Microsoft Tracks DeadLock Ransomware's Decentralized Extortion Operation
Microsoft has been tracking DeadLock ransomware as an emerging financially motivated operation that uses decentralized infrastructure to support victim communications and data leak operations.
The malware was first observed in July 2025 and has since impacted organizations across various sectors, including information technology, mining, transportation, and logistics, manufacturing, hospitality, consumer goods, and others in Europe, Asia, North America, South America, and Africa.
DeadLock ransomware employs double extortion tactics, encrypting victim environments while threatening to publicly release exfiltrated data. As of July 2026, the operators have published more than 80 compromised organizations on their data leak site, called the DeadLock blog, with over half of the claimed victims in Europe.