SOLUTION 02 · For incident response and the CISO

The ransom note is the last message. Where were the earlier ones?

Ransomware is a supply chain, and the encryption event sits at the end of it. Access is brokered, priced and escrowed weeks earlier, in public, by people who advertise. Your name appears in that market long before it appears on a leak site.

01Why it keeps happening

The four places the current answer runs out

Your first alert is their last step

If detection begins at the payload, the access was sold weeks ago, the reconnaissance is finished and the exfiltration is complete. You are not detecting an attack; you are receiving its invoice.

The access listing names your sector, not you

"Manufacturing, $400M revenue, AD admin, $12k" is a description of maybe four companies. Nobody on your team is reading those posts, and the language they are written in is often not one your feed covers.

Leak-site posts disappear

Victim entries get pulled when negotiation starts and re-posted when it fails. If you only see the site when you go looking, you see whichever version the crew wants public today.

The vulnerability was in the backlog

The edge device that let them in had a CVE with a mediocre CVSS score and an active exploit market. Your prioritization saw the score; the crew saw the price.

02How it got here

How extortion stopped needing encryption

Every era added a lever and kept the old ones. The defensive posture that only detects encryption is now watching the least-used tool in the kit.

THREAT EVOLUTION

EACH ERA STACKED ON THE LAST

  1. 2016-2019

    Encrypt and demand

    A single lever: your files are locked, pay for the key. Good backups were a near-complete answer, and the industry duly bought backups.

  2. 2020-2023

    Double extortion

    Exfiltrate first, then encrypt, then publish on a leak site if the invoice goes unpaid. Backups stop being a defence against the second lever, because the data is already gone.

  3. YOU ARE HERE

    2024-2026

    Extortion without encryption

    Crews increasingly skip the payload entirely: steal, publish a proof pack, run a countdown. There is no malware for the EDR to catch, and the first technical artefact of the attack may be a blog post.

  4. Next

    Regulator-timed pressure

    Disclosure deadlines become the leverage. The countdown is aimed less at your operations than at the window in which you must notify a regulator, and it is set by whoever reads the law faster.

03What we do about it

Five plays, and the window each one runs in

Every play names the module that does the work. Nothing here is a capability we describe without shipping.

Watch the wholesale layer

Access-broker listings, sector-shaped and priced, indexed across the forums where they run. Catching your own profile in a listing is the cheapest incident response you will ever run.

DRAGNET

The archive outlives the post

Leak-site entries, countdowns and proof packs are captured as they are found and kept afterwards: our own copy, the page as it looked, and the time we first read it. We do not watch for the moment a crew pulls an entry and we record no deletion time, so what you hold is the version we saw, which is the version that survives their editing.

DRAGNET

Read the deal, not the advert

The forum post is the storefront; price, samples and escrow move to Jabber, and that room corpus is indexed full-text. Nothing labels a thread as escrowed for you, you read it, but a thread where a guarantor has been brought in is a materially different signal from a braggart's post, and only one of them means a buyer exists.

JABBERNAUT

Patch what the crews are buying

CVEs carry their ransomware-campaign linkage, their KEV status and how far the public exploit has matured, which turns a 400-item backlog into the short list of vulnerabilities the crews have already tooled up against.

CVEKIT

The crew plans where the leak site can't show you

A countdown is a public artefact; the decision to start one is made earlier, in an invite-only Discord server, alongside affiliate recruitment and target selection. Indexed the same way and searchable the same way as the rest, so the plan can be read beside the listing and the thread. They remain three queries against three corpora; what changes is that the third one is no longer missing.

GUILDWIRE

Also drawn onSherlogMalveine

Also searchedTelepathy

04In practice

Three weeks before the note

Day 0

An access broker posts on an underground forum: manufacturing, revenue band, domain admin. No company name; those go to serious buyers in private.

Day 0

Dragnet indexes the post with its screenshot. Nothing fires, because nothing is watching on your behalf; the post is now simply searchable, and the revenue band and employee count in it narrow the victim to a handful of firms.

Day 1

Your weekly sector sweep returns it, and you are one of the handful. Reading it costs a minute.

Day 2

You take the listing to the Jabber corpus and find a garant thread naming the same access. Escrow means a buyer, a price and a date. You now have a countdown nobody has told you about.

Day 3

You hunt on the assumption of compromise rather than the possibility of it, and find the foothold on an edge appliance whose CVE was in next quarter's window.

05What changes

The move, stated plainly

No customer logos and no invented percentages: we have not deployed long enough to have honest ones. What we can state is what the workflow becomes.

You find out when the files stop opening

You find out when the access is advertised, while it is still a hypothesis you can hunt

The leak-site entry is gone when legal asks for it

Our copy, its screenshot and the time we first read it sit in the case file

Patch order follows CVSS

Patch order follows what the crews are buying, with the listing attached to the change ticket

Questions

Ransomware early warning, honestly answered

Your competitors will learn about the leak from the invoice.

Learn about it from the log batch.

NDA-friendly briefings · global coverage · no slideware