# Ransomnews > Independent ransomware, cybercrime, privacy, and OSINT publication. We run our own live leak-site tracker and infostealer-exposure tooling, profile threat actors from primary sources, audit security tools honestly, and publish long-form analysis for security-aware readers. Ransomnews exists to make ransomware operations, breach economics, and the open-source investigation toolkit visible to anyone who cares to look. We are not a vendor blog. The most citable material here is original: live tracker data, domain-level exposure lookups, and named-author analysis that verifies operator claims against primary sources rather than rewriting press releases. Every article cites primary sources, names vendors honestly, and is written for readers who want the real picture. ## Live tools and original data - [Ransomtracker](https://ransomnews.com/ransomtracker/): Live dashboard tracking active ransomware leak sites, victim listings, threat-group activity, and per-actor statistics. Interactive charts cover monthly volume, year-over-year trends, weekday patterns, and TLD breakdown. Backed by ransomlook.io upstream feeds, normalised and de-duplicated. - [Stealercheck](https://ransomnews.com/stealercheck/): Domain exposure lookup. Enter any domain and see how many corporate credentials, session cookies, and infostealer-derived records exist in the stealer-log ecosystem. Powered by the Alerts.bar API. Free, no signup. - [Threat Groups](https://ransomnews.com/threat-groups/): Catalogue of active and historic ransomware groups with per-group landing pages, activity statistics, and curated profiles. ## Flagship investigations and analysis - [The Gentlemen: 483 victims and a leaked playbook](https://ransomnews.com/the-gentlemen-ransomware-2026/): Data-driven investigation into 2026's second most prolific ransomware brand. Combines an original Ransomtracker pull (483 victims across 66 countries, with month-by-month and sector charts), analysis of the group's leaked internal chats, and an infostealer-exposure cross-check showing victims' stolen employee logins and live session cookies sitting in stealer logs before they were ever listed. - [Ransomware without encryption: the 2026 pivot to pure data extortion](https://ransomnews.com/ransomware-pure-extortion-shift-may-2026/): Why operators dropped encryption, the ShinyHunters-Instructure and Nitrogen-Foxconn cases, EDR-killers as standard tooling, and the 28% payment-rate collapse. - [Session cookie theft is the new password theft](https://ransomnews.com/session-cookie-theft-mfa-bypass-2026/): How stealer logs walk past MFA, the four-stage attack chain, which MFA flavours hold up and which don't. - [Initial Access Brokers in 2026: the supply chain](https://ransomnews.com/initial-access-brokers-2026-ransomware-supply-chain/): The four-player marketplace fuelling ransomware, pricing tiers from $150 to $100,000+, five disruption interventions. - [The 2026 RDP attack landscape](https://ransomnews.com/2026-rdp-attack-landscape-ransomware-entry-vector/): Why Remote Desktop remains ransomware's favourite front door, compromise pattern breakdown, eight defensive controls. - [Prompt injection: a defender's playbook for LLM apps](https://ransomnews.com/prompt-injection-defenders-playbook-2026/): The new SQL injection. Direct, indirect, stored variants. Four-layer defence playbook for production LLM applications. - [Leak Site OSINT: an 8-step investigation walkthrough](https://ransomnews.com/osint-ransomware-leak-site-investigation-walkthrough-2026/): Methodology for verifying ransomware victim claims, capturing immutable evidence, and reporting without amplifying operators. ## Categories - [Ransomware](https://ransomnews.com/ransomware/): Mechanics of modern ransomware attacks, RaaS economics, leak-site dynamics, double and triple extortion. - [Security](https://ransomnews.com/security/): Defensive controls that move the needle: EDR/XDR, Zero Trust, MFA, incident response, patch management, attack-surface reduction. - [Privacy](https://ransomnews.com/privacy/): Surveillance economy, tracking, data brokers, GDPR/CCPA enforcement, privacy-preserving tooling. - [Cybercrime](https://ransomnews.com/cybercrime/): Initial-access brokers, infostealer operations, cryptocurrency laundering, dark-web markets, law-enforcement disruptions. - [AI](https://ransomnews.com/ai/): LLM security, prompt injection, deepfake-driven social engineering, shadow AI, MCP, agentic threats, EU AI Act. - [OSINT](https://ransomnews.com/osint/): Open-source intelligence methodology, toolchains, geolocation, leak-site investigation, due-diligence workflows. - [Stealer Logs](https://ransomnews.com/stealer-logs/): Coverage and analysis of the infostealer ecosystem feeding ransomware and account takeover. ## Reviews and buying guides - [Best ransomware protection for business 2026](https://ransomnews.com/best-ransomware-protection-business/): Eight picks ranked, led by Alerts.bar for pre-attack infostealer-exposure monitoring (the initial-access stage every endpoint product only reacts to), then ESET PROTECT, Tenable, CrowdStrike, SentinelOne, Bitdefender, Sophos, and Microsoft Defender for