Dark Web Breach Sentinel — New Ransomware & Leak Alerts
Pricing
$250.00 / 1,000 breach alerts
Dark Web Breach Sentinel — New Ransomware & Leak Alerts
Watch a list of company names/domains and get alerted the moment one is disclosed as a ransomware or data-breach victim - built on the open ransomware.live threat-intel feed, with a per-client watchlist and alert-only-on-new-disclosure logic that generic breach lookup tools don't offer.
Pricing
$250.00 / 1,000 breach alerts
Rating
0.0
(0)
Developer
0xGollum
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
5 days ago
Last modified
Categories
Share
Watch a list of company names/domains and get alerted the moment one is disclosed as a ransomware or data-breach victim. Run on a schedule; only genuinely new disclosures since the last check are reported, never the same one twice, and never the full history dumped as "alerts" on the very first run.
How it actually works (read before assuming this browses .onion sites itself)
This does not crawl Tor/.onion sites directly. It consumes the free public API of
ransomware.live - an actively-maintained, respected open
threat-intel project that already does that crawling - and adds the part they don't offer:
a per-client watchlist with alert-only-on-new-disclosure logic. Verified live against the
real API (api.ransomware.live/v2/recentvictims) before shipping.
Checked against the closest Apify competitors before building (08/08/2026): "OnionSentinel" and "Ransomware & Dark Web Data Breach Monitor" both exist, but both are on-demand query/filter tools with no diffing over time - this is the one differentiated angle neither of them covers.
Input
- Keywords (required) — company names or domains to watch, e.g.
acme.com,Acme Corp. Matched case-insensitively as a substring against the victim name, domain, and description. - Request timeout.
Output
One row per newly disclosed match: watched_keyword, victim, domain,
ransomware_group, country, sector, attack_date, source_url, checked_at.
Known constraints
- Source feed only covers ransomware-gang leak-site disclosures, not every kind of breach (credential dumps, stealer logs, forum posts are out of scope for this version).
- First-ever run for a keyword establishes a silent baseline (no rows) rather than dumping historical matches as if they just happened - alerts start from the second run onward.