Deadlock is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
observed victims (by country)
ItalySpainPolandUnited States
observed sectors
Professional ServicesManufacturingTechnologyOther
90 victims · last active 24 Aug 2026
recent activity · our intel
source: ransomware.live1 refs → FAQ2
What tactic does the Deadlock group employ?+
Deadlock uses a double-extortion tactic, as it exposes victims on a data leak site.
What should defenders focus on to protect against Deadlock?+
Defenders should focus on leaked data monitoring, offline backups for critical systems, and phishing awareness.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.