An archive of private messages from Verified.ru, one of the founding venues of Russian-speaking cybercrime, covers 152,973 messages sent by 8,650 accounts between 13 July 2005 and 30 March 2010. Ransomnews has analysed it in full. What it documents is not a bazaar but an institution: a published rulebook, a fixed penalty tariff, escrow, a blacklist, and 4,867 disciplinary notices telling members exactly what they had done wrong.
Verified needs little introduction to anyone who has followed this ecosystem. It sat for well over a decade among the most selective venues available to Eastern European operators, and it was still consequential enough in 2021 that its compromise, via its domain registrar, and the subsequent contested takeover both made the security press. Almost everything written about the forum, though, describes its later years. This archive covers the beginning.
What the archive contains
The material is sender-side: for each account, the private messages that account sent, decoded from cp1251 out of a database dump named verified.sql. That shape matters for reading it. Where a conversation is one-sided in the record, the other half simply wasn’t captured, so I have avoided inferring anything from silence.
Volume tracks the forum’s rise closely. 869 messages in the closing months of 2005 that the archive covers, then 10,878, then 26,018, then 34,405, and 63,826 in 2009. The record stops on 30 March 2010, three months into a year that was already running at a comparable rate.
One account did the governing
The first private message in the database, numbered 1 and timestamped 13 July 2005, was sent by an account called Link to an account called Minsk. Its subject is “Administrator” and its body is a single line: “You are the administrator of this forum.” Link never sent another private message. Minsk sent 6,227 more.
That file is the largest in the archive: 6,227 conversations, active from the archive’s opening day until its last. Minsk is not a trader. Of those conversations, 2,746 carry the subject “You have received a warning for violating the rules of the forum” and a further 1,252 read “You have violated the rules of Verified.ru – Only checked people”. The rest are advertising, blacklist matters, escrow, and the occasional poll.
Six other staff accounts appear alongside: parik, Emptiness, TechAdmin, Phantom, VR_Support and one called simply Administrator. Most span nearly the whole period. Between them they issued 4,867 infraction notices that state a reason, and Minsk sent 4,062 of them. Enforcement on Verified was, in practice, one person’s job.
The notices are formulaic, which is exactly what makes them useful. A standard one reads: “Dear LLLL, you have received a warning on the forum Verified.ru. Reason: Duplicate message. For this violation you are assessed 1 point. If your penalty points reach 10, you will be banned.” It then links to the rules thread, verified.ru/showthread.php?t=21612, and quotes the offending post back at the member.
That’s a disciplinary system with a published tariff, a documented reason, an evidence quote and an appeal path. The heavier notice adds a line that would not look out of place in a corporate handbook: for serious violations, the block will never be lifted.
What actually got members punished
Two thirds of every punishment handed out on Verified, 3,280 notices, was for the same offence: advertising something the forum had not vetted. Not fraud, not scamming another member, not sloppy tradecraft. Selling before you had been checked.
The forum’s name is not decoration. Its slogan, repeated in every notice of that class, was “Only checked people”. Vetting was the product. A buyer on Verified was paying for the assurance that the seller across from him had passed through a process, and the administration protected that assurance more aggressively than it protected anything else. The standard tariff for breaking it was four points, and 2,991 notices carry exactly that figure.
Second on the list, at 644 notices, is a category with no equivalent in any legitimate marketplace: “English-speaking member”. Thirteen percent of all discipline on Verified was for being an English speaker. The forum wasn’t merely Russian-language by convention, it policed the boundary, and it treated an anglophone presence as an infraction in its own right rather than a nuisance to be tolerated.
Further down, at 55 notices, sits the rule everyone in this field has heard of and few have seen enforced on paper: “We do not work on RU”. Members were formally disciplined, with points and post deletion, for targeting Russian and CIS victims. The convention that would later define the entire ransomware economy, and that still shapes which victims turn up on leak sites, was already a written offence with a tariff attached in 2008.
The remainder is small-scale housekeeping. Duplicate posts, all-capitals thread titles, off-topic replies, rudeness to other members, clone accounts. 932 notices carried the maximum ten points, which under the forum’s own rules meant an immediate ban, so roughly one disciplinary action in five ended somebody’s membership on the spot.
Escrow, blacklist and the concentration of power
Beyond discipline, two other mechanisms show up repeatedly. The first is the guarantor service, 271 messages under the subject “Garant”, where the administration held funds while a deal completed. Minsk personally handled 169 of them. The second is “Black”, the blacklist, appearing in 501 message subjects, where members brought accusations against each other and the administration ruled.
Put those together with the enforcement numbers and a picture emerges that is worth pausing on. The same account wrote the rules, judged the violations, banned the offenders, arbitrated the disputes and held the escrow. There was no separation of powers on Verified, and no appeal beyond the person who issued the sanction. Members accepted that because the alternative, trading with strangers and no recourse, was worse.
It was also, plainly, a business
812 messages in the archive concern advertising. VR_Support, one of the staff accounts, spends most of its traffic on exactly this: 77 messages headed “Advertising”, plus threads titled “Payment for advertising”, “Renewal of advertising” and, inevitably, “Unpaid advertising”. Sellers bought placement, the forum invoiced them, and staff chased the ones who did not pay.
