On 11 February 2025 an account using the handle ExploitWhispers published the internal chat archive of the Black Basta ransomware operation. Reporting puts the volume at roughly 197,000 to 200,000 messages, drawn from around 80 chatrooms across Matrix servers on six domains.
Nearly everything else in this corpus is a description of an attacker written by somebody outside the attack — a victim notification, a vendor report, a regulator’s finding, a court filing. This is the operation describing itself, to itself, with no expectation of being read.
The Date Range Is Reported Inconsistently
Analyses agree the archive begins around September 2023. They disagree on where it ends: some place the last messages in June 2024, others in the autumn of that year. This desk has not resolved the discrepancy and does not treat any endpoint as settled.
The gap matters for anything inferred from silence. An archive ending in June 2024 says nothing about the eight months before the group went quiet.
The Leaker Gave A Reason
ExploitWhispers said the group had crossed a line by attacking Russian banks. Whether that is the real motive, a cover, or one grievance among several is not established. It is a stated reason, not a demonstrated one.
The identity of the leaker is likewise unestablished. Reporting variously describes a disgruntled affiliate and a rival operator. Both are inferences from the contents.
Multiple Firms Judged The Archive Authentic
Research teams that had worked Black Basta incident response reported that operational details in the chats matched their own casework — infrastructure, timing, victim names they already knew. That is the strongest available authenticity test short of a prosecution, and it is why this file is graded high.
It is not a guarantee. An archive can be authentic in bulk and still contain inserted or removed material, and no analyst reviewed it before publication. Nothing in the files that follow rests on a single message.
Why This Desk Is Filing Seven Files On One Leak
This corpus has spent 500 files discounting attacker figures because they came from attackers. At 25-1111, 25-1001 and 25-0105 the volume claims were recorded as claims and left there, because nothing existed to check them against.
Here, for one group and roughly one year, there is something to check them against. That is rare enough to be worth working properly rather than summarising.
Compiled from published analyses of the leaked archive by security vendors and from contemporaneous reporting, listed below. This desk has not obtained or examined the archive itself and relies entirely on others’ readings of it. The volume, chatroom and domain counts vary between sources and are given as ranges. Corrections: corrections@forensicpost.com.
- Black Basta ransomware gang’s internal chat logs leak onlineBleepingComputer
- Experts race to extract intel from Black Basta internal chat leaksThe Register
- Black Basta exposed: a look at a cybercrime data leakIntel 471
- Deciphering Black Basta’s infrastructure from the chat leakFlare
- Analysis of Black Basta ransomware chat leaksTrellix