In late February 2022, after the Conti group posted a message backing Russia over the invasion of Ukraine, a Ukrainian researcher published the group’s internal communications. Reporting describes an initial dataset of 393 JSON files holding 60,094 messages spanning 21 January 2021 to 27 February 2022, followed by a further release of around 107,000 messages, along with source code and administrative panel material.
The access is described as the group’s XMPP chat server backend. Researchers who examined the material assessed it as genuine.
This Corpus Almost Never Sees The Inside
Nearly every file in this database is written from the victim’s side of the glass — a notification letter, a regulatory filing, a vendor report. The corpus records at 26-0802 that a quarter of its files cannot even establish how the intruder got in, because the organisation did not say.
The Conti leak is one of the few moments where the other side is legible: not what a group did to someone, but how it decided what to do. That is why this file exists despite there being no victim organisation and no affected population to count.
It Reads Like A Software Company
The reported contents describe organisational structure, negotiation practice, evasion of law enforcement, and development priorities — including a recurring engineering problem with encrypting very large files.
That last detail is the useful one. A criminal operation with a backlog and a performance bug is an operation with constraints, deadlines and people who are bad at their jobs. This corpus files extortion groups as actors with capabilities; the leak is the reminder that they are also organisations with limits, and that the limits are exploitable.
The Cause Was Politics, Not Policing
No law enforcement operation produced this. The group published a political statement, and someone with access objected to it strongly enough to burn that access.
The corpus records enforcement outcomes at 26-0716b, where two men were sentenced, and at 26-0707, where a botnet was rebuilt within six days of seizure. This file records a third mechanism, which no state controls and none can repeat on demand: an operation of this kind is held together by the agreement of people who can each individually end it.
Built on contemporaneous reporting and vendor analyses of the leaked dataset. The February 2022 timing, the pro-Russia statement, the 393 files / 60,094 messages figure and date range, the subsequent ~107,000-message release, the XMPP/Jabber server as the described source, and the general characterisation of the contents are as reported. This desk has not obtained or examined the dataset and does not reproduce any of its contents beyond what is described in published reporting. Bitcoin balances circulated at the time are not carried: valuations quoted then were contested and are not something this desk can verify. The researcher is not named. Graded high on the event, medium on any specific claim about what the chats contain. Corrections: corrections@forensicpost.com.