuously monitors hidden services (.onion) and clearnet PR portals maintained by active ransomware syndicates and data leak cartels.
Leak Site Reachability: Tor hidden services frequently experience circuit instability, ISP DDoS, operator migration, and law enforcement actions. When a mirror is reported unreachable, it indicates mirror availability during the check cycle, not threat group cessation.
Collection Schedule: Collection workers cycle across all mirrors around the clock. Collection success percentages represent successfully parsed responses relative to total mirror polling attempts.
Safety Boundaries: The pipeline extracts only public metadata and listing titles. CTI.FYI never downloads exfiltrated payloads, private decryption material, credential dumps, or malware binaries.
Deduplication & Normalization
Raw extortion claims frequently contain tracking noise, varied URL parameters, re-posts, and shared affiliate leaks across multiple syndicate rebrands.
Canonical URL Deduplication: URLs are stripped of tracking tokens, session IDs, and normalized by scheme, host, and path to prevent duplicate ingestion.
Title & Entity Normalization: Raw actor post titles are normalized using Unicode NFKD, prefix/flag stripping (e.g., removing "[NEW]", "[UPDATE]", or date tags), and mapped against known aliases across syndicates sharing victims.
Multi-Group Aliasing: Shared affiliate infrastructure (e.g. LockBit re-posts or multi-cartel leaks) is cross-referenced to avoid double-counting victims across affiliated operators.
Post Re-visitation & In-Place Updates: When threat actors update an existing disclosure—such as revealing the victim's identity from a placeholder, releasing data proofs, or changing publication dates—CTI.FYI revisits and updates the record in-place rather than generating duplicate entries, triggers fresh entity enrichment, and records an updated timestamp.
Automated Metadata Enrichment
Most extortion listings contain only an actor-authored title or acronym. CTI.FYI enriches raw claims with contextual intelligence using structured AI and OSINT heuristics:
Canonical Entity & Sector: Machine classification extracts formal business names, primary headquarters country (ISO Alpha-2), and standard industry sectors (aligned with NAICS/GICS taxonomies).
Confidence & Provenance: Enriched attributes are generated automatically and tagged with confidence scores. Users can report misclassifications or submit verified corrections.
Missing Metadata Handling: When an actor does not provide a country, sector, or descriptive context, attributes remain explicitly marked as "Unknown" rather than hallucinated or inferred.
Timestamp Precision: Claimed publication dates provided by actors are preserved as claimed dates. If an actor provides only a date without a specific time, midnight is treated as date-only granularity. Intercept timestamps record when CTI.FYI first detected the listing.