A posting plinth holding a name plate, one sheet behind glass and a countdown wheel, with an already emptied vault standing apart behind it.

Dedicated Leak Site (DLS)

A dedicated leak site, or DLS, is a criminal-run website where a ransomware group lists the organisations it says it has breached and publishes their stolen data if a ransom goes unpaid. It turns stolen data into leverage. MITRE ATT&CK mentions it once, inside T1657 Financial Theft, under the Impact tactic.

You have probably met the term in an advisory or a vendor report, and directly underneath it, a number: victims this quarter, groups active this year, a percentage change. That number almost certainly came off these sites. So does much of what the industry reports about ransomware volume.

This page covers what a dedicated leak site is, how the extortion model around it works, and then spends its centre on the part nobody publishes: how far leak-site data can be trusted, and what your organisation should have decided before its name appears on one.

One scope note before anything else. The phrase "leak site" is also used for unrelated adult-content aggregators. This page is about ransomware extortion infrastructure and nothing else.

A noticeboard with a pinned name plate, one sheet under glass and a date wheel, beside an already emptied filing drawer.

Explain It Like I'm 10

Imagine someone copies your papers, then pins your name to a public noticeboard with a photograph of one page and a date written beside it. The note says the rest goes up on that date unless you pay. Your papers are already gone. The noticeboard is not how they were taken; it is how you are pushed into paying to stop everyone reading them. A dedicated leak site is that noticeboard, run by the people who took the papers.

Dedicated Leak Site Quiz

Test your knowledge about Dedicated Leak Site - maybe you already know everything about it.

EasyQuestion 1 of 3

What is a dedicated leak site for ransomware groups?

A press with one arm clamping a data drum and another feeding a sheet into a posting frame, a countdown wheel between them and an auction cradle further along.

How the extortion model works

The sequence is consistent enough that a six-agency government advisory describes it in one sentence. In #StopRansomware: Gunra Ransomware, published 10 August 2026 by CISA, the FBI, DC3, the NSA, the US Secret Service and the Republic of Korea's National Police Agency, the model is: actors "leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid". The advisory records that the group "quickly established a DLS on the Tor network to list victims and publish exfiltrated data".

Three things in that advisory deserve separating out, because they are design decisions rather than facts of nature.

  • The deadline is engineered. Victims are directed to a negotiation portal, "assigned a Client ID and an initial password", and told to negotiate "within five to seven days". A countdown is a pressure feature, and a government primary documents it as one.
  • Publication is not the ceiling. The same advisory notes that if the ransom is not paid, the actors "threaten to sell victim data on the DLS". Auctioning follows publishing.
  • This is a business with suppliers. Gunra "expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums", derived from leaked source code of an earlier family.

The model has also drifted away from encryption. Palo Alto Networks reports that encryption-based extortion declined 15% from the year before, as attackers "skip encryption and move straight to data theft and disruption", and the Verizon 2026 Data Breach Investigations Report records that in some cases actors "simply rely on extortion alone and do not trigger the encryption of data". The leak site is what makes theft-only extortion viable: without a credible publication threat, stolen data is not leverage.

The scale of the surrounding phenomenon is not in doubt, whatever the counting problems below. The same Verizon report records that ransomware grew again to 48% of all breaches, up from 44% the previous year - a share of breaches in that dataset, which is a different measurement from anything a leak site produces, and the two should never be quoted as if they were the same number.

A press extruding the graduated rail used to measure it, with a counting drum on one line and a second line bypassing the counter entirely.

How reliable is dedicated leak site data?

This is the part that matters if you are about to quote a number.

Leak sites are where the industry's ransomware statistics come from. Unit 42 describes its own practice plainly: researchers "often use this data to determine overall levels of ransomware activity and pinpoint the date a specific ransomware group was first active". That is the trendline. It is assembled by monitoring sites that the offenders build, populate and control.

The team that builds one of those datasets publishes the caveat itself. Defenders should "use leak site data with caution because it might not always reflect actuality". The failure modes are specific, and each belongs to whoever documented it.

Failure mode

Why it happens

What it does to a number

Victims who pay may never be listed

Unit 42: "if a victim offers immediate payment, the ransomware incident might not appear on a group's leak site"

Undercounts, and undercounts unevenly - the fastest payers are invisible

A group can operate before it has a site

Unit 42: "A ransomware group might start without a leak site as it builds its infrastructure"

Distorts first-seen dates and new-group counts

Silence is not shutdown

Unit 42: "A lack of leak site posts does not necessarily mean these groups have ceased operations"

Reads a rebrand, a retreat or a merger as a decline

The count is of claims

ENISA counts, in its own words, "cybercrime claims" from "monitored Data Leak Sites (DLS) and cybercriminal forums"

A post is an assertion by an offender, not a verified breach

Volume can track attention

ENISA: "increased reporting of a specific threat does not necessarily reflect an increased tempo but rather speaks to the audience's interest"

Confuses coverage with activity

The European Union Agency for Cybersecurity is the source to read directly on this. Its Threat Landscape 2025 analysed 4,875 incidents from 1 July 2024 to 30 June 2025, "mainly based on information from open sources", and states that open sources and voluntarily shared information "do not constitute a complete picture of the cyber threat landscape". Its analysts curated the dataset, in their words, "to avoid inflating the threat". ENISA also notes that ransomware is among the threats "often claimed directly by their operators", which is precisely the property that makes it visible and makes it unreliable in the same breath.

