A leaked MySQL database from the RAMP cybercrime forum has exposed the inner workings of a major Russia-linked ransomware marketplace, while separate reporting says the FBI later seized the forum. Analysis of the leak showed RAMP operated from November 2021 through January 2024 as a commercial hub for the full ransomware supply chain, connecting initial access brokers, ransomware-as-a-service (RaaS) operators, and affiliates through public listings and private negotiations.
The dataset reportedly contained 7,707 users, 1,732 threads, 340,333 IP log records, 1,899 private conversations, and 3,875 private messages, revealing 333 access-sale threads and 60 RaaS threads. Listings targeted organizations in more than 20 countries, with the United States appearing in about 40% of identifiable offers, and victims spanning government, banking, healthcare, energy, technology, defense, and telecommunications. The records showed affiliates could receive up to 90% of ransom proceeds, underscoring how ransomware campaigns were sustained by a specialized underground market built around stolen access, affiliate recruitment, and private deal-making.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Comparitech analyzed the leaked RAMP database and disclosed details showing the forum had 7,707 users, 1,732 threads, 340,333 IP log records, and extensive private communications, illustrating how ransomware actors collaborated through the platform.
Infosecurity Magazine reported that the FBI took down the RAMP ransomware forum, marking a law enforcement disruption of the criminal marketplace.
During its operation, RAMP hosted hundreds of threads advertising access to compromised networks and dozens of ransomware-as-a-service offerings, showing it functioned as a commercial ecosystem for ransomware operations targeting organizations in more than 20 countries.
The leaked MySQL database analyzed by Comparitech contained records spanning through January 2024, including user accounts, forum threads, private messages, IP logs, and administrator activity documenting the forum's scale and operations.
The leaked RAMP forum database indicates the Russia-linked cybercrime marketplace was active from November 2021, supporting ransomware-related access sales, affiliate recruitment, and private deal-making.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.