Ransomware leak site claims show up in the news constantly: a gang says it has stolen a company's data, posts a countdown, and threatens to publish everything. Reporting on these claims is legitimate and necessary. But reading that coverage with a critical eye, understanding what a Tor leak site actually is and what its claims are worth, matters as much as the story itself.
What a ransomware leak site actually is
Most prominent ransomware groups run dedicated data leak sites on the Tor network. This is part of what security researchers call double extortion: the group encrypts a victim's files and also steals a copy, then threatens to publish the stolen data if the ransom is not paid. The tactic was pioneered by the Maze ransomware group in November 2019 and has since become standard practice across the ransomware ecosystem.
These sites are hosted as Tor onion services, which conceal the operators' location and identity using the same open-source technology that protects ordinary privacy-conscious users. That is a deliberate choice. It makes the infrastructure harder for investigators and hosting providers to take down quickly.
Why the claims on these sites are not neutral evidence
A leak site posting is not a verified disclosure. It is a pressure tactic aimed at a victim organization, written by people with a direct financial incentive to make the breach sound as severe as possible.
Groups have been known to exaggerate stolen data volumes, rebrand after law enforcement action, or post claims about victims who were never actually compromised, simply to generate fear. Treating a leak site's own description of an incident as established fact skips a step that careful reporting should not skip.
What responsible coverage looks like
Good reporting on ransomware leak sites treats the claim as a claim, not a confirmed fact, until there is independent verification: a statement from the victim organization, confirmation from incident responders, or samples of leaked data that have been authenticated.
Some outlets go further and analyze the attackers' own internal communications after a leak or a group's infrastructure is compromised. The Record's reporting on the Yanluowang ransomware group is one example: a researcher obtained the group's internal chat logs after they leaked, processed them chronologically, and used them to map the group's internal structure and hierarchy. That is reporting built on evidence, not on repeating the group's self-description.
As a reader, you can ask the same questions a careful journalist asks:
- Has the named victim confirmed or denied the incident?
- Is the evidence independently verified, or only the attacker's own word?
- Does the outlet distinguish between the group's claims and confirmed facts?
- Is the story describing the incident, or quoting the extortion message almost verbatim?
Why amplification is a real risk
Leak sites exist partly as a publicity tool. A ransomware group wants journalists, researchers, and victims' customers to see its claims, because public pressure increases the odds of payment.
Coverage that reprints a group's threats uncritically, names victims before confirmation, or treats a leak site's countdown timer as a newsworthy event in itself can do some of that pressure work for the attackers, even unintentionally. This is not a reason to avoid covering ransomware. It is a reason to cover it with the same skepticism applied to any self-interested source.
What happens when these sites get taken down
Leak sites are not permanent fixtures. Law enforcement has seized Tor negotiation and leak infrastructure in several cases, including the Ragnar Locker ransomware operation's dark web extortion sites, taken down as part of an international police action.
In other cases, groups have tried to contest or reverse a seizure. After the FBI took action against AlphV/Blackcat's infrastructure, the group claimed to have "unseized" its domain. The unsealed search warrant in that case showed law enforcement had collected hundreds of key pairs used to operate the group's onion services, including leak sites and affiliate panels. This illustrates how contested and unstable this infrastructure can be. Claims made by a group mid-dispute with law enforcement deserve particular caution.
A note on curiosity and safety
Some readers want to view a leak site directly rather than rely on secondhand reporting. This is where the known pitfalls of the dark web matter most.
Tor Browser, maintained by the Tor Project, conceals your traffic's path but does not make your actions anonymous. Logging into any personal account, reusing a username, or downloading a file from an unverified source can undermine that protection regardless of Tor.
General-purpose directories like "the Hidden Wiki" are not a safe or reliable way to find anything on Tor. What exists under that name today is mostly clones and copycats, many containing outdated, fake, or dangerous links. There is no single trustworthy version of it.
If you need an onion address for a legitimate organization, the safest method is to get it directly from that organization's official clearnet site, the same way you would verify an onion address for Proton Mail or any other service you already trust. A search engine like DuckDuckGo can help you find an organization's official site, but it cannot verify that any particular onion link is genuine. That verification has to come from the organization itself.
The bigger picture
Ransomware groups rely on dark web infrastructure throughout their operations, from recruiting affiliates on forums to running the leak sites themselves. Understanding that infrastructure helps explain why these claims appear where they do and why they are built to apply pressure.
Reading the coverage well means separating the attacker's narrative from what has actually been verified. A leak site's own words are the start of a story, not the end of one.