All data on Ransomwhere.org is sourced from open intelligence feeds. Use our proxy API for convenience or go directly to the upstream sources below.
Base URL: https://ransomwhere.org — All endpoints return JSON. No authentication required. Data is cached server-side.
/api/statsGlobal statistics — total victims, groups, attacks, last update timestamp.
/api/victimsRecent victim entries (last 100). Each includes victim name, group, country, sector, and discovery date.
/api/groupsAll tracked ransomware groups with profiles, leak site locations, and status.
/api/groups/:slugDetail for a specific group including all victims attributed to that group.
/api/newsLatest ransomware news from BleepingComputer and The Hacker News RSS feeds, filtered by ransomware keywords.
These are the original APIs and feeds that power Ransomwhere.org. Some require free API keys — registration details linked below.
Primary data source for all victim and group data.
https://api.ransomware.live/v2Auth: None (free, open)Bitcoin payment tracking. Contact for API access.
https://api.ransomwhe.re/v1Auth: API key required (free)IoC feed for ransomware-associated indicators.
https://threatfox-api.abuse.ch/api/v1Auth: API key required (free at auth.abuse.ch)Malware sample repository for ransomware binaries.
https://mb-api.abuse.ch/api/v1Auth: API key required (free at auth.abuse.ch)All data is provided for research and educational purposes. When using data from Ransomwhere.org, please attribute the original data sources listed above.
Rate limits: Our API is cached at the intervals shown above. For higher-frequency access, use the upstream APIs directly with your own API keys.