The number that shows the size of the gap

Group-IB, whose page ranks first for this term on both major engines, puts leak-site listings at about 10% of all ransomware victims, on the reasoning that most victims pay to keep their data unpublished. Three qualifiers travel with it, and dropping any changes its meaning: it is one vendor's telemetry, no method is published on the page, and it dates from 2023.

#### The tension worth stating rather than resolving

That figure sits in tension with a more recent dataset. The Verizon 2026 DBIR reports that 69% of ransomware victims did not pay, with a median payment of $139,875. If most victims refuse, more of them should end up listed, not fewer. These are different datasets, different windows and different definitions, and this page is not going to average them into a third number that belongs to nobody. The honest read is that the size of the gap between listings and incidents is contested, while the existence of the gap is not.

None of this makes the data useless, and the source of the caveat says so in the same passage: "Despite these drawbacks, data pulled from ransomware leak sites provides valuable insight on the state of ransomware operations." ENISA's response is the mature one - curate the dataset, state the method, keep using it. The correction here is about calibration, not dismissal. The industry measures the ransomware landscape with a ruler the offenders print, and the useful response is to know the ruler.

A cabinet of drawers holding payment instruments, with a single posting frame mounted in a narrow slot on one drawer side, connected to nothing.

Which ATT&CK technique covers a dedicated leak site?

None of its own, and that surprises people who go looking.

Impact is the tactic where ATT&CK puts the outcomes an adversary is working toward - in the framework's own words, the adversary "is trying to manipulate, interrupt, or destroy your systems and data". Extortion sits there because that is where the money is.

The term itself appears in a single clause inside T1657 Financial Theft: "Adversaries may use dedicated leak sites to distribute victim data." T1657 has no sub-techniques, sits under the Impact tactic, and is at version 1.2, last modified 12 May 2026.

Now read its detection strategy. `DET0495` carries five analytics, and they describe anomalous access to "financial applications, browser-based banking sessions, or enterprise ERP systems", outbound connections to cryptocurrency nodes, access to "payment applications, browser plug-ins, or Apple Pay services", unauthorised activity in "SaaS financial systems (e.g., QuickBooks, Workday, SAP S/4HANA cloud)", and "fraudulent invoices, impersonation of vendors, or BEC-style payment redirections".

Not one of them observes extortion publication. The framework files leak sites under the technique where the money is, and its detection content is a payment-fraud specification. The consequence, stated once: extortion pressure is not a detection row. It is an outcome the rest of the intrusion produces, which is why the controls that change it sit upstream of the listing.

The framework does acknowledge that coercion goes further than publishing. Mitigation M1017 recommends training users on procedures "to prevent and respond to swatting and doxing, acts increasingly deployed by financially motivated groups to further coerce victims". And the mismatch shows in ATT&CK's own procedure examples, where a group is recorded as having "extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site" - filed under a technique whose analytics watch accounting software.

Two identical foundation blocks, one with a clamped dial and one with an empty dial socket, a caliper spanning the gap between them.

Who was first, and does the founding date hold up?

The field has a founding story: Maze ransomware launched the first dedicated leak site in December 2019. Group-IB's page states it in those words, and it is repeated widely.

The same page also carries a section titled "The First Dedicated Leak Sites: Snatch and Maze", and a body line reading "Since Snatch and Maze introduced the model". Three statements on one page, and they do not agree about whether one group or two started this.

The careful version

Other research teams are more careful. Unit 42 writes that leak sites "first appeared in 2019, when Maze ransomware began using a double extortion tactic", and calls Maze "the first known ransomware group to establish a leak site". Year, not month. Known, not first.

The defensible position is narrow: Maze and 2019 are solid, the specific month is contested across sources, and no law-enforcement or academic primary fixing the date was located for this article. That distinction matters more here than it would elsewhere. A page arguing that leak-site numbers need provenance cannot repeat a founding date without checking it.

A frame holding one claim card above six latch sockets, of which only two hold seated latches and four stand empty.

What a listing does, and does not, prove

A listing establishes two things: a group claims to hold data belonging to a named organisation, and it is willing to publish some of it to prove the claim.

By itself, it does not establish the size of the dataset, its authenticity, whether encryption occurred, or even that the named organisation is where the data came from - data taken from a supplier or a customer can be listed under the better-known name. That reasoning follows from the caveats above rather than from a source that states it, and it should be treated as reasoning rather than as a cited finding, but it is the reason a listing is a lead to verify rather than a fact to act on.

