grid lines

[ Live Intelligence Index ]

The AlienGate Dark Web Database

A curated index of ransomware, darknet markets, and threat actors. Intelligence accessible only in the dashboard.

3,903

Ransomware attacks

3,963

Breach disclosures

1,849

Monitored nodes

50M

METI registration

5min

Alert response

[ Ransomware victim index ]

Ransomware attacks & victim index

CLASSIFIED · VIEW-ONLY

3,903 attacks tracked. Victim domains are partially masked; source URLs are redacted.

Filter

Showingof results

[ Source Coverage ]

What we monitor

REFERENCES REDACTED

1,849 nodes across four source classes, checked continuously for availability.

icon

162

Darknet markets

Tor and I2P marketplaces where credentials and access are traded.

142 ONLINE

20 OFFLINE

icon

594

Ransomware threat actors

Leak sites and negotiation portals run by active ransomware operations.

142 ONLINE

20 OFFLINE

icon

126

Infostealer channels

Telegram channels distributing RedLine, Lumma, Vidar and Raccoon logs.

142 ONLINE

20 OFFLINE

icon

967

Threat actor channels

Telegram groups used for coordination, recruitment and data brokering.

142 ONLINE

20 OFFLINE

Showing 1-12 of 3903 results

Showing 1-12 of 3903 results

Showing 1-12 of 3903 results

Showing 1-12 of 3903 results

[ Threat actor groups ]

120+ groups tracked continuously

AlienGate continuously tracks 120+ active ransomware groups across dark web leak sites, Telegram channels, and underground forums.

LockBit

386

Cl0p

412

BlackCat

174

ALPHV

168

Medusa

142

Akira

241

Black Basta

118

Hive

96

Maze

64

Ryuk

58

Conti

147

REvil

89

DarkSide

42

DragonForce

76

Lynx

54

Qilin

164

Monti

38

NightSpire

29

INC Ransom

129

Play

156

Hunters International

91

Royal

73

RansomHub

198

KillSecurity

44

Fog

61

8Base

83

Abyss

27

Vice Society

52

Snatch

36

AvosLocker

48

Lorenz

31

Embargo

24

BianLian

107

Ragnar Locker

39

BlackSuit

94

Omega

22

CoinbaseCartel

18

TheGentlemen

87

NoEscape

41

Meow

33

Scattered Spider

67

+ 80 more groups

AlienGate's dark web intelligence database covers ransomware attacks and data breach disclosures attributed to all major threat actor groups. This includes LockBit ransomware victims, Clop ransomware disclosure leaks, BlackCat (ALPHV) ransomware breach data, Medusa ransomware attacks, Akira ransomware victim organizations, DragonForce ransomware incidents, and hundreds of smaller ransomware-as-a-service (RaaS) operators. Our breach database tracks victim organizations across healthcare, manufacturing, legal, financial services, education, and government sectors. All records include the victim organization name, victim domain, threat actor attribution, and date of discovery. Source URLs and dark web links are masked and accessible only through the AlienGate secured dashboard.

[ Faq ]

Frequently asked questions

Everything you need to know about the product and billing.

Simply sign up with your email and enter your company domain. You can start with a free breach check immediately, and expand to continuous monitoring when ready.

No. AlienGate supports DAST beyond OWASP Top 10, providing comprehensive coverage including network vulnerability scanning capable of detecting 15,000+ CVEs.

AlienGate provides screenshots, port/service details, technology detection, and credential exposure context—giving you the proof needed to validate risks and justify remediation priorities.

Yes. The Investigations feature turns alerts into trackable cases with assigned owners, status tracking, and evidence collection. Reports can be generated for executives and compliance teams.

AI accelerates operations with automated risk scoring, smart summaries of findings, and next-action guidance—helping teams focus on what matters most without manual triage.

3,903 organisations are already in here. Check whether yours is.

Forty seconds against the full unmasked index. No card, no sales call, just whether your domain appears and where it came from.