The ransom note is the last message. Where were the earlier ones?
Ransomware is a supply chain, and the encryption event sits at the end of it. Access is brokered, priced and escrowed weeks earlier, in public, by people who advertise. Your name appears in that market long before it appears on a leak site.
The four places the current answer runs out
Your first alert is their last step
If detection begins at the payload, the access was sold weeks ago, the reconnaissance is finished and the exfiltration is complete. You are not detecting an attack; you are receiving its invoice.
The access listing names your sector, not you
"Manufacturing, $400M revenue, AD admin, $12k" is a description of maybe four companies. Nobody on your team is reading those posts, and the language they are written in is often not one your feed covers.
Leak-site posts disappear
Victim entries get pulled when negotiation starts and re-posted when it fails. If you only see the site when you go looking, you see whichever version the crew wants public today.
The vulnerability was in the backlog
The edge device that let them in had a CVE with a mediocre CVSS score and an active exploit market. Your prioritization saw the score; the crew saw the price.
How extortion stopped needing encryption
Every era added a lever and kept the old ones. The defensive posture that only detects encryption is now watching the least-used tool in the kit.
THREAT EVOLUTION
EACH ERA STACKED ON THE LAST
2016-2019
Encrypt and demand
A single lever: your files are locked, pay for the key. Good backups were a near-complete answer, and the industry duly bought backups.
2020-2023
Double extortion
Exfiltrate first, then encrypt, then publish on a leak site if the invoice goes unpaid. Backups stop being a defence against the second lever, because the data is already gone.
YOU ARE HERE
2024-2026
Extortion without encryption
Crews increasingly skip the payload entirely: steal, publish a proof pack, run a countdown. There is no malware for the EDR to catch, and the first technical artefact of the attack may be a blog post.
Next
Regulator-timed pressure
Disclosure deadlines become the leverage. The countdown is aimed less at your operations than at the window in which you must notify a regulator, and it is set by whoever reads the law faster.
Five plays, and the window each one runs in
Every play names the module that does the work. Nothing here is a capability we describe without shipping.
Watch the wholesale layer
Access-broker listings, sector-shaped and priced, indexed across the forums where they run. Catching your own profile in a listing is the cheapest incident response you will ever run.
DRAGNETThe archive outlives the post
Leak-site entries, countdowns and proof packs are captured as they are found and kept afterwards: our own copy, the page as it looked, and the time we first read it. We do not watch for the moment a crew pulls an entry and we record no deletion time, so what you hold is the version we saw, which is the version that survives their editing.
DRAGNETRead the deal, not the advert
The forum post is the storefront; price, samples and escrow move to Jabber, and that room corpus is indexed full-text. Nothing labels a thread as escrowed for you, you read it, but a thread where a guarantor has been brought in is a materially different signal from a braggart's post, and only one of them means a buyer exists.
JABBERNAUTPatch what the crews are buying
CVEs carry their ransomware-campaign linkage, their KEV status and how far the public exploit has matured, which turns a 400-item backlog into the short list of vulnerabilities the crews have already tooled up against.
CVEKITThe crew plans where the leak site can't show you
A countdown is a public artefact; the decision to start one is made earlier, in an invite-only Discord server, alongside affiliate recruitment and target selection. Indexed the same way and searchable the same way as the rest, so the plan can be read beside the listing and the thread. They remain three queries against three corpora; what changes is that the third one is no longer missing.
GUILDWIREThree weeks before the note
An access broker posts on an underground forum: manufacturing, revenue band, domain admin. No company name; those go to serious buyers in private.
Dragnet indexes the post with its screenshot. Nothing fires, because nothing is watching on your behalf; the post is now simply searchable, and the revenue band and employee count in it narrow the victim to a handful of firms.
Your weekly sector sweep returns it, and you are one of the handful. Reading it costs a minute.
You take the listing to the Jabber corpus and find a garant thread naming the same access. Escrow means a buyer, a price and a date. You now have a countdown nobody has told you about.
You hunt on the assumption of compromise rather than the possibility of it, and find the foothold on an edge appliance whose CVE was in next quarter's window.
The move, stated plainly
No customer logos and no invented percentages: we have not deployed long enough to have honest ones. What we can state is what the workflow becomes.
You find out when the files stop opening
You find out when the access is advertised, while it is still a hypothesis you can hunt
The leak-site entry is gone when legal asks for it
Our copy, its screenshot and the time we first read it sit in the case file
Patch order follows CVSS
Patch order follows what the crews are buying, with the listing attached to the change ticket
Ransomware early warning, honestly answered
The other four
Credential exposure
We do not stop the login. We hold the record that would have made it work, and you can search it today.
Vulnerability triage
Your backlog is sorted by severity. The attacker's is sorted by price.
Brand & executive exposure
Your executives are discussed in channels they cannot open, in languages your feed does not read.
Fraud & abuse
The chargeback is the symptom. The breach that caused it happened somewhere upstream.
Your competitors will learn about the leak from the invoice.
Learn about it from the log batch.
NDA-friendly briefings · global coverage · no slideware