The gang behind the Conti ransomware has joined the ranks of hackers who create “leak sites” for victims’ data.

One of the biggest threats in cyberspace is ransomware attacks. However, in recent months, more and more ransomware gangs have been combining these attacks with data, creating so-called “leak sites,” which they use to expose sensitive documents from companies that refuse to pay the ransom.
These “leak sites” are a new trend, as ransomware is adopting a new tactic called “double extortion.”
A representative example of how ransomware gangs use “leak sites” and “double blackmail” to put pressure on victimsis the case of the University of Utah.
A few days ago, the university administration admitted to paying a large sum to a ransomware gang, despite having restored the encrypted files via backups.
The university said it was forced to pay the gang because the hackers threatened to leak files containing sensitive student data.
More and more ransomware gangs are creating leak sites
These days, more and more ransomware gangs are turning to leak sites to put additional pressure on victims.
The good news is that not all gangs have their own website. However, their number has been steadily increasing since December 2019, when the operators of the Maze ransomware took the lead and created the first site.
Today, the list of ransomware gangs using leak sites includes: Ako, Avaddon, CLOP, Darkside, DoppelPaymer, Maze, Mespinoza (Pysa), Nefilim, NetWalker, RagnarLocker, REvil (Sodinokibi), and Sekhmet.
Some of these groups are not particularly well-known, but there are others like Maze, DoppelPaymer, REvil, and NetWalker that are among the biggest threats.
Other groups, such as BitPaymer, WastedLocker, LockBit, ProLock, and Dharma, have yet to adopt this tactic . One reason may be that some groups do not want to attract too much attention, and leak sites tend to attract too much attention from journalists, cybersecurity companies , and law enforcement officials
Conti ransomware creates its own leak site
Since last week, another major ransomware group has joined the double blackmail game and created its own leak site.
The group operates the relatively new Conti ransomware, which is said to be used by the operators of the Ryuk ransomware.
The Conti ransomware group's leak site was discovered by a malware analyst under the pseudonym BreachKey. The site is available at different URLs on both the public Internet and the dark web.
BreachKey said the site already includes records from 26 companies that have fallen victim to the group's attacks and have refused to pay the ransom.

The creation of yet another leak site shows that the double blackmail system is here to stay.
This new trend also means that changes need to be made to the way companies deal with ransomware attacks. While in the past, victim companies only had to recover files and get back to their daily activities, now they also have to deal with the breach and potential data leak.