This is the commercial logic that explains the enforcement pattern. If the forum sells advertising, and the value of that advertising rests on buyers trusting vetted sellers, then unverified advertising is not a rules infraction. It is revenue theft, and a threat to the only asset the forum has. Two thirds of all punishment suddenly looks less like pedantry and more like a company protecting its margin.
The VR_Support question
VR_Support is a name with a later history. In February 2021, following the compromise of Verified through its domain registrar the previous month, a group announced it had taken control of the forum and communicated that claim under the alias VR_Support. Flashpoint reported the takeover at the time, noting that members were sceptical of the timing and that the previous administration never acknowledged the transfer.
In this archive, VR_Support is not new. The account is active from 3 October 2006 to 29 March 2010, sends 209 messages, sells the forum’s advertising and issues rule warnings alongside the rest of the staff. It was part of the administration for at least three and a half years of the period covered here.
I want to be careful about what that does and does not establish. It doesn’t prove the same human being was behind the handle in 2006 and in 2021. A support alias can be inherited, handed over with the forum, or simply taken by whoever ends up holding the infrastructure. What it does establish is that the name used to announce a takeover in 2021 was not invented for the occasion. It was the forum’s own staff identity, fourteen years old, and choosing it would have carried a specific meaning for anyone who had been around long enough to recognise it.
Why a 2010 archive still matters
Read the modern ransomware economy against this document and the resemblance is uncomfortable. Affiliate programmes vet their partners before granting access. Ransomware-as-a-service operations publish rules about which sectors are off limits and expel affiliates who break them. Forums still run guarantor services, still maintain arbitration threads, still ban for scamming other criminals long before they would ban for anything done to a victim.
None of that was invented by the ransomware crews. It was inherited, and this archive is one of the places it can be watched being built. The penalty-points system does not exist in the 2005 to 2007 material. It appears in mid-2008, at the exact point the forum outgrew what informal moderation could handle, and Minsk’s traffic jumps from a few hundred messages a year to 1,656 and then 3,051. Scale forced formalisation. The same pressure produces the same answer today.
The lasting significance of Verified is not any particular deal recorded in it. It’s that the Russian-speaking underground worked out, fifteen years before the current extortion economy, that the scarce commodity in criminal commerce is not tooling or access. It is trust, and trust has to be administered.
What I could not establish
Several things are outside what this material can support, and it’s worth saying so plainly.
- No identities. The archive contains handles, not people. Nothing here attributes an account to a named individual, and I have not attempted it.
- No line to the ransomware era. I checked whether the handles from our earlier work on the REvil source-code developer appear anywhere in this corpus. They do not, with zero matches on a word-boundary search. Verified was formative for the ecosystem, but this particular thread does not run through it.
- Only one side of each exchange. The record is sender-side, so replies are frequently missing and conversation counts should not be read as complete dialogues.
- The trade itself resists counting. Private-message subject lines are mostly conversational, so any attempt to quantify what was bought and sold from them would be guesswork. The governance layer is measurable in a way the commerce is not.
This is the first of several pieces drawn from a set of forum archives. We track live extortion activity on the Ransomtracker, maintain profiles of active crews in the threat group catalogue, and have written on how access reaches these markets in the first place in our work on initial access brokers.
Frequently asked questions
What was the Verified forum?
Verified was one of the most selective Russian-language cybercrime forums, active for well over a decade. Membership depended on vetting, which is where the name comes from, and its slogan appears throughout this archive as “Only checked people”.
What period does this archive cover?
13 July 2005 to 30 March 2010. It holds 152,973 private messages sent by 8,650 accounts, decoded from cp1251 out of a database dump. It predates the January 2021 compromise of the forum by more than a decade.
Who ran Verified?
Enforcement in this period was dominated by a single account, Minsk, active across the whole archive and responsible for 4,062 of the 4,867 infraction notices. Six other staff accounts appear alongside it, including VR_Support, parik, Emptiness, TechAdmin, Phantom and one named Administrator. No real identities are established here.
What were members punished for most often?
Advertising something the forum had not vetted, which accounts for 3,280 of 4,867 notices. Second is “English-speaking member” at 644. Both were enforced far more often than scamming other members, which appears only 15 times.
Does the archive show the rule against attacking Russian targets?
Yes. “We do not work on RU” appears as a formal, punishable infraction 55 times, carrying penalty points and post deletion. The convention that still shapes ransomware victim selection was written policy on Verified by 2008.
Is VR_Support in this archive the same VR_Support that claimed the forum in 2021?
That cannot be established from the data. The account is present as forum staff from October 2006 to March 2010, which shows the alias was not created for the 2021 takeover announcement, but a support identity can change hands. Treat continuity of the name as a fact and continuity of the person as an open question.
How does this connect to modern ransomware operations?
Through governance rather than tooling. Vetting before access, published rules on prohibited targets, escrow, arbitration and expulsion for defrauding other criminals are all visible here years before ransomware-as-a-service adopted the same structures.
Sources and further reading
- Krebs on Security, Three Top Russian Cybercrime Forums Hacked
- Flashpoint, New Mysterious Operators Usurp Elite Russian Hacker Forum Verified
- Intel 471, Friendly fire: four well-known cybercriminal forums dealing with breaches
- Ransomnews, The REvil source-code developer behind a forum moderator account
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
