FORSANSEC PRODUCT

Know the moment a threat actor
claims to have breached you.

Threat Actor Claim continuously monitors ransomware leak sites, extortion channels and dark-web forums, and alerts your team the moment your organization — or a vendor in your supply chain — is named.

Live monitoring active
Syncing latest data…
01

Continuous claim monitoring

Leak sites, extortion blogs and closed forums are crawled around the clock for new victim claims as they're posted.

02

Real-time alerting

The moment your organization or brand is named, your SOC gets an alert with the claim, source and evidence captured.

03

Threat actor attribution

Claims are linked to tracked threat actor profiles — TTPs, past victims, and typical follow-through behavior.

04

Third-party exposure

Track claims against your vendors and supply chain, so a breach two hops away doesn't reach you unannounced.

STEP 1

Monitor

Leak sites & forums crawled continuously.

STEP 2

Detect

New claim mentioning your brand is captured.

STEP 3

Verify

Analysts triage and score confidence.

STEP 4

Alert

Your team is notified with full context.

STEP 5

Report

Evidence packaged for IR & leadership.

INSIDE A CLAIM

This is what a claim looks like the moment it's posted.

Extortion groups publish victim claims on leak sites and closed channels within minutes of an intrusion being declared. Threat Actor Claim captures the post, timestamps it, and starts the alert clock immediately — before the claim spreads further.

Mockup for illustration — a stylized reconstruction of a typical leak-site post format, not a live capture.

http://xk4h...onion/leaks/post-2291
NEW VICTIM POSTED
// meridian-health-group.claim
Victim: Meridian Health Group████
Revenue: $████M████ (est.)
Data exfiltrated: 340 GB — finance, HR, patient records
Deadline: 72:00:00 until publication
Proof: 3 sample files attached████████
⏱ Claim posted 00:00:41 ago — Threat Actor Claim alert already dispatched
UNDER THE HOOD

Sources & tooling behind every alert

Threat Actor Claim doesn't watch one feed — it correlates across the channels threat actors actually use to publish and amplify claims.

Tor Hidden Services

Ransomware & extortion leak sites crawled continuously over Tor.

Telegram Channels

Public and semi-private channels used to announce and amplify claims.

Paste & Leak Sites

Pastebin-style dumps monitored for credentials and exfiltrated data.

Hacking Forums

Closed and open-registration forums where access and data are traded.

Discord Servers

Threat-actor and marketplace servers tracked for claim chatter.

Actor Attribution Engine

Matches new claims against tracked threat-actor profiles and TTPs.

Live product demo

Sample data · illustrative

Everything below is populated with a fabricated demo dataset (fictional victim names) so you can explore the interface. No real claims are represented.

Claims tracked (range)
Active threat actor groups
Sectors targeted
Median time to alert
11 min
Median claim-to-alert timeline (sample claim)
00:00
Claim posted
00:41
Detected
04 min
Verified
11 min
Team alerted

Claims over time

Daily claim volume across monitored sources

Top threat actor groups

By number of claims in range

Recent claims

Most recent first

Threat actor Claimed victim Sector Country Date Confidence Status

Want this monitoring your organization?

Tell us a bit about your organization and our team will set up a walkthrough with real coverage of your brand.

Thanks — we've received your request and will reach out shortly.