Desk live·
ForensicPost
Ransomware/Method/File 25-0527

Two Leaked Ransomware Operations Disagree on Pricing, Geography and Scale

Three months apart, two operations had their internals published. On pricing, geography, scale and structure the two records point in opposite directions — which is the most useful result available.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
D. Kennedy13 min readConfidence: medium4 sources reviewed

In February 2025 the Black Basta chat archive was published. In May 2025 the LockBit affiliate panel was dumped. This corpus has filed thirteen files across the two and this one puts them next to each other.

Where They Diverge

Findings comparedPublished analyses of both leaks
TimeEventEvidence
PricingIndexed to looked-up victim revenue against flat tens of thousands25-0215 against 25-0519
Largest demand$28.7m against roughly $120,00025-0215 against 25-0519
GeographyPredominantly Western reporting against China firstCorpus record against 25-0517
Scale$107m traced over two years against $2.3m over five months25-0227 against 25-0511
Source typeConversation requiring interpretation against operational records25-0211 against 25-0508

The Divergence Is The Finding

A second sample that confirmed the first would have been more satisfying and much less informative. What two disagreeing samples establish is that no single leak supports a general claim about how ransomware operations work — which is precisely what this desk warned about at 25-0226 before having any way to test it.

The warning was written when there was one source. It now has evidence behind it.

What Survives Both

Two things. First, that the volume and address figures these operations generate are artefacts of their systems rather than measurements of anything — established independently at 25-0215 and 25-0510 by different routes.

Second, that both operations were commercial concerns with staff, tiers, cuts and conversion problems. Neither leak shows anything resembling the adversary of the briefing slide, and the two agree on that despite agreeing on nothing else.

What This Desk Is Not Going To Write

A synthesis. Two operations is not a sample of a market containing dozens, and the two available ones were selected by whoever chose to leak them rather than by anything resembling a sampling frame.

The corpus measured its own selection bias against incident-response data at 25-1225b and found it over-represents the worse outcome on every measure. The same instinct applies here: two leaks are two leaks, and thirteen files built on them are thirteen files that need this one attached.

This is a method file

It compares findings already filed at 25-0211 through 25-0228 and 25-0508 through 25-0525 rather than adding material. All underlying sources are cited in those files; the principal analyses are listed again below. This desk has examined neither leak directly. No general claim about ransomware operations is made or intended. Corrections: corrections@forensicpost.com.

Sources
  1. Inside LockBit’s admin panel leak: affiliates, victims and millions in cryptoTrellix
  2. Black Basta exposed: a look at a cybercrime data leakIntel 471
  3. LockBit leak provides insight into RaaS enterpriseTRM Labs
  4. Leaked Black Basta chat logs show banality of ransomwareBankInfoSecurity
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary