P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Threats

Extortion site (leak site): what it is and how it is attacked

The page an extortion group uses to name victims and publish what they took.

Also known as

  • leak site
  • data leak site
  • DLS
  • shame site
  • negotiation portal
  • victim blog

Typing any of them into the editor finds this object.

Why it matters on a security diagram

It is the second half of a modern extortion incident and the one the board hears about, and it is the reason a restored backup does not end the matter. A diagram that stops at encryption has drawn half the event.

How it gets attacked, and what reduces it

How it gets attacked

  • Not applicable: it is the adversary's own infrastructure
  • Publication used as the deadline, so the pressure is a clock rather than a technical problem
  • Naming before publishing, which extracts payment without releasing anything

What reduces it

  • Decide in advance who speaks and to whom, because the timetable will be set by somebody else
  • Assume publication when scoping notification duties rather than waiting for it
  • Preserve the listing as evidence, since it dates the claim and often names what was taken

Where it sits

Group
Threats · The adversary and the things they bring.
Whose side, by default
Attacker · Working against the organisation.
Catalogue identifier
leak-site

Reviewed . CC BY 4.0.

Others in threats

The threats group carries every object in it, including the ones with no page of their own.

Extortion site on your own diagram

Open the editor, press N, and type leak site. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.

Open the diagram maker