A criminal noticeboard became a disclosure channel

For many organisations, a listing is the first time they, their customers or their regulator learn anything at all. The extortion model turned a criminal noticeboard into a disclosure channel, and no organisation gets to opt out of that.

On the question everyone asks next, this page quotes and stops. The authoring agencies of the Gunra advisory write that they "do not encourage paying ransom as payment does not guarantee victim files will be recovered", adding that payment "may also embolden adversaries to target additional organizations", and they urge prompt reporting to the FBI, USSS or CISA regardless of whether an organisation pays. Group-IB reports the practical counterpart from the other end: "Even when victims pay, deletion is not guaranteed. Links to compromised files have remained accessible after ransoms were met." Whether to pay is a legal, insurance and jurisdictional decision, and this article does not offer one.

Three levers already thrown and pinned on a dusty console, facing a sealed door whose posting frame is still empty.

What to decide before your name appears

Every competing page captured for this article ends at monitoring, and Google's own generated answer closes by offering it. Monitoring is a reasonable control category, but it is not the thing that determines how the next 48 hours go. These are, and all three can be settled while nothing is happening.

  • The communications position. Who speaks, to whom, and in what order, if the first notification is a public listing rather than an internal alert. The sequence that works when you find out first is not the sequence you need when a customer's journalist finds out first.
  • The legal and regulatory position. Which counsel is called, which notification clocks start on what trigger, and in which jurisdictions. A listing may start a clock that an unpublished incident would not. That is a decision to have made rather than legal advice to take from a glossary page. The agencies' own instruction is narrower and easier to act on: report the incident promptly to the FBI, the US Secret Service or CISA, and do it regardless of whether the organisation ends up paying.
  • The evidence position. What gets preserved, by whom, and how the fact of a listing is recorded without anyone in the organisation improvising a trip to look at it. Decide who owns that, and how, before the day it is needed.

One structural point sits underneath all three. The listing is the last step of a chain that began with access and continued through exfiltration. Everything that changes the outcome - stopping the intrusion, spotting the staging, cutting the data out before it leaves - happens earlier. By the time a name is on a site, the decisions left are about response, not prevention.

A counting drum with a single intake from one press, a capped port where an outside feed would attach, and an empty verification cradle.

What we do not know

There is no independent count of leak-site activity. Every published figure located for this article, vendor or agency, is derived from reading the offenders' own sites. There is no external register, no mandatory feed, and no verification step between a criminal posting a name and that name becoming a data point in someone's annual report.

The founding month is unsettled, as the sources above show.

And the discipline applies to this page too. Every figure quoted above came from someone else's dataset, and the three that matter most - the proportion, the payment rate and the breach share - were produced by two vendors and one report with different methods, different windows and different definitions of a victim. None of them was verified independently for this article, because there is nothing independent to verify them against.

And this page has a deliberate boundary. It does not name victims, name or locate sites, or explain how monitoring reaches them. That is a choice, not an omission: a page that helped anyone find this material would be doing a second round of harm to people who did not consent to the first.

A five-tier stepped rack, each tier a drawer front with a plug seated in its socket, fed from a shared spine behind.

Frequently asked questions

Is a leak-site listing proof that a breach happened? No. It is a claim made by an offender with an incentive to exaggerate. Treat it as a lead to verify rather than a confirmed fact, and be careful about the difference when the organisation named is a customer or a supplier rather than you.

Do all ransomware victims end up on a leak site? No, and the exceptions are the whole calibration problem. Victims who pay quickly may never be listed, some groups run without a site, and others post selectively. A count of listings is a count of what offenders chose to publish.

Is there an ATT&CK technique for leak sites? Not one of their own. The term appears in a single clause inside T1657 Financial Theft, under the Impact tactic, and that technique's detection analytics describe payment fraud rather than extortion publication.

If we pay, does the listing come down? There is no guarantee. The authoring agencies state that payment does not guarantee recovery, and a vendor source reports that links to stolen files have stayed reachable after ransoms were met. Payment buys a promise from a criminal.

Why do numbers from different reports disagree so much? Because each is built from a different slice of the same adversary-published surface, with different windows, different curation rules and different definitions of a victim. Disagreement between two ransomware reports is usually a methodology difference, not a contradiction.

Four stations on one trunk: a provenance stamp, a verification clamp, three pre-set levers, and a valve far upstream where the capsules first enter.

How to use this term well

Four moves, in order, each drawn from the sources above.

  1. When you quote a leak-site-derived number, say whose dataset it is, which window it covers, and how it was curated. ENISA publishes all three for its own figures; most reports do not.
  2. Treat a listing as a claim to be verified, not as a confirmed breach - particularly when the name on it is not your own organisation.
  3. Settle the communications, legal and evidence positions in advance. They are the only part of this that is yours to decide.
  4. Remember where the leverage came from. The data left the network before any of this was visible, and that is where the controls that matter live.

The sensor is useful and it is operated by the offenders. Both halves of that sentence have to survive onto the slide.