Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

What Ward checks

Area: Reputation and impersonation

Ransomware

Looks for your domain and your company name on ransomware groups' leak sites, using recent data from RansomLook and RansomFeed that we download every few hours and match on our servers.

What it can report

Open each one to see what it means and how to fix it.

Mentioned on a ransomware leak site

What it means

A ransomware group has listed example.com as a victim on its leak site. Ransomware groups encrypt a company's files and steal copies, then publish the victims to pressure them into paying.

What could happen

If it's really your company, someone has probably already been inside your systems and may hold your data, with legal duties if it includes personal data. If it isn't, because leak sites sometimes show a wrong website for a victim, nothing else is needed. Check it first, and quickly.

How an attacker would use it

Criminals got in through an exposed remote access or a stolen password, spent days looking around and copying files, then encrypted the servers and demanded payment. When the deadline passed, they posted the company on their site to pressure it, and customers and the press can see it.

How to fix it

  1. Check the post: the victim's name, country and website in the technical details. Is it your company?If it isn't, mark the finding as a false positive with a note.
  2. If it is, activate your incident response plan and contact a specialist incident response team and your cyber insurance carrier before deciding anything about the demand.
  3. Disconnect the affected systems from the network and keep them as they are, to preserve evidence.
  4. Change all passwords from a clean device, starting with email, remote access and administrator accounts.
  5. Report it to the FBI (ic3.gov) and CISA (cisa.gov/report).
  6. Ask a lawyer about breach-notification obligations if personal data is involved, and prepare what you'll tell customers.

How to check it's fixed

Ward downloads the leak-site data regularly and compares it with your domain again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

vosotros

Example with sample data. In your dashboard, the explanation uses your own domain and details.