The essentials
- Verify first: leak-site "proof" is sometimes recycled from old breaches, inflated, or another company's data entirely.
- Capture the listing and samples immediately — postings change and vanish, and you will need the record.
- The posting itself starts clocks: regulators, contracts, and insurers may all have notice requirements regardless of what you pay or say.
- Paying for "deletion" buys a promise from criminals; there is no verification, and copies routinely survive.
- If the data is real, the intrusion that took it may still be live — scoping the source breach comes with the response.
Leak sites exist to add public shame to private extortion — the countdown, the logo wall, the journalist tips are all pressure engineering. Some listings precede real, devastating dumps. Others are bluffs stapled to stale data.
Which one you are facing is a question of evidence, and everything sensible you do next — legal, communications, negotiation posture — depends on answering it before reacting.
Do this now
- Capture everything now. Screenshots and archived copies of the listing, samples, and countdown, with timestamps. Repeat as the posting changes.
- Verify the samples. Have the smallest possible team check: is this our data, is it current, what systems does it come from, does it match a known old breach instead?
- Stand up the response. Counsel and incident responders together — the leak listing is both a legal event and evidence of an intrusion that needs scoping. If you have cyber insurance, notice goes out now.
- Assess the source breach. If the data is genuine, find the exfiltration: when, from where, and whether access persists. Eviction and leak response run in parallel.
- Run the notification analysis. Based on what is verifiably exposed — regulators, individuals, and contractual parties, on the clocks that apply. Document the reasoning either way.
- Prepare communications on facts. Holding statements that promise investigation age well; specific denials issued before verification do not. Monitor the site for updates and further posts.
What not to do
- Do not contact the attackers through the leak portal without counsel and a strategy — first contact sets the negotiation.
- Do not pay for deletion expecting deletion; assume copies persist regardless.
- Do not publicly deny before verification, or confirm beyond what is verified.
- Do not let staff download the dump onto ordinary machines to "check it" — handle it forensically.
- Do not treat the listing as the incident; it is the symptom of one.
Preserve the evidence
Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:
- Archived copies and screenshots of the listing and samples over time.
- The verification analysis: what matched, what didn't, which systems.
- Exfiltration indicators from the source-breach investigation.
- The notification decision log with timestamps.
Keep a clear head
Countdowns are theater aimed at the boardroom — they exist to compress your decision-making below the speed of verification. The organizations that navigate leak listings well are the ones that let evidence, counsel, and process set the pace, and treat the timer as scenery.
Questions victims ask
They promise deletion if we pay. Is that real?
You would be buying an unverifiable promise from an extortion business. Some crews do remove listings after payment; whether copies survive is unknowable, and resale has happened. Treat exposed data as exposed regardless of payment.
How do we know the leak is real?
Sample analysis: match files, records, and timestamps against your systems. Real leaks match current internals; bluffs recycle old breaches, public data, or another victim's files. The answer is usually clear within hours of honest checking.
Do we have to tell customers if it's real?
Often, and on defined clocks depending on jurisdiction and contracts. That determination needs counsel working from the verified scope — which is why verification and capture come first.