Ransomware Victim Feed Screensaver
The Ransomware Victim Feed screensaver shows the most recent entries from ransomwatch, an open-source archive that mirrors the victim listings ransomware gangs publish on their own leak sites. Every row is an unverified criminal claim, dated, not a confirmed breach. It's free, needs an internet connection, and ESC exits.
How the Ransomware Victim Feed screensaver works
The saver reads ransomwatch's public posts.json straight from GitHub in your browser — no key, no server, no third-party aggregator.
That file holds roughly 16,000 archived listings with the newest at the end; the saver keeps only the latest 40 and scrolls them slowly.
Each row shows the name the gang posted, the group that claimed it in accent colour, and the date ransomwatch's collector first saw the post.
It refreshes every 30 minutes, and several copies on screen share one download rather than each fetching the file.
A worked example
A row might read NF Stroth & Associates — PLAY — claimed 2025-06-16: the Play group listed that firm on its leak site on that date. Whether data was actually taken, and whether the organisation ever confirmed it, is not something the feed knows. Security teams use walls like this as an early-warning board, not as evidence.
Settings & tips
- Scroll speed sets how fast the wall creeps; leave it low for a quiet operations-room display.
- The header shows the date of the newest entry — check it, because ransomwatch's collector runs on its own schedule and can lag.
- Names come straight from criminal postings and can be misspelled, duplicated, or simply false.
Frequently asked questions
- Are these confirmed breaches?
- No. Every row is a claim a ransomware group made on its own leak site to pressure a target. Some are exaggerated, some are recycled old data, and some victims never confirm anything.
- Is the data live?
- The saver always fetches ransomwatch's current file, so you see the newest entries the project has published. Each row is dated, and the header shows the latest date, so you can judge how fresh the archive is.
- Does it need an API key?
- No — the file is served openly from GitHub with permissive CORS, so the browser reads it directly.
- Does it work offline?
- No. The list is fetched live, so offline it shows a short notice instead.
- Is it free?
- Yes — free, no download, in your browser. It links to nothing: there are no clickable leak-site addresses anywhere in the saver.