DeadLock Ransomware Group Targets Over 80 Organizations Worldwide
DeadLock, a ransomware group, has been making headlines since its appearance in July 2025. The group has listed over 80 organizations on its leak site, known as the DeadLock blog, with more than half of the claimed victims located in Europe.
The targeted sectors include IT, mining, manufacturing, transportation, logistics, hospitality, and consumer goods. DeadLock's operation follows a familiar double-extortion model: attackers first steal sensitive information, then lock files and use the threat of a public data leak to increase pressure on victims.
What sets DeadLock apart is its decentralized infrastructure, which uses blockchain-backed services and the Session messaging network to support negotiation, leak publication, and victim communication. This makes it harder for law enforcement or hosting providers to disrupt their operations.