Skip to content

Actor Profiles

Actor profiles collect the intelligence eCrime.ch has observed for a ransomware group, extortion actor, or leak-site brand.

Actor profile overview

The profile header summarizes the actor and gives fast context:

  • first and last observed activity
  • tracked events
  • indexed events and removed events
  • confirmed data-leak rate
  • torrent intelligence coverage
  • average indexed file counts where available

The timeline and trend sections help distinguish recently active groups from historical brands, rebrands, and inactive leak sites.

Depending on available data, a profile can include:

  • management-level key facts
  • analyst assessment
  • leak-site screenshots and evidence
  • torrent coverage and peer-observation summaries
  • geography and sector distribution
  • tradecraft, tools, and vulnerability references
  • source links, notes, and related reporting

Not every actor has the same depth of coverage. Newer or short-lived sites may have only basic event and screenshot evidence, while long-running actors usually have richer profile, torrent, file, and victimology data.

Use actor profiles to answer questions such as:

  • Is this actor currently active?
  • Which countries and sectors does it most often affect?
  • Has eCrime.ch observed leaked data or only claims?
  • Are torrent peers or recurring infrastructure visible for this actor?
  • Which vulnerabilities, tools, or aliases are associated with this group?

Actor profiles are also linked from search results, event detail pages, and intelligence navigation.