Ransomware leak sites are usually read one announcement at a time: a victim appears, journalists confirm, the entry either gets a data dump or quietly disappears. Read as a longitudinal dataset instead, every announcement across dozens of sites, each kept with the time we first saw it, the blogs describe the industry better than any of its press releases.
The most informative moment is the one where an entry stops being reachable. Entries are re-checked on a schedule, so a victim listing that disappears is observable to within a re-check interval. Be careful what that window measures. It is how long the victim stayed publicly named, not how long the negotiation ran, because negotiation normally begins before the announcement, which is itself a pressure tactic. A disappearance is not proof of payment either: entries also come down after law-enforcement action, after a rebrand, or because the group withdrew a claim it could not support. Read with those limits, the windows still separate groups sharply. Some clear listings in days, others leave them up for over a month.
ANNOUNCEMENT → ENTRY GONE · BY GROUP
sample figuresGRP ··K
n=61
GRP ··V
n=44
GRP ··R
n=37
GRP ··T
n=23
DELETION WITHOUT A DUMP USUALLY MEANS PAYMENT
Language and geography matter too. Victims that first surface in non-English channels remain systematically underrepresented in English-language reporting, however large the incident. An announcement in a Telegram channel that no western feed monitors is, for practical purposes, invisible to the victim's own industry peers.
Everything here came from Dragnet's own archive. What we collected stays readable with the time we first saw it and the page as it was captured, whether or not the original is still up. The dataset is in the product today.