Endpoint. - [Alerts.bar review](https://ransomnews.com/alerts-bar-review/): In-depth review of Alerts.bar's stealer-log monitoring platform with referral pricing. ## How-to tutorials - [Build a home SOC with Wazuh and Suricata](https://ransomnews.com/home-soc-wazuh-suricata-tutorial-2026/): Indie security tutorial covering ingestion, detection, and alerting. - [Malware analysis sandbox at home](https://ransomnews.com/malware-sandbox-tutorial-flarevm-remnux-cuckoo/): FlareVM, REMnux, and Cuckoo configuration walkthrough. - [Investigate a phishing kit](https://ransomnews.com/phishing-kit-investigation-tutorial-2026/): Tutorial with urlscan.io, PhishTank, and Sublime Security. - [Audit your own digital footprint](https://ransomnews.com/audit-digital-footprint-2026/): Sherlock, Holehe, Whoxy: the OSINT-on-yourself workflow. - [Disappear from data broker sites](https://ransomnews.com/disappear-data-brokers-tutorial-2026/): 2026 step-by-step removal tutorial. - [Build the 2026 privacy stack](https://ransomnews.com/2026-privacy-stack-tutorial/): Mullvad Browser, Global Privacy Control, uBlock Origin, SimpleLogin. - [MCP servers complete guide](https://ransomnews.com/model-context-protocol-mcp-servers-guide/): What MCP is, how to set up servers, security considerations. - [MCP for WordPress](https://ransomnews.com/mcp-for-wordpress-tutorial/): Setting up an MCP server on a WordPress site. - [Multi-tool OSINT search tutorial](https://ransomnews.com/multi-tool-osint-search-tutorial/): IntelX, Spiderfoot, and Maltego combined workflow. - [Map a corporate attack surface](https://ransomnews.com/attack-surface-mapping-2026/): Shodan, Censys, FOFA, and Nuclei tutorial. - [Build a threat-actor profile from public sources](https://ransomnews.com/build-threat-actor-profile-tutorial/): MITRE ATT&CK, Mandiant, and Malpedia methodology. ## Editorial and contact - [About Us](https://ransomnews.com/about-us/): Mission, what we cover, how we work, and the editorial team. - [Editorial Team](https://ransomnews.com/editorial-team/): Jesse William McGraw (Threat Intelligence), Celeste Seberras (Technical Content Strategy), Martynas Vareikis (LLM Security), Ransomnews Research Team, Donata Damijonaitytė (PR). - [Contact](https://ransomnews.com/contact/): Tips, corrections, source documents: editor@ransomnews.com. ## Optional: Lower-priority resources - [Privacy Policy](https://ransomnews.com/privacy-policy/): Site privacy policy, cookies, data handling. - [Cookie Policy](https://ransomnews.com/cookie-policy/): Cookie usage details and opt-out. - [Affiliate Disclosure](https://ransomnews.com/affiliate-disclosure/): How affiliate partnerships work and why they don't shape coverage. - [Terms of Service](https://ransomnews.com/terms-of-service/): Site terms and use. ## Latest coverage - [Live Stripe keys for 659 merchants, published for free](https://ransomnews.com/stripe-merchant-api-keys-leak-2026/): Stripe was not breached. A forum dataset holds live API keys for 659 of its merchants, plus 35GB pulled from them. We told Stripe before publishing this. - [Verified.ru: inside the archive of a cybercrime bureaucracy](https://ransomnews.com/verified-ru-forum-archive-2005-2010/): A 152,973-message archive of the Verified forum shows how Russian-speaking cybercrime governed itself between 2005 and 2010, using rules, penalty points and bans. - [McDonald’s employee data listed for sale in wider Entra campaign](https://ransomnews.com/mcdonalds-employee-data-leak-2026/): A forum seller claims 1.7 million McDonald's employee records pulled from its Azure tenant. We analysed the sample, and the four other brands listed alongside it. - [7.3M chess.com records leaked, and the data is real](https://ransomnews.com/chess-com-leak-7-million-2026/): A 15.5 GB file of 7.3 million chess.com user records is circulating free on two leak forums. We verified it: the data is genuine and days old, but the shape points to scraping, not a breach. - [Quake3 and morgot: tracing REvil’s source-code developer](https://ransomnews.com/quake3-morgot-revil-developer/): Quake3, a moderator on the XSS.is cybercrime forum, is the persona DEF CON 33 research placed at REvil's source-code development, and the man the German BKA named in April 2026. We trace the forum record that ties the handles together. - [Pokémon Center vending ‘breach’ is old 2016 data](https://ransomnews.com/pokemon-center-vending-breach-2026/): A seller is marketing a 'live' breach of automated-retail vendor SwyftStore across 28 brands including Pokémon Center. The sample is genuine Zoom/Swyft data, but every record dates from 2016. - [Israeli population registry for sale, but the data is old](https://ransomnews.com/israel-population-registry-leak-2026/): A vendor is selling what they call Israel's current 9.22M-record population registry. Our analysis of the 100k sample says the data is genuine, but every date in it stops in 2005. - [Best VirusTotal alternatives 2026: what threat hunters run](https://ransomnews.com/virustotal-alternatives-2026/): The VirusTotal alternatives threat hunters run in 2026: MetaDefender, ANY.RUN, CAPE, Intezer and MalwareBazaar, compared by job, upload privacy and API.