Dark Web Breach Sentinel — New Ransomware & Leak Alerts avatar

Dark Web Breach Sentinel — New Ransomware & Leak Alerts

Pricing

$250.00 / 1,000 breach alerts

Go to Apify Store
Dark Web Breach Sentinel — New Ransomware & Leak Alerts

Dark Web Breach Sentinel — New Ransomware & Leak Alerts

Watch a list of company names/domains and get alerted the moment one is disclosed as a ransomware or data-breach victim - built on the open ransomware.live threat-intel feed, with a per-client watchlist and alert-only-on-new-disclosure logic that generic breach lookup tools don't offer.

Pricing

$250.00 / 1,000 breach alerts

Rating

0.0

(0)

Developer

0xGollum

0xGollum

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

5 days ago

Last modified

Share

Watch a list of company names/domains and get alerted the moment one is disclosed as a ransomware or data-breach victim. Run on a schedule; only genuinely new disclosures since the last check are reported, never the same one twice, and never the full history dumped as "alerts" on the very first run.

How it actually works (read before assuming this browses .onion sites itself)

This does not crawl Tor/.onion sites directly. It consumes the free public API of ransomware.live - an actively-maintained, respected open threat-intel project that already does that crawling - and adds the part they don't offer: a per-client watchlist with alert-only-on-new-disclosure logic. Verified live against the real API (api.ransomware.live/v2/recentvictims) before shipping.

Checked against the closest Apify competitors before building (08/08/2026): "OnionSentinel" and "Ransomware & Dark Web Data Breach Monitor" both exist, but both are on-demand query/filter tools with no diffing over time - this is the one differentiated angle neither of them covers.

Input

  • Keywords (required) — company names or domains to watch, e.g. acme.com, Acme Corp. Matched case-insensitively as a substring against the victim name, domain, and description.
  • Request timeout.

Output

One row per newly disclosed match: watched_keyword, victim, domain, ransomware_group, country, sector, attack_date, source_url, checked_at.

Known constraints

  • Source feed only covers ransomware-gang leak-site disclosures, not every kind of breach (credential dumps, stealer logs, forum posts are out of scope for this version).
  • First-ever run for a keyword establishes a silent baseline (no rows) rather than dumping historical matches as if they just happened - alerts start from the second run onward.